> ## Documentation Index
> Fetch the complete documentation index at: https://syteca.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuring LDAP Integration in a Kerberos-Only Authentication Environment

> Set up Syteca in a Windows environment where NTLM is disabled and Kerberos is the only available authentication method, and resolve the connectivity issues that come with it.

**Kerberos** is a network authentication protocol that lets computers prove their identity over an unsecured network without transmitting passwords in plain text. It supports centralized authentication and is the foundation Single Sign-On (SSO) is built on.

Kerberos is based on the concept of a **Ticket** - an encrypted data packet issued by the **Key Distribution Center (KDC)**. On initial authentication, the KDC issues a **Ticket Granting Ticket (TGT)**. When the user accesses a specific resource, they present the TGT to receive a **Service Ticket (TGS)** for that resource.

This page covers configuring Syteca to work correctly once NTLM is disabled and Kerberos is the only authentication method available in the domain, plus the connectivity issues that setup commonly introduces.

## Configure Group Policy for Kerberos-only authentication

To disable NTLM and enforce Kerberos authentication:

<Steps>
  <Step title="Open Security Options">
    Open **Group Policy Management** and navigate to **Policies > Windows Settings > Security Settings > Local Policies > Security Options**.
  </Step>

  <Step title="Set the NTLM restriction policies to Deny">
    Set the following two policies:

    | Policy | Setting |
    | - | - |
    | **Restrict NTLM: Incoming NTLM Traffic** | Deny All Accounts |
    | **Restrict NTLM: Outgoing NTLM traffic to remote Servers** | Deny All |
  </Step>

  <Step title="Apply the policy">
    Run the following command to apply the updated policies immediately:

    ```bat theme={"system"}
    gpupdate /force
    ```
  </Step>
</Steps>

<Frame caption="The Security Options list in Group Policy Management Editor.">
  <img src="https://mintcdn.com/syteca/0v2KCT8vq_mcz8a7/images/administration/integrations/kerberos-group-policy-security-options.png?fit=max&auto=format&n=0v2KCT8vq_mcz8a7&q=85&s=e7ce9c74f40ed020b573b24d26d38385" alt="Group Policy Management Editor showing Security Options" width="1243" height="426" data-path="images/administration/integrations/kerberos-group-policy-security-options.png" />
</Frame>

<Frame caption="Restrict NTLM: Incoming NTLM Traffic and Outgoing NTLM traffic to remote Servers, both set to deny.">
  <img src="https://mintcdn.com/syteca/0v2KCT8vq_mcz8a7/images/administration/integrations/kerberos-restrict-ntlm-policies.png?fit=max&auto=format&n=0v2KCT8vq_mcz8a7&q=85&s=ea86a19beb1d13d91e699f01e2d74614" alt="Restrict NTLM policies set to Deny All Accounts and Deny All" width="1242" height="101" data-path="images/administration/integrations/kerberos-restrict-ntlm-policies.png" />
</Frame>

## Configure Syteca Server for Kerberos environments

To ensure Syteca Server operates correctly in an environment where Kerberos is the only available authentication method:

<Steps>
  <Step title="Run the server under a Domain Admins account">
    Start Syteca Server under an Active Directory user account that belongs to the **Domain Admins** group.
  </Step>

  <Step title="Refresh the automatic LDAP target">
    In the Management Tool, go to **Configuration > LDAP Targets** and click **Refresh Automatic LDAP Target**.
  </Step>
</Steps>

<Frame caption="Refreshing the automatic LDAP target in the Management Tool.">
  <img src="https://mintcdn.com/syteca/0v2KCT8vq_mcz8a7/images/administration/integrations/kerberos-refresh-automatic-ldap-target.png?fit=max&auto=format&n=0v2KCT8vq_mcz8a7&q=85&s=87538ccfa79a47c53200a19fd8469fae" alt="LDAP Targets tab showing the Refresh Automatic LDAP Target button" width="1853" height="985" data-path="images/administration/integrations/kerberos-refresh-automatic-ldap-target.png" />
</Frame>

<Warning>
  Running Syteca Server under a Domain Admins account is specifically required for Kerberos-only environments - this is a broader privilege than Syteca normally needs, so scope it to this use case rather than applying it by default.
</Warning>

## Troubleshooting

### RDP access issues after disabling NTLM

After disabling NTLM, the following RDP scenarios no longer work:

* Logging in as a local user over RDP
* Connecting via IP address over RDP
* Connecting with Network Level Authentication (NLA)

<Frame caption="The authentication error shown when connecting via RDP in ways NTLM disabling breaks.">
  <img src="https://mintcdn.com/syteca/0v2KCT8vq_mcz8a7/images/administration/integrations/kerberos-rdp-authentication-error.png?fit=max&auto=format&n=0v2KCT8vq_mcz8a7&q=85&s=7908d64bab2bd64cf1dd7f3437a2a605" alt="Remote Desktop Connection authentication error dialog" width="942" height="762" data-path="images/administration/integrations/kerberos-rdp-authentication-error.png" />
</Frame>

To avoid connectivity issues:

<Steps>
  <Step title="Add the Domain Controller and target machine to the hosts file (if the connecting PC isn't domain-joined)">
    If the PC you're connecting from isn't in the domain, add the Domain Controller and target machine to its `hosts` file.

    <Frame caption="Domain Controller and target machine entries added to the hosts file.">
      <img src="https://mintcdn.com/syteca/0v2KCT8vq_mcz8a7/images/administration/integrations/kerberos-hosts-file-entries.png?fit=max&auto=format&n=0v2KCT8vq_mcz8a7&q=85&s=f4e52d141aa533923fe36b952d7a011c" alt="hosts file with Domain Controller and target machine entries" width="1010" height="909" data-path="images/administration/integrations/kerberos-hosts-file-entries.png" />
    </Frame>
  </Step>

  <Step title="Always log in as a domain user">
    Kerberos doesn't issue tokens for local accounts - logging in as a local user won't authenticate.
  </Step>

  <Step title="Connect using the machine hostname, not its IP address">
    Kerberos ties authentication to the hostname; connecting by IP address breaks the ticket exchange.
  </Step>
</Steps>

### Password rotation errors

You may encounter the error **"New password does not meet password policy"** when rotating passwords for [Secrets](/docs/pam/secrets/add-secret) under an AD account.

To resolve this, adjust the following settings in **Group Policy Management > Policies > Windows Settings > Security Settings > Account Policies > Password Policy**:

| Setting | Change to | Why |
| - | - | - |
| **Minimum password age** | `0` | The default of 1 day prevents changing a password more than once per 24 hours, which blocks automated rotation from running more than once a day. |
| **Enforce password history** | `0` or disabled | If the generated password matches one already in the AD history (by default, the last 24 passwords), Active Directory rejects it. |

<Frame caption="The Password Policy settings relevant to automated password rotation.">
  <img src="https://mintcdn.com/syteca/0v2KCT8vq_mcz8a7/images/administration/integrations/kerberos-password-policy-settings.png?fit=max&auto=format&n=0v2KCT8vq_mcz8a7&q=85&s=c42aa724954a0bb80181bfc477393971" alt="Group Policy Password Policy settings" width="669" height="246" data-path="images/administration/integrations/kerberos-password-policy-settings.png" />
</Frame>

### Manual LDAP target not working

Adding a manual LDAP target doesn't work in Kerberos-only environments.

To resolve this, use **Refresh Automatic LDAP Target** instead of adding an LDAP target manually - see [Configure Syteca Server for Kerberos environments](#configure-syteca-server-for-kerberos-environments) above.

<Frame caption="The Edit LDAP Target panel - manual entry isn't supported in Kerberos-only environments.">
  <img src="https://mintcdn.com/syteca/0v2KCT8vq_mcz8a7/images/administration/integrations/kerberos-edit-ldap-target-manual.png?fit=max&auto=format&n=0v2KCT8vq_mcz8a7&q=85&s=cd7f4b134d753f1c010dcbe5f5ce9292" alt="Edit LDAP Target panel" width="1858" height="984" data-path="images/administration/integrations/kerberos-edit-ldap-target-manual.png" />
</Frame>

## Related

<CardGroup cols={2}>
  <Card title="LDAP targets" icon="folder-tree" href="/docs/administration/integrations/ldap-targets">
    General LDAP target configuration, automatic and manual.
  </Card>

  <Card title="Remote password rotation" icon="refresh-cw" href="/docs/pam/secrets/remote-password-rotation">
    The rotation mechanism affected by AD password policy settings above.
  </Card>

  <Card title="Add a secret" icon="key-round" href="/docs/pam/secrets/add-secret">
    Configure the AD account secrets referenced in this guide.
  </Card>
</CardGroup>
