During a county AD review, several users are found with Kerberos pre-authentication disabled. What does that configuration class represent?
Select an answer to reveal the explanation.
Short Explanation
Pre-auth is like showing ID before you get the ticket. Turn it off and the ticket process gets a lot friendlier for the wrong people. Flag users missing pre-auth as a real exposure class.
Full Explanation
Kerberos pre-authentication normally requires proof of identity before certain ticket material is issued. Accounts with pre-authentication disabled are a known misconfiguration class tied to AS-REP-related exposure themes. The setting does not imply smart-card enforcement or forest-wide NTLM disablement. Testers should report it as identity hygiene risk without needing an exploit walkthrough in the question context.