Skip to main content
Kerberos is a network authentication protocol that lets computers prove their identity over an unsecured network without transmitting passwords in plain text. It supports centralized authentication and is the foundation Single Sign-On (SSO) is built on. Kerberos is based on the concept of a Ticket - an encrypted data packet issued by the Key Distribution Center (KDC). On initial authentication, the KDC issues a Ticket Granting Ticket (TGT). When the user accesses a specific resource, they present the TGT to receive a Service Ticket (TGS) for that resource. This page covers configuring Syteca to work correctly once NTLM is disabled and Kerberos is the only authentication method available in the domain, plus the connectivity issues that setup commonly introduces.

Configure Group Policy for Kerberos-only authentication

To disable NTLM and enforce Kerberos authentication:
1

Open Security Options

Open Group Policy Management and navigate to Policies > Windows Settings > Security Settings > Local Policies > Security Options.
2

Set the NTLM restriction policies to Deny

Set the following two policies:
3

Apply the policy

Run the following command to apply the updated policies immediately:
Group Policy Management Editor showing Security Options

The Security Options list in Group Policy Management Editor.

Restrict NTLM policies set to Deny All Accounts and Deny All

Restrict NTLM: Incoming NTLM Traffic and Outgoing NTLM traffic to remote Servers, both set to deny.

Configure Syteca Server for Kerberos environments

To ensure Syteca Server operates correctly in an environment where Kerberos is the only available authentication method:
1

Run the server under a Domain Admins account

Start Syteca Server under an Active Directory user account that belongs to the Domain Admins group.
2

Refresh the automatic LDAP target

In the Management Tool, go to Configuration > LDAP Targets and click Refresh Automatic LDAP Target.
LDAP Targets tab showing the Refresh Automatic LDAP Target button

Refreshing the automatic LDAP target in the Management Tool.

Running Syteca Server under a Domain Admins account is specifically required for Kerberos-only environments - this is a broader privilege than Syteca normally needs, so scope it to this use case rather than applying it by default.

Troubleshooting

RDP access issues after disabling NTLM

After disabling NTLM, the following RDP scenarios no longer work:
  • Logging in as a local user over RDP
  • Connecting via IP address over RDP
  • Connecting with Network Level Authentication (NLA)
Remote Desktop Connection authentication error dialog

The authentication error shown when connecting via RDP in ways NTLM disabling breaks.

To avoid connectivity issues:
1

Add the Domain Controller and target machine to the hosts file (if the connecting PC isn't domain-joined)

If the PC you’re connecting from isn’t in the domain, add the Domain Controller and target machine to its hosts file.
hosts file with Domain Controller and target machine entries

Domain Controller and target machine entries added to the hosts file.

2

Always log in as a domain user

Kerberos doesn’t issue tokens for local accounts - logging in as a local user won’t authenticate.
3

Connect using the machine hostname, not its IP address

Kerberos ties authentication to the hostname; connecting by IP address breaks the ticket exchange.

Password rotation errors

You may encounter the error “New password does not meet password policy” when rotating passwords for Secrets under an AD account. To resolve this, adjust the following settings in Group Policy Management > Policies > Windows Settings > Security Settings > Account Policies > Password Policy:
Group Policy Password Policy settings

The Password Policy settings relevant to automated password rotation.

Manual LDAP target not working

Adding a manual LDAP target doesn’t work in Kerberos-only environments. To resolve this, use Refresh Automatic LDAP Target instead of adding an LDAP target manually - see Configure Syteca Server for Kerberos environments above.
Edit LDAP Target panel

The Edit LDAP Target panel - manual entry isn't supported in Kerberos-only environments.

LDAP targets

General LDAP target configuration, automatic and manual.

Remote password rotation

The rotation mechanism affected by AD password policy settings above.

Add a secret

Configure the AD account secrets referenced in this guide.