Skip to main content
AD Academy
Back to all recipes
Level: MidLast updated:

Reset the krbtgt password after a suspected Golden Ticket

# Двойной сброс с паузой на полную репликацию (10+ часов)
Reset-ADServiceAccountPassword -Identity krbtgt   # или официальный скрипт Microsoft
repadmin /syncall /AdeP

Why it works this way

krbtgt is the key that signs every Kerberos ticket. Stolen, it lets an attacker forge anyone.

Caution

High-risk. Reset twice, at least 10 hours apart (a full replication cycle). Doing the second reset too soon breaks authentication domain-wide.

Watch out

  • Twice, at least 10 hours apart — otherwise old tickets remain valid.
  • Two resets back to back break domain authentication. Do not rush it.

Related events