I recently disabled #NTLM authentication in my #Windows #Domain, testing if i can rely only on #Kerberos.
Well, i had to revert it. PCs failed login after overnight hibernation (workstation domain trust failing). Couldn't add new #WS2025 domain controller. Couldn't even make it join the domain.
Looks like user authentication works fine with Kerberos, but computer principal authentication/ticket renewal doesn't.
#homelab #infosec