ADCS CAs, non-ADCS CAs, Managed PKIs, Public CAs, and Standalone CAs will be impacted. These changes will cause authentication failures with certificates issued using client authentication and not using Active Directory to supply subject information. Microsoft is phasing in changes to how certificates are mapped to Windows accounts. To address the threats from CVE-2022-34691, CVE-2022-26931 and CVE-2022-26923, Microsoft will enforce strong mappings between an authentication certificate and the account object with a new Object Identifier Extension (OID) 1.3.6.1.4.1.311.25.2.