🔹 Feature: Post-Quantum Cryptography (PQC) in Active Directory Certificate Services
🔹 What It Does: Windows Server 2025 AD CS can now issue and manage certificates using NIST-standardized post-quantum algorithms — designed to survive attacks from future quantum computers. Your root CA, code signing certs, TLS, and domain auth get a quantum-safe path before hackers with quantum hardware arrive.
⚠️ Why this matters NOW (before quantum is here):
🔸 Harvest now, decrypt later: Attackers are already capturing encrypted traffic today, planning to decrypt it once a sufficiently powerful quantum computer exists. Anything encrypted in 2026 must still protect data in 203X.
🔸 Long-lived trust: Root CAs and code-signing certs issued today need to remain trustworthy for 10–20+ years. Once quantum breaks RSA/ECDSA, every signature made with them is forgeable retroactively. Migration starts before the headlines.
What Is It Giving You:
✅ ML-DSA Today (Phase 1): NIST FIPS 204 — quantum-safe digital signatures, available now in Windows Server 2025 AD CS with the May 2026 security update.
✅ ML-KEM + Composite Algorithms Next (Phase 2): FIPS 203 key encapsulation and composite certs (classical + PQ) where both signatures must validate — attacker must break both algorithms.
✅ Pure or Composite Certificates: Pure = single PQ algorithm. Composite = classical (RSA/ECDSA) + PQ in one cert. Pragmatic migration path — secure as long as either algorithm holds.
✅ Full PKI Surface Roadmap: ML-DSA support across all AD CS role services — CEP, CES, NDES, and Online Responder (OCSP).
✅ Modern Crypto Foundation: PQC requires CNG key storage providers. Legacy CSPs are not supported — time to retire the old crypto stack.
📋 Requirements:
🔸 AD CS servers: Windows Server 2025 with the 2026-05 security update (KB5087539) or later.
🔸 Clients: Windows 11 24H2 / 25H2 with the 2025-10 update (KB5067036) or later.
“Q-Day” has no calendar invite — cryptographic migrations take years. Start planning the PQC migration of your enterprise PKI today. 🚀
🌐 https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/post-quantum-cryptography-overview