No announcement yet.

Account option flags in User Properties

  • Filter
  • Time
  • Show
Clear All
new posts

  • Account option flags in User Properties


    I am using Windows server 2008, In AD User Properities(DSA.MSC) under Account tab we have a "Account Options" which defines the UserAccountControl Attributes...

    I am having lot of doubts in this Account option flags...

    1) Account is sensitive and cant be delegated:

    I checked this option for a acc, But the acc is still able to give delegation for several OU, and this acc can be changed by a Delected Acc...Then what is the purpose of this option

    2) I can enable all DES,AES256,AES512 encryption types...If i apply which one would be applied?

    3) Do not use Kerberos preauthentication

    If i enable this option then no need of DES,AES256,AES512 encryption types but still i can sellect or deselect all these types...

    Please Clarify my Doubts...

  • #2
    Re: Account option flags in User Properties

    Is there any relation between the "delegation tab of computer properties" and "account is sensitive and can not be delegated" account option in user properties???


    • #3
      Re: Account option flags in User Properties

      navrajan I am really confused on your question and I start looking at my server to understand. Can you please provide more detail as is it a DC/DNS/ etc.. screen shots would be ideal.