Skip to main content
AD Academy
Advanced Attacks and Modern Defenses
Advanced12 minLast updated: Topic 1 of 4

AS-REP Roasting

Exploiting accounts without Pre-Authentication.

Not read

What you will learn here

  • What Pre-Authentication is
  • How attackers abuse accounts without it
  • How to find and fix such accounts

When an account is flagged 'Do not require preauthentication', anyone can request an AS-REP for it and receive a block encrypted with the user's password — and crack it Offline.

# Locate Vulnerable Accounts
Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true} -Properties DoesNotRequirePreAuth

# Fix
Set-ADAccountControl -Identity svc_legacy -DoesNotRequirePreAuth $false
powershell
Architecture and Theory — Under the Hood

When 'Do not require preauthentication' is checked, the DC returns an AS-REP encrypted with the user's password to anyone who asks — without any prior authentication. This allows for offline cracking even without a domain account.

Practical Configuration (PowerShell / GUI)
# Who turned on the flag and when - checking write permissions on userAccountControl
Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true} -Properties whenChanged,LastLogonDate,MemberOf |
  Select Name,whenChanged,LastLogonDate

# Turning off the flag for all accounts at once
Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true} |
  ForEach-Object { Set-ADAccountControl $_ -DoesNotRequirePreAuth $false }

# Hardening: Forcing AES and monitoring for re-enabling of the flag
Set-ADUser user1 -KerberosEncryptionType AES128,AES256
powershell
Real-world Scenarios in the Organization
  • The flag is usually set due to old integration with Linux/Java — it's necessary to check if it's still relevant.
Troubleshooting and Diagnosis
  • Event 4768 with Pre-Authentication Type 0 = AS-REP request without preauth.
Glossary and Quick Command Line
  • AS-REP — The KDC's first reply.
  • UAC flag 0x400000 = DONT_REQ_PREAUTH.

Check yourself

What does AS-REP Roasting enable?

Was this page helpful?