Test-MtAdKrbtgtPasswordLastSet
SYNOPSIS
Checks when the KRBTGT account password was last set.
SYNTAX
Test-MtAdKrbtgtPasswordLastSet [-ProgressAction <ActionPreference>] [<CommonParameters>]
DESCRIPTION
The KRBTGT account is a critical service account used by the Key Distribution Center (KDC) service for Kerberos authentication. Its password is used to encrypt and sign all Kerberos tickets. This test retrieves the date when the KRBTGT password was last changed.
Security Best Practice:
- KRBTGT password should be rotated at least every 180 days
- If domain compromise is suspected, rotate the password twice (with 10+ hours between)
- The account should remain disabled (standard UAC = 514)
EXAMPLES
EXAMPLE 1
Test-MtAdKrbtgtPasswordLastSet
Returns $true if KRBTGT account data is accessible.
PARAMETERS
-ProgressAction
Determines how PowerShell responds to progress updates generated by a script, cmdlet, or provider, such as the progress bars generated by Write-Progress.
Type: ActionPreference
Parameter Sets: (All)
Aliases: proga
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
CommonParameters
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
INPUTS
OUTPUTS
System.Boolean
NOTES
RELATED LINKS
https://maester.dev/docs/commands/Test-MtAdKrbtgtPasswordLastSet