Posted in

Post-Quantum Cryptography (PQC) in Active Directory Certificate Services

🔹 Feature: Post-Quantum Cryptography (PQC) in Active Directory Certificate Services
🔹 What It Does: Windows Server 2025 AD CS can now issue and manage certificates using NIST-standardized post-quantum algorithms — designed to survive attacks from future quantum computers. Your root CA, code signing certs, TLS, and domain auth get a quantum-safe path before hackers with quantum hardware arrive.

⚠️ Why this matters NOW (before quantum is here):
🔸 Harvest now, decrypt later: Attackers are already capturing encrypted traffic today, planning to decrypt it once a sufficiently powerful quantum computer exists. Anything encrypted in 2026 must still protect data in 203X.
🔸 Long-lived trust: Root CAs and code-signing certs issued today need to remain trustworthy for 10–20+ years. Once quantum breaks RSA/ECDSA, every signature made with them is forgeable retroactively. Migration starts before the headlines.

What Is It Giving You:
✅ ML-DSA Today (Phase 1): NIST FIPS 204 — quantum-safe digital signatures, available now in Windows Server 2025 AD CS with the May 2026 security update.
✅ ML-KEM + Composite Algorithms Next (Phase 2): FIPS 203 key encapsulation and composite certs (classical + PQ) where both signatures must validate — attacker must break both algorithms.
✅ Pure or Composite Certificates: Pure = single PQ algorithm. Composite = classical (RSA/ECDSA) + PQ in one cert. Pragmatic migration path — secure as long as either algorithm holds.
✅ Full PKI Surface Roadmap: ML-DSA support across all AD CS role services — CEP, CES, NDES, and Online Responder (OCSP).
✅ Modern Crypto Foundation: PQC requires CNG key storage providers. Legacy CSPs are not supported — time to retire the old crypto stack.

📋 Requirements:

🔸 AD CS servers: Windows Server 2025 with the 2026-05 security update (KB5087539) or later.
🔸 Clients: Windows 11 24H2 / 25H2 with the 2025-10 update (KB5067036) or later.

“Q-Day” has no calendar invite — cryptographic migrations take years. Start planning the PQC migration of your enterprise PKI today. 🚀

🌐 https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/post-quantum-cryptography-overview

Microsoft Certified Trainer, Office 365, AWS, Azure and Cloud Expert-Architect. In the IT world for over than 20 years.

Apart from the main area of Microsoft Azure expert in the field of infrastructure servers Windows Server 2003-2019, Microsoft Active Directory, Hyper-V Private Cloud, IIS, System Center, SQL.

Private Cloud, System Center, Hyper-V, Open Stack Expert and all Microsoft products Expert. Linux Server administrator.

My Azure community projects:

https://mazeball.azurewebsites.net/
https://github.com/MariuszFerdyn?tab=repositories

More