Kavinda Munasinghe’s Blog Rotating Header Image

Overweight Kerberos tokens

Does your active directory user account belong to too many groups?  What I mean by “too many groups” here varies, but the limit is approximately 120 groups if you’re on Windows 2000 (SP2) or Windows Server 2003 and even less if you’re still on Windows 2000 (original released version).

Why you belong to that many groups is another question, but in-case you do belong to that many groups and also are seeing symptoms like

Group policy not being applied
Validated to use network resources fails
IIS configured for Windows authentication fails

You could be suffering from “Token Bloat!” Read more at Mark Minasi’s Windows Networking Tech Page October 2006

2 Comments

  1. Merill says:

    Oops, Minasi’s link is broken

  2. Kavinda says:

    Fixed the link. Thanks Buddy.

Leave a Reply