The Protected Users security group was introduced with Windows Server 2012 R2 and continued in Windows Server 2016. This group was developed to provide better protection for high privileged accounts from credential theft attacks. Members of this group have non-configurable protection applied. In order to use the Protected Users group, PDC should be running with a minimum of Windows Server 2012 R2 and the client computers that member of this group log into should be running with a minimum of Windows 8.1 or Windows 2012 R2.
If a member of this group logs into Windows 8.1, Windows Server 2012 R2, Windows 10, or Windows Server 2016, we can expect the following:
- Members of this group cannot use NTLM, digest authentication, ...