Glossary
Protected Users
Protected Users is a built-in AD security group that forces stronger, non-cacheable authentication for its members to limit credential theft.
Protected Users is a global security group introduced with Windows Server 2012 R2; its domain-controller-side protections require the Windows Server 2012 R2 domain functional level. Membership triggers non-configurable protections on both the client and the domain controller: members cannot authenticate with NTLM, Digest or CredSSP delegation, their credentials are not cached for offline sign-in, Kerberos pre-authentication cannot use DES or RC4, their tickets cannot be delegated (constrained or unconstrained), and their TGT lifetime is capped at four hours rather than the default ten.
It matters because it removes several of the easiest credential-theft paths — NTLM hashes lying in memory, cached logons, and delegation abuse — for exactly the accounts attackers want most. Add human Tier 0 and Tier 1 administrators to it, but test first: service accounts, computer accounts and anything that still depends on NTLM or delegation will break. Never add every privileged account at once; keep a break-glass account outside the group and roll out in waves while watching failed logon events on the domain controllers.