Information
Kerberos policy settings determine Kerberos-related attributes of domain user accounts, such as the Maximum lifetime for user ticket and Enforce user logon restrictions settings. However, these policy settings are not used for stand-alone client computers because they do not participate in a domain. If you disable this policy setting, users could receive session tickets for services that they no longer have the right to use because the right was removed after they logged on.
Solution
Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-
Computer Configuration\Windows Settings\Security Settings\Account Policies\Kerberos Policy\Enforce user logon restrictions
Impact- None. This is the default configuration.