TYB
For Windows users.
When the FullSecureChannelProtection registry key is deployed, DCs will be in enforcement mode. This setting requires that all devices using Netlogon secure channel either:
Use secure RPC.
Are allowed in "Domain controller: Allow vulnerable Netlogon secure channel connections" group policy.
https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc
Run registry editor as administrator. Navigate to:
Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters
Find or create key "FullSecureChannelProtection"
Set value to: 1
Restart machine.