Finally!
I mean... TLS 1.2 with AES256 is there since Windows Vista! Why accept it in first place in Azure... MS should have done that over ten years ago.
Today is the day Azure Storage stops supporting versions 1.0 and 1.1 of Transport Layer Security (TLS). TLS 1.2 is the new minimum. The change has been a long time coming. Microsoft warned users several years ago that February 3, 2026, was the cut-off date after which the deprecated standards would no longer be supported. The …
On the client side Microsoft's love of old crap and "forever" keeping it... and now, saying "something".... sigh....
Good to see.... but honestly, Microsoft has been in the trash bin due to this for a very very very very very very long time.
That is to say, one component of Windows 7 (schannel), required manual or scripted or policy or installation tweeking.
I'm not aware of any version of Windows that supports 'thought control' (What You Want is What You Get), so in that sense any change you make to Windows default settings is "manual"
That requirement was removed somewhere around either Sp1 or Sp2. Not sure the exact date, but I know it definitely got removed, else I'd have nuked tons of them out of the network for more than a decade by enforcing it on Domain controllers and most other servers. Similar for Vista, same requirement was removed with Sp2 or shortly after.
Probably more a "uses that library in the product" effect than a conscious decision. That crypto stuff is ugly to manually take care of, let alone coding it. Which is the reason why wireguard became successful, removed a lot of unneeded complexity and nonsense bits...