Policy overview

Key metadata and intent for this policy.

ClassComputer
CategorySystem > Kerberos
Supported onAt least Windows 11 Version 24H2

Supported OS tags: Windows11

This policy setting enables or disables delegated managed service account logons for this machine. If you enable this policy setting, delegated managed service account logons will be supported by the Kerberos client. Note that this policy has certain prerequites. The prerequisites and the directions to create a new delegated managed service account can be found at https://go.microsoft.com/fwlink/?linkid=2250379. If you disable or do not configure this policy setting, delegated managed service account logons will not be supported.

Internal name
DelegatedMSAEnabled
Policy ID
ad7632f4067b
Elements
1

Registry values

How enabled and disabled states update the registry.

Registry locationTypeEnabled valueDisabled value
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters\DelegatedMSAEnabledREG_DWORD
1
0

Policy elements

Inputs and configuration options exposed by this policy.

ElementTypeRegistry mappingConstraints & behavior
Realms:
ID DmsaRealmsList
list
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters\DmsaRealms
Type REG_MULTI_SZ
None

Other policies in this category

Explore related policies at the same level.

View all policies in this category