Share via

Enabled AES Encryption via Group Policy

rr-4098 2,211 Reputation points
2024-10-24T18:14:22.7966667+00:00

When enabling AES encryption on user accounts, do I need to update the Default Domain Policy or the Default Domain Controller Policy or both?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments

Answer accepted by question author
  1. Yanhong Liu 14,320 Reputation points Microsoft External Staff
    2024-10-25T08:58:10.2133333+00:00

    Hello,

    When you enable AES encryption for user accounts, you typically update the Default Domain Policy instead of the Default Domain Controller Policy. This is because AES encryption is primarily concerned with authentication and encryption requirements for user and computer accounts in a domain, which are typically enforced through domain policies.

    The Default Domain Controller Policy applies primarily to the domain controllers themselves. This policy contains some configuration for the domain controllers, but it does not directly affect the behavior of user or computer accounts. Therefore, you typically do not need to modify the Default Domain Controller Policy when you enable AES encryption.

    I hope the information above is helpful.

    Best Regards,

    Yanhong Liu

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.