Hi LAIDLAW, JASON,
Microsoft has no unified release date to transition all Windows Server tooling to a strict TLS 1.3-only state. Although Windows Server 2022 and Windows Server 2025 enable TLS 1.3 by default through the Windows encryption engine at %SystemRoot%\System32\schannel.dll, Microsoft designed TLS 1.3 to work only with services rewritten to use a modern programming structure called SCH_CREDENTIALS, rather than the older SCHANNEL_CRED structure. Furthermore, TLS 1.3 removed mid-connection certificate renegotiation, a feature many legacy services still use to verify identity. If you force a TLS 1.3-only environment by going to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server and Client and setting the Enabled DWORD to 0 and DisabledByDefault DWORD to 1 (which tells Windows to completely block TLS 1.2 for all incoming and outgoing traffic), unmigrated tools immediately break. For example, Remote Desktop (%SystemRoot%\System32\termsrv.dll), MMC consoles, and the Credential Security Support Provider (%SystemRoot%\System32\credssp.dll) still require TLS 1.2; disabling it causes connections to drop with client error 0x4 or 0x80090302 (SEC_E_UNSUPPORTED_FUNCTION, meaning the tool requested a blocked encryption method) and records Schannel Event ID 36871 with internal error state 10013 in the System Event Log (%SystemRoot%\System32\Winevt\Logs\System.evtx). Similarly, WinRM (%SystemRoot%\System32\wsmsvc.dll) and PowerShell remoting over HTTPS rely on the kernel web driver (%SystemRoot%\System32\drivers\http.sys) for incoming connections and Windows HTTP Services (%SystemRoot%\System32\winhttp.dll)—controlled via DefaultSecureProtocols under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp and HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp—for outgoing connections, both of which fail without TLS 1.2 and return error 0x80072F8F (ERROR_WINHTTP_SECURE_FAILURE, a failed secure handshake) or 0x80090331 (SEC_E_ALGORITHM_MISMATCH, meaning client and server could not agree on a protocol).
Microsoft updates server components individually across operating system releases, support for your remaining tools is split. For scripting, PowerShell 7 (%ProgramFiles%\PowerShell\7\pwsh.exe) uses modern .NET and supports TLS 1.3 out of the box, whereas Windows PowerShell 5.1 (%SystemRoot%\System32\WindowsPowerShell\v1.0\powershell.exe) relies on .NET Framework 4.8 and requires setting the SystemDefaultTlsVersions and SchUseStrongCrypto DWORD values to 1 under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319 and HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Internet Settings's counterpart HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\.NETFramework\v4.0.30319 so PowerShell lets Windows pick the newest encryption protocol, though scripts hardcoding Tls12 will still fail with 0x80090331 if TLS 1.2 is disabled. For domain operations, Windows Server 2025 updated the Active Directory service (%SystemRoot%\System32\ntdsai.dll) to support TLS 1.3 for LDAPS traffic, while Active Directory Certificate Services (%SystemRoot%\System32\certsrv.exe) web enrollment endpoints still need TLS 1.2 for client-certificate handshakes.
Finally, the Windows Update Agent (%SystemRoot%\System32\wuaueng.dll) and management, backup, and security agents like Microsoft Defender for Endpoint (%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe) still require TLS 1.2 to communicate with cloud and local management servers, and because Microsoft officially deprecated WSUS in Windows Server 2025 in favor of Azure Update Manager, WSUS will not be updated for TLS 1.3-only environments. This is an ongoing architectural transition and TLS 1.2 with strong cipher suites remains fully compliant with modern security standards, you should keep both TLS 1.2 and TLS 1.3 enabled and wait for official Microsoft updates across future Windows Server releases.
Hope this answer has brought you some useful information. If it did, please hit “accept answer”. Should you have any questions, feel free to leave a comment.
VPHAN