---
title: DevicePKInitBehavior enum | Wartiva GraphQL API
description: GPO policy: "Support device authentication using certificate" under Computer Configuration > Administrative Templates > System > Kerberos.
url: https://wartiva.com/api-docs/types/device-pkinit-behavior.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL enum

# `DevicePKInitBehavior` enum

GPO policy: "Support device authentication using certificate" under Computer Configuration > Administrative Templates > System > Kerberos. Controls how domain-joined devices use public key (PKINIT) certificate-based authentication for initial Kerberos authentication (RFC 4556). Registry: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\kerberos\parameters:DevicePKInitBehavior (REG_DWORD). Requires DevicePKInitEnabled=1 at the same registry path to take effect. Reference: [Policy CSP - Kerberos](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-kerberos#devicepkinitbehavior)

## Values

| Enum Value | Description |
|---|---|
| `AUTOMATIC` | Automatic (registry value 0). The device attempts to authenticate using its certificate (PKINIT). If a domain controller that supports device certificate authentication cannot be found, the device falls back to password-based authentication. |
| `FORCE` | Force (registry value 1). The device always uses certificate-based (PKINIT) Kerberos authentication. If a domain controller supporting device certificate authentication cannot be reached, authentication fails entirely. |

## Used by

- [`ComputerAdministrativeTemplates`](https://wartiva.com/api-docs/types/computer-administrative-templates.html) type: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.

## Example

### Example

```json
"AUTOMATIC"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
