Authentication policies and silos for Tier 0 accounts
Restrict where Tier 0 admins can authenticate with AD authentication policies and silos: prerequisites, claims, TGT lifetime, audit mode and enforcement.
Guides tagged
Restrict where Tier 0 admins can authenticate with AD authentication policies and silos: prerequisites, claims, TGT lifetime, audit mode and enforcement.
Rotate krbtgt without an outage: New-KrbtgtKeys.ps1, replication checks, RODC krbtgt accounts, a routine schedule and the incident-mode double reset.
Get certificate authentication ready for KB5014754 Full Enforcement: SID extension, altSecurityIdentities, KDC events 39/40/41 and the fixes that work.
Configure KCD and RBCD without new attack paths: protocol transition, SPN scoping, and auditing who can write msDS-AllowedToActOnBehalfOfOtherIdentity.
Remove RC4 from Kerberos safely: audit 4768/4769, fix accounts without AES keys, set msDS-SupportedEncryptionTypes and DefaultDomainSupportedEncTypes, enforce.
Find every non-DC account trusted for unconstrained delegation, map what depends on it, and migrate to constrained delegation or RBCD without outages.
Audit unconstrained, constrained, and resource-based constrained delegation in Active Directory, and lock down privileged accounts against abuse.
Enforce AES-only Kerberos, disable RC4 and DONT_REQ_PREAUTH, rotate krbtgt correctly, and detect Kerberoasting and golden ticket abuse.