TLS1.2 enablement would be nice, I tend zo use the script from here https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/reference-connect-tls-enforcement