TLSv1 and TLSv1.1 are less secure and no longer supported by browsers, which poses a security risk for DVLS. We recommend that users disable TLSv1 and TLSv1.1 in their IIS configuration on Windows servers hosting DVLS. On Windows Server 2022 and later, TLS 1.0 and TLS 1.1 are disabled by default.
Microsoft has written a guide on TLS version enforcement capabilities now available per certificate binding on Windows Server 2019.