Your domain controllers run Windows Server 2019. Security wants to prevent helpdesk admin accounts from authenticating with NTLM, block credential delegation, and limit Kerberos to strong encryption while maintaining normal sign-in. What should you do for these helpdesk accounts? (Choose two)
Choose an answer
Tap an option to check your answer.
Correct answer: Add the accounts to the Protected Users security group., Enable AES128_HMAC_SHA1 and AES256_HMAC_SHA1 encryption types on the accounts and require a password change..
Why this is the answer
Adding accounts to the Protected Users security group automatically prevents NTLM authentication, blocks credential delegation (constrained or unconstrained), and configures Kerberos to use only AES encryption. This directly addresses the requirements for NTLM restriction, delegation prevention, and strong Kerberos encryption. Enabling AES128HMACSHA1 and AES256HMACSHA1 encryption types on the accounts and requiring a password change ensures these strong Kerberos encryption types are used and updates any cached keys. Enabling 'Account is sensitive and cannot be delegated' only prevents delegation, not NTLM or Kerberos encryption. Configuring a domain GPO to 'Deny all' NTLM would affect all users, not just helpdesk. Disabling Kerberos RC4 support on domain controllers by GPO would impact all users and might break compatibility for older clients, and doesn't explicitly enforce AES for the specific accounts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed