(Service Principal Name) is the unique name of a service in , for example MSSQLSvc/sql01.lab.local:1433. uses it to know which service to issue a ticket for.
# Display SPN of an account
setspn -L LAB\svc_sql
# Search for user accounts with SPN (Kerberoasting targets)
Get-ADUser -Filter {ServicePrincipalName -like "*"} -Properties ServicePrincipalName
# Check if LDAPS is active (port 636)
Test-NetConnection dc01.lab.local -Port 636powershellArchitecture and Theory — Under the Hood
links a service name (HTTP/web01.corp.com) to the account running it. Without SPN — no , falls back to . LDAPS = over TLS on port 636.
Practical Configuration (PowerShell / GUI)
# SPN Registration
setspn -S HTTP/portal.corp.com CORP\svc_web
# Duplicate check (Duplicate SPN = Broken Kerberos)
setspn -X
# LDAPS — Requires a certificate in the computer's Personal store with Server Authentication EKU
# Check
ldp.exe → Connection → Connect → Port 636 → SSLpowershellReal-World Scenarios in an Organization
- Web application running under a service account — must have an for each hostname (short + FQDN).
- LDAPS is mandatory before enabling Channel Binding (protects against relay).
Troubleshooting
- klist purge and retry after fix.
- Event 4771 with code 0x25 = Clock skew, 0x18 = incorrect password.
- certutil -store MY — checking DC certificates for LDAPS.
Glossary and Quick Command Line
- — Service Principal Name.
- LDAPS — over TLS (636).
- setspn -L user — list SPNs for an account.