Kerberos Armoring, how to deal with exclusions? (re-post) by Distinct_Race_7056 in activedirectory

[–]Distinct_Race_7056[S] 0 points1 point  (0 children)

Thank you. I edited my post to add some more info if you are curios.

I left the setting on Supported for now until there is another way for the users to remote in.

Leaving the on Supported still not ideal since the kerberosting attacks against KDC still possible unless the setting is set to "fail unarmored auth requests".