Cannot join with service account after enabling a group policy to disable RC4 and enable AES128 and 256 receiving error: KRB5KDC_ERR_ETYPE_NOSUPP (-1765328370): KDC has no support for encryption type.
The following GPO was configured: Network Security: Configure encryption types allowed for Kerberos” setting with RC4 disabled, AES128/256 enabled.
We changed MsDS-SupportedEncryptionTypes set to 31 from 18 on all domain controller servers for the AD computer object for the client and enabled AES encryption type in the /opt/quest/vas/vas.conf . Once the encryption type was 31, then join command started to fail with unsupported encryption type.
In Windows Event Viewer under Security, EventID: 4769 is seen.
1 - Enable the account for AES
We needed to Uncheck Use Kerberos DES encryption types for this account on the account.
3 - Ensure all domains and trusts support AES. For instruction go to KB186646
4 - Reset the password of the service account used to do the join after the encryption type has been changed.