Active directory: disable DES/RC4 and enable AES

Jaro 121 Reputation points
2025-11-19T19:39:57.4066667+00:00
For security reasons, I want to disable the risky DES/RC4 protocols and enable AES via GPO.
I've been checking the events on my domain controllers and I don't find any 4769 events. Does this mean I'm ready to enable AES?

Thanks
Microsoft Security | Active Directory Federation Services
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2025-11-19T19:40:26.05+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    To disable DES and RC4 encryption protocols and enable AES in your Active Directory environment, you can configure the encryption types allowed for Kerberos via Group Policy. Here are the steps you should follow:

    1. Open Group Policy Management: Navigate to the Group Policy Management Console on your domain controller.
    2. Edit the Default Domain Policy: Locate the Default Domain Policy or create a new GPO that will apply to your domain controllers.
    3. Configure Encryption Types: Go to Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options. Look for the policy named Network security: Configure encryption types allowed for Kerberos.
    4. Enable AES Encryption: Ensure that you check the options for AES128_HMAC_SHA1 and AES256_HMAC_SHA1 to enable AES encryption.
    5. Disable RC4: If you want to disable RC4, make sure that it is not selected in the same policy settings.

    Regarding the absence of Event ID 4769, this event indicates that a Kerberos ticket was requested. If you are not seeing these events, it may suggest that there are no requests for tickets using the RC4 encryption type, which could imply that your environment is ready to enable AES. However, it's essential to ensure that all systems in your environment support AES before making this change.

    Always test the configuration in a controlled environment before applying it broadly to avoid any disruptions.


    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.