If I am not mistaken Kerberos authentication works off the SPN that the SQL Server service creates in the AD domain, or that is created manually. If the SPN is not found when authenticating a login it switches to NTLM. You would need to ensure the SPN is not found or does not exist. The service account for SQL Server would need to be blocked from creating an SPN if it is not already (if the SPN was created manually).