last sync: 2024-Sep-18 17:50:24 UTC

Azure Active Directory Domain Services managed domains should use TLS 1.2 only mode

Azure BuiltIn Policy definition

Source Azure Portal
Display name Azure Active Directory Domain Services managed domains should use TLS 1.2 only mode
Id 3aa87b5a-7813-4b57-8a43-42dd9df5aaa7
Version 1.1.0
Details on versioning
Versioning Versions supported for Versioning: 1
1.1.0
Built-in Versioning [Preview]
Category Azure Active Directory
Microsoft Learn
Description Use TLS 1.2 only mode for your managed domains. By default, Azure AD Domain Services enables the use of ciphers such as NTLM v1 and TLS v1. These ciphers may be required for some legacy applications, but are considered weak and can be disabled if you don't need them. When TLS 1.2 only mode is enabled, any client making a request that is not using TLS 1.2 will fail. Learn more at https://docs.microsoft.com/azure/active-directory-domain-services/secure-your-domain.
Mode Indexed
Type BuiltIn
Preview False
Deprecated False
Effect Default
Audit
Allowed
Audit, Deny, Disabled
RBAC role(s) none
Rule aliases IF (1)
Alias Namespace ResourceType Path PathIsDefault DefaultPath Modifiable
Microsoft.AAD/domainServices/domainSecuritySettings.tlsV1 Microsoft.AAD DomainServices properties.domainSecuritySettings.tlsV1 True True
Rule resource types IF (1)
Microsoft.AAD/domainServices
Compliance Not a Compliance control
Initiatives usage none
History
Date/Time (UTC ymd) (i) Change type Change detail
2021-05-18 14:34:48 change Minor (1.0.0 > 1.1.0)
2021-04-21 13:28:46 add 3aa87b5a-7813-4b57-8a43-42dd9df5aaa7
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC