Support compound authentication
Jump to overview

Policy overview

Key metadata and intent for this policy.

Computer
Category
System > Kerberos
Supported on
At least Windows Server 2012, Windows 8 or Windows RT

Supported OS tags: Windows10, Windows10RT, Windows11, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2012, WindowsServer2012R2, WindowsServer2016

This policy setting controls configuring the device's Active Directory account for compound authentication. Support for providing compound authentication which is used for access control will require enough domain controllers in the resource account domains to support the requests. The Domain Administrator must configure the policy "Support Dynamic Access Control and Kerberos armoring" on all the domain controllers to support this policy. If you enable this policy setting, the device's Active Directory account will be configured for compound authentication by the following options: Never: Compound authentication is never provided for this computer account. Automatic: Compound authentication is provided for this computer account when one or more applications are configured for Dynamic Access Control. Always: Compound authentication is always provided for this computer account. If you disable this policy setting, Never will be used. If you do not configure this policy setting, Automatic will be used.

Internal name
ServerAcceptsCompound
Policy ID
648b25b7e6ea
Elements
1

Registry values

How enabled and disabled states update the registry.

ScopeRegistry locationTypeEnabled valueDisabled valueCopy
Computer
Path
Software\Policies\Microsoft\Netlogon\Parameters
Value name
CompoundIdDisabled
REG_DWORD
HKLM
0
HKLM
1
Registry location
Type REG_DWORD · Computer
Path
Software\Policies\Microsoft\Netlogon\Parameters
Value name
CompoundIdDisabled
Hive
HKLM
Enabled value
0
Disabled value
1

Policy elements

Inputs and configuration options exposed by this policy.

ScopeElementTypeRegistry mappingConstraints & behaviorCopy
Computer
Support authorization with client device information:
ID CompoundIdEnabled
enum
Path
Software\Policies\Microsoft\Netlogon\Parameters
Value name
CompoundIdEnabled
Type
REG_DWORD
Options: Never (0), Automatic (1), Always (2)
Support authorization with client device information:
Computer · Type enum
Registry mapping
Path
Software\Policies\Microsoft\Netlogon\Parameters
Value name
CompoundIdEnabled
Type
REG_DWORD
Details
Options: Never (0), Automatic (1), Always (2)