Dynamic Access Control: Settings for "Device Claims"

InfoTechdude 156 Reputation points
2020-09-01T16:55:26.763+00:00

Hi,

I try to combine together all requrements for "Device Claims". From what I could see 1) There have to be Windows 8 not below 2)Kerberos setting in Group policy

21906-dac.jpg

Plus I presume DC running 2012 +. Are there any other requirements? While KDC GP must be run on DC, Kerberos GP - must be on client? Can somebody clarify this one and confirm the above ones? Thank you!

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,774 questions
{count} votes

Accepted answer
  1. Fan Fan 15,321 Reputation points Microsoft Vendor
    2020-09-02T02:48:54.74+00:00

    Thanks for posting here!
    Based on my research, when we try to set the device claims, and user claims we need to set the GPOs = KDC GP must be run on DC, Kerberos GP - must be on clients.
    As you said ,Dynamic Access Control is not supported in Windows operating systems prior to Windows Server 2012 and Windows 8. When Dynamic Access Control is configured in environments with supported and non-supported versions of Windows, only the supported versions will implement the changes.
    For more information about the requirements , you can refer to the following link:
    https://video2.skills-academy.com/en-us/windows/security/identity-protection/access-control/dynamic-access-control

    Best Regards,


0 additional answers

Sort by: Most helpful