tto / docs / windows / spn downgrade protection

Windows Server logs LSA (LsaSrv) Error Event ID 40970

HKLM\SYSTEM\CurrentControlSet\Control\LSA
Reg_DWORD = SpnDowngradeProtection
Value = 0

Installing the January 11, 2022 Windows updates and later Windows updates may cause authentication to fail for 3-part SPNs where Kerberos authentication is not successful. For these environments, it is likely that Kerberos authentication for 3-part SPNs has not worked for some time.

more info: KB5011233