Hi,
If the user account is member of protected group, only kerberos is supported. NTLM is not supported.
To ensure that kerberos authentication is working fine you should check:
- Only the FQDN is supported to access via remote desktop because when you use IP adress, you will use NTLM for authentication
- Check SPN settings, if the server has many FQDN , you should add same SPNs for each FQDN
- Check if network flow is opened between client machine and domain controller for kerberos authentication
Please don't forget to mark helpful reply as answer