I have a weird situation. My Win 2016 servers were ruined by AD group polices.
IIS 10 have started to throw 403 error after automatic AD group policy update at the moment X. Beforehand remote party called us with no problems via https with client certificates.
I have a backup before the moment X and after the moment X, but I cannot pinpoint the setting that was changed by AD GP.
I have a setup paper with all settings needed to setup our web service from scratch. I have checked them all against victim servers. Nothing changed. At every level Anonymous Auth is enabled and SSL Settings->Client certificates->Accept.
Our admins swear they have changed nothing. IIS logs show nothing after moment X.
Any ideas where to look at? Registry? Metabase?
Exact error returned to the caller as per SOAP e2e trace logs:
The HTTP request was forbidden with client authentication scheme 'Anonymous'.[The remote server returned an error: (403) Forbidden.]