kerberos authentication error

Russell Ang 66 Reputation points
2021-09-30T06:15:45.843+00:00

Hi,

I can login to any server with authentication successfully. But when come to launch or run cmd or powershell with admin privileges' access. Will throw out error with access denied. Even i'm enterprise admin or domain admin doesn't seem to have access. Only need to try authentication as different user using same account it's successfully.

Below is the screenshot without authenticate, but i ready have enterprise admin seem not able to manage the remote server. 136469-1.jpg

Anyone encounter for kerberos authentication error?

Windows for business Windows Client for IT Pros Directory services Active Directory
Windows for business Windows Server User experience Other
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. Gary Reynolds 9,621 Reputation points
    2021-10-26T07:43:06.88+00:00

    Hi @Russell Ang

    I thought I would jump in and give a few pointers to check that Kerberos is working as expected. These test are using NetTools, however, some of the functionality is available in other MS tools, but NetTools makes it easier to jump between tests.

    Go to Authentication -> Sessions - confirm that the active session is Kerberos or Negotiate in the Auth column

    143659-image.png

    In the Quick Search bar enter the name of the server logged onto and click search
    143722-image.png

    In the search view double click on the server, In the Properties dialog, select the Delegation tab and right click on one of the Service Principal Names and select Request SPN

    143660-image.png

    This will select the Kerberos Tickets option and display all the Kerberos tickets that have been cache, confirm that the selected SPN is in the list and also check the bottom area of screen for any error messages.

    143704-image.png

    Select Authentication -> User Rights and click refresh - check the administrators group to see if the Attribute are set to D, this means that you have a restricted token and UAC is enabled for privileged users.

    143620-image.png

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.