ADMX Guide

Disable CNAME lookup when negotiating Kerberos authentication

Category

Computer Configuration > Administrative Templates > Microsoft Edge > HTTP authentication

Scope

Both

Registry Key

HKLM\Software\Policies\Microsoft\Edge

Description

Determines whether the generated Kerberos SPN is based on the canonical DNS name (CNAME) or on the original name entered. If you enable this policy, CNAME lookup is skipped and the server name (as entered) is used. If you disable this policy or don't configure it, the canonical name of the server is used. This is determined through CNAME lookup.