Setting user object attributes msDS-SupportedEncryptionTypes and userAccountControl using the cmdlets Get-QADUser and Set-QADUser to enable encryption methods work with Kerberos
set-Location c:\
Add-PSSnapin Quest.ActiveRoles.ADManagement
Get-PSsnapin
Set-QADPSSnapinSettings -DefaultSizeLimit 0
Get-Command Get-QAD*
Get-QADUser -sl 0 -IncludeAllProperties -SerializeValues
PS C:\> Get-QADUser spider001 -sl 0 -IncludeAllProperties -SerializeValues > C:\User.txt
PS C:\> Get-QADUser spider001 -sl 0 -IncludedProperties userAccountControl,’msDS-SupportedEncryptionTypes’ | Format-Tabl
e name,userAccountControl,’msDS-SupportedEncryptionTypes’
Name userAccountControl msDS-SupportedEncryptionTypes
spider001 2163200 31
PS C:\> Set-QADUser spider002 -objectAttributes @{‘msDS-SupportedEncryptionTypes’=31}
PS C:\> Set-QADUser spider002 -objectAttributes @{‘userAccountControl’=2163200}
PS C:\> Set-QADUser spider003 -objectAttributes @{‘msDS-SupportedEncryptionTypes’=31}
PS C:\> Set-QADUser spider003 -objectAttributes @{‘userAccountControl’=2163200}
PS C:\> Get-QADUser spider002 -sl 0 -IncludedProperties userAccountControl,’msDS-SupportedEncryptionTypes’ | Format-Tabl
e name,userAccountControl,’msDS-SupportedEncryptionTypes’
Name userAccountControl msDS-SupportedEncryptionTypes
spider002 2163200 31
