kerberos authentication error

Russell Ang 66 Reputation points
2021-09-30T06:15:45.843+00:00

Hi,

I can login to any server with authentication successfully. But when come to launch or run cmd or powershell with admin privileges' access. Will throw out error with access denied. Even i'm enterprise admin or domain admin doesn't seem to have access. Only need to try authentication as different user using same account it's successfully.

Below is the screenshot without authenticate, but i ready have enterprise admin seem not able to manage the remote server. 136469-1.jpg

Anyone encounter for kerberos authentication error?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,070 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,811 questions
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. Thameur-BOURBITA 32,496 Reputation points
    2021-09-30T09:45:43.003+00:00

    Hi

    Hi

    It seems that the Admin account you are using is members of protected user.
    You can remove it from protected users to be able to use ntlm protocol for authentication.
    Regarding the kerberos error, check if the SPN configuration is correct on the impacted server, if you want keep Admin account with privileged in protected users.

    Please don't forget to mark helpful reply as answer

    0 comments No comments

  2. Russell Ang 66 Reputation points
    2021-09-30T11:31:52.03+00:00

    @Thameur-BOURBITA

    I've checked security group doesn't not have protected user.

    0 comments No comments

  3. Thameur-BOURBITA 32,496 Reputation points
    2021-09-30T12:16:42.477+00:00

    Did you check SPN configuration ?

    Please don't forget to mark helpful reply as answer


  4. Limitless Technology 39,331 Reputation points
    2021-09-30T13:03:57.953+00:00

    Hello @Russell Ang

    I agree that besides checking if Enterprise Admin or Domain Admin is member of the local Administrators group, you may be using an account added in "Protected Users" group.

    Since local Admin security is a concern nowadays I would recommend you to implement LAPS as a solution for centralized Local Administrator management of your environment without exposing your domain Admins groups.

    LAPS:
    https://www.microsoft.com/en-us/download/details.aspx?id=46899
    LAPS Guide:
    https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/local-administrator-password-solution-laps-implementation-hints/ba-p/258296

    Hope this helps with your query,

    --------------

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

  5. Russell Ang 66 Reputation points
    2021-10-01T01:05:33.667+00:00

    Hello @Limitless Technology

    The issues is I'm getting kerbose authentication error, to any domain servers.

    0 comments No comments