The July 2026 Windows update for CVE-2026-56155 does not automatically harden every Active Directory Federation Services Distributed Key Manager ACL. It installs the new behavior in Audit Mode so administrators can identify affected permissions, test remediation, and opt in before automatic remediation begins.
Current as of 2026-08-15
Microsoft KB5121391 says Audit Mode starts after the July 14 update. Administrators can opt in with the documented RemediateDkmAcl registry value. Automatic remediation is scheduled to begin October 13, 2026 for supported systems unless the documented opt-out applies.
Decision summary
- Apply the July 2026 or later update to every federation server.
- Read Audit Mode events; do not report the update as an automatic ACL fix.
- Back up, test, and use Microsoft’s documented opt-in when ready.
- Investigate key exposure separately; vulnerable permissions do not by themselves prove theft.
Understand the rollout phases
Audit Mode identifies permissions that require remediation without changing them automatically. Administrators can set HKLM\SOFTWARE\Microsoft\ADFS\RemediateDkmAcl as a DWORD with value 1 to opt in to remediation after testing. Microsoft’s automatic phase begins October 13, 2026 for Windows Server 2016 and later unless administrators use the documented control. Windows Server 2012 and 2012 R2 have additional prerequisite and support considerations.
Use the documented events
- Events 1132, 1133, and 1134 support audit and readiness review.
- Events 1135 and 1136 report remediation behavior.
- Collect the AD FS Admin log from every federation server.
- Correlate event timing with update installation and service restarts.
Safe remediation sequence
- Inventory every federation server and operating-system version.
- Install the July 2026 or a superseding update on all nodes.
- Back up AD FS and Active Directory recovery information according to the organization’s runbook.
- Review audit events and dependencies.
- Test the opt-in in a representative environment.
- Enable documented remediation in a controlled window.
- Verify AD FS service, relying-party authentication, event results, and rollback readiness.
Separate vulnerability remediation from incident response
The ACL condition can create a path to sensitive DKM material, but it does not prove the token-signing key was stolen. When evidence suggests unauthorized access, preserve logs, review federation trust and signing certificates, investigate identity activity, and involve qualified responders. Rotate keys only under a tested incident plan when scope warrants it.
Prepare for October
Organizations that cannot complete opt-in remediation before October should document the compatibility blocker, monitoring, owner, deadline, and Microsoft-supported temporary action. Do not silently defer.
For related guidance from ITECS, see ITECS cybersecurity services.
Sources and update trigger
Review trigger: Recheck Microsoft’s KB before opt-in and before October 13, 2026, and update immediately if rollout dates, events, or prerequisites change.
continue reading
More ITECS blog articles
About ITECS Team
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles