John W. Sopko Jr. wrote: > The afs/cell.name service principal only belongs to the standard > "domain users" group, (I think this is standard), and I do not believe > the afs service principal will need to be in any other groups. Thus > the PAC data for the service principal should not be growing. And as > long as it is less then 12k this should not cause a problem, > sound correct? Thanks.
The PAC doesn't contain the authorization data for the service. It contains the authorization data for the user.
smime.p7s
Description: S/MIME Cryptographic Signature
