Netlogon Domain Controller Enforcement Mode is enabled by default beginning with the February 9, 2021 Security Update, related to CVE-2020-1472. This will block vulnerable connections from non-compliant devices. DC enforcement mode requires that all Windows and non-Windows devices use secure RPC. Microsoft addressed a Critical RCE vulnerability on August 11, 2020. Customers should review the updated FAQs guidance from August to provide further clarity on this upcoming change. Organizations that deploy Microsoft Defender for Identity or Microsoft 365 Defender are able to detect adversaries as they try to exploit this specific vulnerability against their domain controllers.”]

