We recently changed the Group Policy setting "Network security: Configure encryption types allowed for Kerberos" to only include AES-128, AES-256, and Future Encryption types, removing the old selection that had RC4 enabled. The domain is a 2008 R2 functional level with one 12R2 DC and one 16 DC. Now the DCs are failing to replicate. I re-enabled RC4 in the GPO, but both of our DCs fail to update to the new GPO, with an error saying they can not authenticate.
Any ideas? The network is pretty much down for the users at the moment.