admin管理员组文章数量:1124693
According to the Windows documentation:
The Enforce user logon restrictions policy setting determines whether the Kerberos V5 Key Distribution Center (KDC) validates every request for a session ticket against the user rights policy of the user account.
I enabled this setting and expected that, if I already had an active TGT (Ticket-Granting Ticket) and the account was then disabled or the password was expired, I would no longer be able to obtain a TS (Ticket for Service) with this TGT. However, I was still able to get a TS.
My client (from which I am sending requests) is a non-Windows client, if it matters.
Did I correctly understand this policy setting, and are my expectations reasonable? If this setting should work as I described, are there any reasons why it doesn’t work?
本文标签:
版权声明:本文标题:active directory - What exactly does the setting "Enforce user logon restrictions" in Kerberos Policy do? - St 内容由网友自发贡献,该文观点仅代表作者本人, 转载请联系作者并注明出处:http://www.betaflare.com/web/1736642717a1946032.html, 本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌抄袭侵权/违法违规的内容,一经查实,本站将立刻删除。
发表评论