There should be no reason why clicking the option on the user in AD to make it use AES wouldn't work, especially if the implementation of Kerberos being used is 100% standard and implemented correctly. This has nothing to do with the etype used for service tickets.
↧