AD-KRBTGT-01 - KRBTGT password last set should be retrievable
Overviewβ
- The KRBTGT account is the most critical service account in Active Directory. It is used by the Key Distribution Center (KDC) service to encrypt and sign all Kerberos tickets within the domain. If this account is compromised, an attacker can forge Kerberos tickets (Golden Tickets) that grant unlimited access to any resource in the domain.
Security Risks:
- Golden Ticket Attacks: Compromised KRBTGT password allows attackers to forge TGTs for any user
- Persistent Access: Attackers can maintain access even after password changes if they create forged tickets with long lifetimes
- Domain-Wide Impact: A single compromised KRBTGT affects the entire domain
Security Recommendationβ
-
Rotate KRBTGT password regularly:
- At least every 180 days (twice per year)
- Immediately if compromise is suspected
-
If compromise is suspected:
- Rotate the password twice with at least 10 hours between rotations
- First rotation invalidates existing forged tickets
- Second rotation ensures any tickets created between rotations are also invalidated
-
Monitor for anomalies:
- Unexpected password changes
- Unusual authentication patterns
- KRBTGT account being enabled (it should always be disabled)
How the Test Worksβ
This test retrieves the KRBTGT account from Active Directory and checks:
- Password last set date
- Days since last password change
- Account status (should be disabled)
Related Testsβ
Test-MtAdKrbtgtLastLogon- Verifies KRBTGT has no interactive logonsTest-MtAdKrbtgtNonStandardUacCount- Validates KRBTGT has standard UAC settings
Related linksβ
- Microsoft Defender for Identity: Change password for krbtgt account
- ANSSI Active Directory checkpoints: Krbtgt account password unchanged for more than a year
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-KRBTGT-01 |
| Severity | High |
| Suite | Active Directory |
| Category | AD.Security |
| PowerShell test | Test-MtAdKrbtgtPasswordLastSet |
| Tags | AD, AD-KRBTGT-01, AD.Security |
Sourceβ
- Pester test:
tests/ad/security/Test-MtAdKrbtgtPasswordLastSet.Tests.ps1 - PowerShell source:
powershell/public/ad/security/Test-MtAdKrbtgtPasswordLastSet.ps1


