--- title: Enforce user logon restrictions (Windows 10) description: Describes the best practices, location, values, policy management, and security considerations for the Enforce user logon restrictions security policy setting. ms.assetid: 5891cb73-f1ec-48b9-b703-39249e48a29f ms.prod: W10 ms.mktglfcycl: deploy ms.sitesec: library author: brianlic-msft --- # Enforce user logon restrictions **Applies to** - Windows 10 Describes the best practices, location, values, policy management, and security considerations for the **Enforce user logon restrictions** security policy setting. ## Reference The **Enforce user logon restrictions** policy setting determines whether the Kerberos V5 Key Distribution Center (KDC) validates every request for a session ticket against the user rights policy of the user account. Validating each request for a session ticket is optional because the extra step takes time, and that can slow network access to services. The possible values for this Group Policy setting are: - Enabled - Disabled - Not defined ### Best practices - If this policy setting is disabled, users might be granted session tickets for services that they do not have the right to use. It is advisable to set **Enforce user logon restrictions** to Enabled. ### Location **Computer Configuration\\Windows Settings\\Security Settings\\Account Policies\\Kerberos Policy** ### Default Values The following table lists the actual and effective default policy values. Default values are also listed on the policy’s property page.
Server Type or GPO | Default Value |
---|---|
Default Domain Policy |
Enabled |
Default Domain Controller Policy |
Not defined |
Stand-Alone Server Default Settings |
Not applicable |
DC Effective Default Settings |
Enabled |
Member Server Effective Default Settings |
Not applicable |
Client Computer Effective Default Settings |
Not applicable |