question

StevenButcher-0447 avatar image
0 Votes"
StevenButcher-0447 asked GaryReynolds answered

After migrating accounts using ADMT and PES users get the following error when trying to change passwords "The encryption type requested is not supported by the KDC"

Migrating users from a 2008R2 AD domain to a 2019 AD domain, both domains have CIS hardening applied to them and have limited the encryption types to AES128_HMAC_SHA1, AES256_HMAC_SHA1, and "Future encryption types".

When a migrated user attempts to change the expired password (over RDP) they get the following error "The encryption type requested is not supported by the KDC"

windows-active-directory
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thameur-BOURBITA avatar image
0 Votes"
Thameur-BOURBITA answered

Hi,

Did you try perform the first reset by a administrator?

It's know behavior , because ADMT is unable to identify if the encryption type on target domain domain.

Below a thread talking about the same issue:

Error "The encryption type requested is not supported by the KDC" when changing passwords on Accounts migrated with ADMT



Please don't forget to mark helpful reply as answer

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

GaryReynolds avatar image
0 Votes"
GaryReynolds answered

Hi

I would also check the msds-supportedencryptiontypes attribute of the migrated user accounts in case it's been set and the value is not compatible with your domain hardening.

Gary.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.