Did anyone one get Kerberos authentication with ZCM 11.2.1 working when the ZCM server (Windows 2008 R2) is a member of the Active Directory Domain?

Is this even supported?

To me, it looks like it couldn't work since the ZCM server's computer account already has the SPN HOST/Server-Name registered so this SPN cannot be used on another (user) account for the Keytab generation?

If there's anyone out there with a Domain-joined ZCM server and Kerberos authentication working, I would be REALLY glad to read about your experiences!