I simply changed your command to use "-kerberos enabled"
That allows the command to modify the SPN rather than trying to disable it *and* modify the SPN at the same time.
Run the 2nd command like this:
nyn001c1::*> vserver nfs kerberos interface modify -vserver nyn001f1 -lif nyn001f1_data2 -kerberos disabled
It doesn't like when you specify the URI with the disable.
For admin/password, perhaps try the cluster admin/password