Back to all recipes
Level: MidLast updated:
Reset the krbtgt password after a suspected Golden Ticket
# Двойной сброс с паузой на полную репликацию (10+ часов)
Reset-ADServiceAccountPassword -Identity krbtgt # или официальный скрипт Microsoft
repadmin /syncall /AdePWhy it works this way
krbtgt is the key that signs every Kerberos ticket. Stolen, it lets an attacker forge anyone.
Caution
High-risk. Reset twice, at least 10 hours apart (a full replication cycle). Doing the second reset too soon breaks authentication domain-wide.
Watch out
- Twice, at least 10 hours apart — otherwise old tickets remain valid.
- Two resets back to back break domain authentication. Do not rush it.