Unable to apply content filtering policy for domain groups when using the Cloud SWG Auth Connector.
Error: Failed S4U s4uLogin for user: 'domain\user'; status=-#####:########:The encryption type requested is not supported by the KDC.
The Auth Connector is unable to authenticate with the Domain Controller (KDC) due to a Windows group policy that restricts the client machine (running BCCA) to only use certain Kerberos encryption types such as AES-128 and AES-256 to talk to the domain controller(s).
See Microsoft blog: Windows Configurations for Kerberos Supported Encryption Type for more information.