Before you can use Access Rules, the following conditions must be fulfilled:
- 
Claim support must be enabled in your Active Directory domain. For details, review the topic Enabling claim support. 
- 
For Access Rules to use device claims, Group Policy setting Computer Configuration > Policies > Administrative Templates > System > Kerberos > Support Compound Authentication with the Always option must be enabled on the client computers, in addition to the Kerberos client support for claims, compound authentication and Kerberos armoring setting (see Client computer). 
- 
The Active Roles Administration Service must be installed on a computer running Windows Server 2016 or a later version of the Windows Server operating system. 
- 
The Active Roles Administration Service that performs authorization using Access Rules must be installed in the Active Directory forest where the user account of the authorizing user is defined and in which the claim types used by the Access Rules are created. Active Roles does not support the use of Access Rules for cross-forest authorization. 
- 
Group Policy setting Computer Configuration > Policies > Administrative Templates > System > Kerberos > Kerberos client support for claims, compound authentication and Kerberos armoring must be enabled on the computer running the Administration Service. 
- 
The Administration Service must be configured to support Kerberos authentication. 
