AD FS CVE-2026-56155: DKM ACL Audit and Remediation Checklist

Microsoft’s July 2026 AD FS update begins DKM ACL auditing; it does not automatically fix permissions. Use documented opt-in remediation, review events, test compatibility, and prepare for October enforcement.

Back to Blog
(Updated )
3 min read
Conceptual illustration of federated identity trust anchored by a central signing key connected to many applications, targeted by an attacker

The July 2026 Windows update for CVE-2026-56155 does not automatically harden every Active Directory Federation Services Distributed Key Manager ACL. It installs the new behavior in Audit Mode so administrators can identify affected permissions, test remediation, and opt in before automatic remediation begins.

Current as of 2026-08-15

Microsoft KB5121391 says Audit Mode starts after the July 14 update. Administrators can opt in with the documented RemediateDkmAcl registry value. Automatic remediation is scheduled to begin October 13, 2026 for supported systems unless the documented opt-out applies.

Decision summary

  • Apply the July 2026 or later update to every federation server.
  • Read Audit Mode events; do not report the update as an automatic ACL fix.
  • Back up, test, and use Microsoft’s documented opt-in when ready.
  • Investigate key exposure separately; vulnerable permissions do not by themselves prove theft.

Understand the rollout phases

Audit Mode identifies permissions that require remediation without changing them automatically. Administrators can set HKLM\SOFTWARE\Microsoft\ADFS\RemediateDkmAcl as a DWORD with value 1 to opt in to remediation after testing. Microsoft’s automatic phase begins October 13, 2026 for Windows Server 2016 and later unless administrators use the documented control. Windows Server 2012 and 2012 R2 have additional prerequisite and support considerations.

Use the documented events

  • Events 1132, 1133, and 1134 support audit and readiness review.
  • Events 1135 and 1136 report remediation behavior.
  • Collect the AD FS Admin log from every federation server.
  • Correlate event timing with update installation and service restarts.

Safe remediation sequence

  1. Inventory every federation server and operating-system version.
  2. Install the July 2026 or a superseding update on all nodes.
  3. Back up AD FS and Active Directory recovery information according to the organization’s runbook.
  4. Review audit events and dependencies.
  5. Test the opt-in in a representative environment.
  6. Enable documented remediation in a controlled window.
  7. Verify AD FS service, relying-party authentication, event results, and rollback readiness.

Separate vulnerability remediation from incident response

The ACL condition can create a path to sensitive DKM material, but it does not prove the token-signing key was stolen. When evidence suggests unauthorized access, preserve logs, review federation trust and signing certificates, investigate identity activity, and involve qualified responders. Rotate keys only under a tested incident plan when scope warrants it.

Prepare for October

Organizations that cannot complete opt-in remediation before October should document the compatibility blocker, monitoring, owner, deadline, and Microsoft-supported temporary action. Do not silently defer.

For related guidance from ITECS, see ITECS cybersecurity services.

Sources and update trigger

Review trigger: Recheck Microsoft’s KB before opt-in and before October 13, 2026, and update immediately if rollout dates, events, or prerequisites change.

continue reading

More ITECS blog articles

Browse all articles

About ITECS Team

The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.

View full profile and articles

Share This Article

Continue Reading

Explore more insights and technology trends from ITECS

View All Articles