Weak and being retired in favour of AES. Accounts lacking an explicit Kerberos encryption type have defaulted to AES-SHA1 since November 2022, and Windows Server 2025 KDCs refuse to issue RC4 TGTs.
Also called Rivest Cipher 4.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains RC4 in context, with comparison tables and the common traps.
Terms in this definition
- AES
Short for Advanced Encryption Standard, a symmetric cipher. With TDE, the RSA TDE protector wraps an AES-256 data encryption key.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- Kerberos
Authentication protocol based on tickets, native to Windows and Active Directory. Azure Files, Entra Domain Services and application proxy KCD all support it.
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
Related terms
- msDS-SupportedEncryptionTypes
A bitmask attribute on an account recording which Kerberos encryption types, for example AES or RC4, it can handle. When it is left empty, the KDC uses the domain's default instead.
- Protected Users
Members get fixed protections: four-hour TGTs, no delegation, no Digest, CredSSP or NTLM, and no RC4 or DES during Kerberos pre-authentication. Keep computer and service accounts out of this global group.