Skip to main content
Version: 2.1.1-preview

Test-MtAdKrbtgtPasswordLastSet

SYNOPSIS

Checks when the KRBTGT account password was last set.

SYNTAX

Test-MtAdKrbtgtPasswordLastSet [-ProgressAction <ActionPreference>] [<CommonParameters>]

DESCRIPTION

The KRBTGT account is a critical service account used by the Key Distribution Center (KDC) service for Kerberos authentication. Its password is used to encrypt and sign all Kerberos tickets. This test retrieves the date when the KRBTGT password was last changed.

Security Best Practice:

  • KRBTGT password should be rotated at least every 180 days
  • If domain compromise is suspected, rotate the password twice (with 10+ hours between)
  • The account should remain disabled (standard UAC = 514)

EXAMPLES

EXAMPLE 1

Test-MtAdKrbtgtPasswordLastSet

Returns $true if KRBTGT account data is accessible.

PARAMETERS

-ProgressAction

Determines how PowerShell responds to progress updates generated by a script, cmdlet, or provider, such as the progress bars generated by Write-Progress.

Type: ActionPreference
Parameter Sets: (All)
Aliases: proga

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

OUTPUTS

System.Boolean

NOTES

https://maester.dev/docs/commands/Test-MtAdKrbtgtPasswordLastSet