Skip to Content

Kerberos Authentication Problems After Last Week’s Microsoft Patch Tuesday

Microsoft has acknowledged that updates released last week might cause problems with Kerberos authentication on Windows Servers with the Domain Controller role. Microsoft says it is working on a solution for the problem. Kerberos is the default authentication protocol for domain-connected devices running Windows 2000 and newer.


So this isn’t impacting home users and non-domain joined devices. Which reduces the problem set for the enterprise very little. This is an unintended consequence of domain hardening actions, which are desirable, taken as part of the update. The issue may raise a Microsoft-Windows-Kerberos-Key-Distribution-Center Event ID 14 error event in the System section of Event Log on your Domain Controller, and is most likely tied to where you have set the This account supports Kerberos AES 256 bit encryption’ or ‘This account supports Kerberos AES 128-bit encryption’ Account Options for your AD users. Lots of variability here; keep an eye on MS for a revised patch.


    Ads Blocker Image Powered by Code Help Pro

    It looks like you are using an adblocker.

    Ads keep our content free. Please consider supporting us by allowing ads on