Ahead of the Microsoft update in March forcing ldap hardening, I have a few questions
1.Is the update actually making any direct changes (enforcing the settings), or is it simply making the necessary changes but the actual applying of the settings will happen later in the year in another update?
2. We are currently in the process of moving to ldaps however I have read that this may be not be necessary and that we can force the ldap signing settings via gpo and this will suffice (along with channel binding). Is this correct?
3. If we wanted to delay the changes I am assuming I simply don’t install the march update until we are ready on the DC’s. What about all the windows clients in the network. Will these simply carry on working even if the update is applied to them?