Define host name-to-Kerberos realm mappings
Jump to overview

Policy overview

Key metadata and intent for this policy.

Computer
Category
System > Kerberos
Supported on
At least Windows Vista

Supported OS tags: Windows10, Windows10RT, Windows11, Windows7, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2008, WindowsServer2012, WindowsServer2012R2, WindowsServer2016, WindowsVista

This policy setting allows you to specify which DNS host names and which DNS suffixes are mapped to a Kerberos realm. If you enable this policy setting, you can view and change the list of DNS host names and DNS suffixes mapped to a Kerberos realm as defined by Group Policy. To view the list of mappings, enable the policy setting and then click the Show button. To add a mapping, enable the policy setting, note the syntax, and then click Show. In the Show Contents dialog box in the Value Name column, type a realm name. In the Value column, type the list of DNS host names and DNS suffixes using the appropriate syntax format. To remove a mapping from the list, click the mapping entry to be removed, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters. If you disable this policy setting, the host name-to-Kerberos realm mappings list defined by Group Policy is deleted. If you do not configure this policy setting, the system uses the host name-to-Kerberos realm mappings that are defined in the local registry, if they exist.

Internal name
HostToRealm
Policy ID
7a447707fba5
Elements
1

Registry values

How enabled and disabled states update the registry.

No explicit registry values are set for enabled or disabled states.

Policy elements

Inputs and configuration options exposed by this policy.

ScopeElementTypeRegistry mappingConstraints & behaviorCopy
Computer
Define host name-to-realm mappings:
ID hosttorealm
list
Path
Software\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\domain_realm
Value name
domain_realm_Enabled
Type
REG_MULTI_SZ
List: additive, explicit value
Define host name-to-realm mappings:
Computer · Type list
Registry mapping
Path
Software\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\domain_realm
Value name
domain_realm_Enabled
Type
REG_MULTI_SZ
Details
List: additive, explicit value