QuestionQ56

Secure Windows Server infrastructure

Your network has an Active Directory Domain Services (AD DS) domain that includes a management server named Server1 and a privileged user named Admin1.

Admin1 uses Server1 to run Active Directory Users and Computers and the Group Policy Management Console (GPMC).

You apply a security baseline to every privileged user to prevent credential caching and delegation. After the baseline is applied, Admin1 is unable to open either console. The consoles display logon and access-denied errors.

You run klist tgt as Admin1 and receive the following error message:

0x80009030e: No credentials are available in the security package

You need to restore AD DS management access for Admin1 without changing domain-wide or server-wide authentication settings.

What should you do?

Explanation

Membership in the Protected Users group applies nonconfigurable authentication protections that disable credential caching, default credential delegation (CredSSP), Digest, and NTLM, and impose Kerberos restrictions. Removing the user from that group is the account-scoped way to remove those restrictions; enabling Digest caching or default-credential delegation does not override Protected Users protections.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!