When an account is flagged 'Do not require preauthentication', anyone can request an AS-REP for it and receive a block encrypted with the user's password — and crack it Offline.
# Locate Vulnerable Accounts
Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true} -Properties DoesNotRequirePreAuth
# Fix
Set-ADAccountControl -Identity svc_legacy -DoesNotRequirePreAuth $falsepowershellArchitecture and Theory — Under the Hood
When 'Do not require preauthentication' is checked, the DC returns an AS-REP encrypted with the user's password to anyone who asks — without any prior authentication. This allows for offline cracking even without a domain account.
Practical Configuration (PowerShell / GUI)
# Who turned on the flag and when - checking write permissions on userAccountControl
Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true} -Properties whenChanged,LastLogonDate,MemberOf |
Select Name,whenChanged,LastLogonDate
# Turning off the flag for all accounts at once
Get-ADUser -Filter {DoesNotRequirePreAuth -eq $true} |
ForEach-Object { Set-ADAccountControl $_ -DoesNotRequirePreAuth $false }
# Hardening: Forcing AES and monitoring for re-enabling of the flag
Set-ADUser user1 -KerberosEncryptionType AES128,AES256powershellReal-world Scenarios in the Organization
- The flag is usually set due to old integration with Linux/Java — it's necessary to check if it's still relevant.
Troubleshooting and Diagnosis
- Event 4768 with Pre-Authentication Type 0 = AS-REP request without preauth.
Glossary and Quick Command Line
- AS-REP — The KDC's first reply.
- UAC flag 0x400000 = DONT_REQ_PREAUTH.