This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
A user can access an intranet site, but the server records NTLM instead of Kerberos. Which action should an administrator take first?
Disable NTLM across the domain immediately.
Confirm the target name and query the expected HTTP SPN.
Increase the user's Kerberos token-size limit.
Which evidence best proves that a remediated service connection is using Kerberos?
The application opens without displaying an error.
The client has a TGT in its Kerberos ticket cache.
The client has the expected service ticket and the target records Kerberos in the successful logon.
Event ID 4769 reports ticket encryption type 0x17 for a service account. What does this result indicate?
The service ticket used RC4 and the service dependency requires remediation.
The KDC couldn't find a mutually supported encryption type.
The service successfully used AES256 encryption.
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?