Environment: SQL Server Always On AG on top of FCI, Windows Server cluster, domain-joined nodes.
Problem: Connections to the AG listener always fall back to NTLM, but only when connecting from the cluster nodes themselves. From any other machine on the network, Kerberos works correctly.
Symptoms:
-
sys.dm_exec_connections.auth_scheme returns NTLM on listener connections from cluster nodes
-
klist shows no ticket generated after a SQL connection attempt
- No Kerberos Event ID 4769 on the Domain Controller during the connection attempt
-
klist get MSSQLSvc/<listener-fqdn>:<port> does return a valid AES-256 ticket when requested manually
- After a SQL connection, the ticket does not appear in
klist — SSPI never requests it
What was already ruled out:
- DNS resolution — correct
- Duplicate SPNs (
setspn -X -F) — none found
-
DisableLoopbackCheck and BackConnectionHostNames — already set, no effect
- AD computer account for the listener VCO — enabled
- Trust relationship on cluster nodes — healthy
Current finding: The ticket can be obtained manually, meaning the SPN is registered and the KDC responds correctly. However, the SQL driver / SSPI never requests the ticket during connection — it goes directly to NTLM without contacting the KDC at all.
Question: Has anyone seen SSPI silently bypass Kerberos on AG listener connections from cluster nodes, specifically in an AG-over-FCI topology? Any way to force the driver to use a specific SPN or disable name canonicalization for this target?NOTE : I suppose the problem begins after April update...because it was running for a long period