ms.service: entra-id
ms.subservice: domain-services
ms.topic: how-to
ms.date: 07/14/2025
ms.author: justinha
ms.reviewer: bochingwa
ms.custom: has-azure-ad-ps-ref, azure-ad-ref-level-one-done
:::image type="content" border="true" source="media/reference-domain-services-tls-enforcement/enable.png" alt-text="Screenshot that shows how to enable TLS 1.2 Only Mode for Domain Services.":::
## [**PowerShell**](#tab/powershell)
## Troubleshooting
- **Use application-level diagnostics**: Some apps provide logs or error messages when TLS handshakes fail. Look for errors related to unsupported protocols.
- If the steps to enable **TLS 1.2 Only Mode** fail, or if your want to **temporarily disable TLS 1.2 Only Mode** open an [Azure support request](/entra/fundamentals/how-to-get-support) for more troubleshooting help.
ms.service: entra-id
ms.subservice: domain-services
ms.topic: how-to
ms.date: 08/15/2025
ms.author: justinha
ms.reviewer: bochingwa
ms.custom: has-azure-ad-ps-ref, azure-ad-ref-level-one-done
:::image type="content" border="true" source="media/reference-domain-services-tls-enforcement/enable.png" alt-text="Screenshot that shows how to enable TLS 1.2 Only Mode for Domain Services.":::
>[!Note]
>Until August 31, 2025, you can select **Disable** to temporarily allow legacy TLS traffic while you update or replace apps that might fail. Select **Enable** again to remain compliant.
## [**PowerShell**](#tab/powershell)
## Troubleshooting
- Some apps provide logs or error messages when TLS handshakes fail. Use application-level diagnostics to look for errors related to unsupported protocols.