Can you set a different default msDS-SupportedEncryptionTypes attribute value during join?
During the domain join the msDS-SupportedEncryptionTypes attribute for the computer object will be set to the following value by default:
This indicates support for:
RC4_HMAC_MD5, AES128_CTS_HMAC_SHA1_96 and AES256_CTS_HMAC_SHA1_96.
With Disable Resource Group Compression bit
In some circumstances you may wish to change the default.