Admin Accounts with SPNs — Hidden Risk Behind Kerberoasting

Admin Accounts with SPNs — Hidden Risk Behind Kerberoasting

🔍 Admin Accounts with SPNs — Hidden Risk Behind Kerberoasting | Directory Insights in 10 MinutesIn this episode, Craig Birch breaks down a major Active Directory security blind spot: Kerberoasting via privileged accounts with SPNs (Service Principal Names).You'll learn how attackers exploit these accounts — and how to find, assess, and fix the risk without breaking your apps.Straightforward, no fluff — just practical identity security guidance.🛠️ What You’ll Learn🔐 What SPNs are — and why they matter⚠️ How attackers use them in Kerberoasting attacks🖥️ Why ADUC isn’t enough for visibility💻 PowerShell + LDAP filters for fast discovery🧠 SDProp and how it flags privileged accounts🤝 Why app owner collaboration is critical🔁 Safer alternatives: gMSAs, strong passwords, and role reviews❌ Why auto-remediation can break things💡 PowerShell SpotlightpowershellCopyEditGet-ADUser -LDAPFilter "(&(admincount=1)(servicePrincipalName=*))" -Properties servicePrincipalName | Select-Object Name, servicePrincipalNameUse this to find privileged accounts with SPNs — the ones most at risk of Kerberoasting.✅ Quick TakeawaysScript it — don’t rely on ADUCNever auto-remove SPNs without impact analysisTalk to app owners before changesHarden service accounts or switch to gMSAsMonitor SDProp-marked accounts to shrink attack surface💬 Found this helpful? Like, share, or comment! Got a topic you want us to cover in 10 minutes or less? Drop it below — we’re listening.

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(18)

Hybrid Identity is Broken: Rethinking AD, Entra ID & the Bridge in Between

Hybrid Identity is Broken: Rethinking AD, Entra ID & the Bridge in Between

Welcome to another episode of Guardians of the Directory, where we pull back the curtain on the real-world challenges in securing and managing Active Directory and hybrid identity environments. In thi...

21 Elo 202541min

Blueprinting Zero Trust From: Strategy to Execution with Jerry Chapman

Blueprinting Zero Trust From: Strategy to Execution with Jerry Chapman

Welcome back to Guardians of the Directory! In this episode, Craig Birch is joined once again by Zero Trust expert Jerry Chapman for a deep dive into the Zero Trust Blueprint—a practical model to help...

26 Kesä 202530min

AdminSDHolder in Active Directory: Hidden Risks and Persistent Threats

AdminSDHolder in Active Directory: Hidden Risks and Persistent Threats

In this episode of Directory Insights in 10 Minutes, Craig Birch breaks down the often-misunderstood AdminSDHolder object in Active Directory and why it's a high-value target for attackers. Learn how ...

1 Touko 20256min

Kerberos Pre-Auth: Hidden AD Risk

Kerberos Pre-Auth: Hidden AD Risk

In this episode of Directory Insights in 10 Minutes, Craig Birch breaks down one of the most overlooked Active Directory misconfigurations: the "Do not require Kerberos pre-authentication" setting.🔍 ...

9 Huhti 20257min

Directory Insights in 10 Minutes: Remediating DES Encryption in Active Directory

Directory Insights in 10 Minutes: Remediating DES Encryption in Active Directory

Welcome to another episode of Directory Insights in 10 Minutes, powered by Guardians of the Directory. In this quick-hitting session, host Craig Birch walks through the process of identifying and reme...

1 Huhti 20254min

Directory Insights in 10 Minutes Reversible Password Encryption – A Hidden Risk

Directory Insights in 10 Minutes Reversible Password Encryption – A Hidden Risk

Summary:In this episode of Directory Insights in 10 Minutes, we dive into a critical yet often overlooked Active Directory misconfiguration—Allowing Password Storage with Reversible Encryption.This se...

18 Maalis 20254min

Directory Insights in 10 minutes: Password Not Required - The Hidden Risk

Directory Insights in 10 minutes: Password Not Required - The Hidden Risk

Episode OverviewIn this episode of Directory Insights in 10 Minutes, we’re exposing a dangerous yet overlooked Active Directory misconfiguration—PasswordNotRequired.Most AD admins assume password poli...

11 Maalis 20255min