Solved

Windows 2012 Dynamic Access Control, What comptuer claim type supports domain membership?

Posted on 2014-12-03
1
293 Views
Last Modified: 2014-12-05
I like to limit access to share by AD domain membership so that only AD domain computer can access the share. What claim type is usually used for this ?

I was trying to use 'objectSID'  which contains domain SID, but in Clain Type to select, it doesn't exist.
0
Comment
Question by:crcsupport
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 80

Accepted Solution

by:
David Johnson, CD, MVP earned 500 total points
ID: 40479393
Device claims are supported in Windows 8+ clients only.
Open Group Policy Management and navigate to Domain.
Right-click the Default Domain Controllers Policy and select Edit.
In the Group Policy Management Editor window, navigate to Computer Configuration, > Administrative Templates, System, and Kerberos.
Select Enable KDC support for claims, compound authentication, and Kerberos armoring.
Click OK. Close Group Policy Management.

http://bit.ly/15Pj4Ix
0

Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
Learn how to PXE Boot both BIOS & UEFI machines with DHCP Policies and Custom Vendor Classes
This tutorial will walk an individual through the process of installing of Data Protection Manager on a server running Windows Server 2012 R2, including the prerequisites. Microsoft .Net 3.5 is required. To install this feature, go to Server Manager…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question