GPO policy: "Support device authentication using certificate" under Computer Configuration > Administrative Templates > System > Kerberos. Controls how domain-joined devices use public key (PKINIT) certificate-based authentication for initial Kerberos authentication (RFC 4556). Registry: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\kerberos\parameters:DevicePKInitBehavior (REG_DWORD). Requires DevicePKInitEnabled=1 at the same registry path to take effect. Reference: Policy CSP - Kerberos
Values
| Enum Value | Description |
|---|---|
|
|
Automatic (registry value 0). The device attempts to authenticate using its certificate (PKINIT). If a domain controller that supports device certificate authentication cannot be found, the device falls back to password-based authentication. |
|
|
Force (registry value 1). The device always uses certificate-based (PKINIT) Kerberos authentication. If a domain controller supporting device certificate authentication cannot be reached, authentication fails entirely. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"AUTOMATIC"