不能对始终在 Windows 中筛选掉的组使用 Active Directory 影子主体组功能

应用对象
Windows Server 2012 R2 Datacenter Windows Server 2012 R2 Standard Windows Server 2012 R2 Essentials Windows Server 2012 R2 Foundation Windows 8.1 Enterprise Windows 8.1 Pro Windows 8.1

症状

Windows Server 2012 R2 域控制器接收来自林信任边界的传入 Kerberos 票证授予票证 (TGT) ,将始终从 PAC 中筛选出表示其域中具有低数量 RID 的已知帐户的所有组 SID,例如域中“域管理员”组的 SID。 当域控制器位于另一个林中且位于 Windows Server 2016 Technical Preview 功能级别,并且该林包含一个具有表示已知帐户的 SID 的影子主体组时,会出现此问题。

解决方法

若要解决此问题,请安装 Windows RT 8.1、Windows 8.1 和 Windows Server 2012 R2 的 2016 年 5 月更新汇总

注意 此更新将新的信任标志TRUST_ATTRIBUTE_PIM_TRUST添加到 R2 域控制器Windows Server 2012。 票证使这些域控制器能够识别来自堡垒林的 Kerberos 票证。 安装此更新后,域控制器将允许在其系统容器中受信任域对象的 trustAttributes 属性上设置此标志,域控制器在执行 SID 筛选时将解释组。

状态

Microsoft 已确认在 "适用于" 部分中所列的 Microsoft 产品中存在问题。

参考资料

了解 Microsoft 用于描述软件更新的术语