Adding a user account to the protected users group causes the protected user to not be able to log into the CA client.
The following error message can be seen in the client log file:
This type of error typically indicates that there is some issue preventing the protected account from being able to use Kerberos in the environment.
Use the setspn utility by running the following command from a DC:
setspn -A NPRepository4(%CA_InstallationName%)/%Coordinator_FQDN% %Coordinator_NetBiosName%
Where:
Example:
setspn -A NPRepository4(DEFAULT)/myhost.domain.local myhost