4.0 KiB
title, description, ms.assetid, ms.pagetype, ms.prod, ms.mktglfcycl, ms.sitesec, author
title | description | ms.assetid | ms.pagetype | ms.prod | ms.mktglfcycl | ms.sitesec | author |
---|---|---|---|---|---|---|---|
Enforce user logon restrictions (Windows 10) | Describes the best practices, location, values, policy management, and security considerations for the Enforce user logon restrictions security policy setting. | 5891cb73-f1ec-48b9-b703-39249e48a29f | security | W10 | deploy | library | brianlic-msft |
Enforce user logon restrictions
Applies to
- Windows 10 Describes the best practices, location, values, policy management, and security considerations for the Enforce user logon restrictions security policy setting.
Reference
The Enforce user logon restrictions policy setting determines whether the Kerberos V5 Key Distribution Center (KDC) validates every request for a session ticket against the user rights policy of the user account. Validating each request for a session ticket is optional because the extra step takes time, and that can slow network access to services. The possible values for this Group Policy setting are:
- Enabled
- Disabled
- Not defined
Best practices
- If this policy setting is disabled, users might be granted session tickets for services that they do not have the right to use. It is advisable to set Enforce user logon restrictions to Enabled.
Location
Computer Configuration\Windows Settings\Security Settings\Account Policies\Kerberos Policy
Default Values
The following table lists the actual and effective default policy values. Default values are also listed on the policy’s property page.
Server Type or GPO | Default Value |
---|---|
Default Domain Policy |
Enabled |
Default Domain Controller Policy |
Not defined |
Stand-Alone Server Default Settings |
Not applicable |
DC Effective Default Settings |
Enabled |
Member Server Effective Default Settings |
Not applicable |
Client Computer Effective Default Settings |
Not applicable |