Skip to main content

DisableAuthNegotiateCnameLookup

Disable CNAME lookup when negotiating Kerberos authentication - DisableAuthNegotiateCnameLookup​

Setting the policy to Enabled skips CNAME lookup. The server name is used as entered when generating the Kerberos SPN.

Setting the policy to Disabled or leaving it unset means CNAME lookup determines the canonical name of the server when generating the Kerberos SPN.

  • True = Disable CNAME lookup during Kerberos authentication
  • False = Use CNAME lookup during Kerberos authentication

Data Type:

Boolean

Supported features:

  • Dynamic Policy Refresh: True
  • Per Profile: False