Glossary
AS-REP roasting
AS-REP Roasting abuses accounts without Kerberos pre-authentication to obtain crackable authentication data without valid credentials.
AS-REP Roasting exploits accounts that have the "Do not require Kerberos preauthentication" option enabled. Normally, Kerberos pre-authentication requires a client to prove knowledge of a password before the domain controller issues an AS-REP response. When pre-authentication is disabled, anyone can request an AS-REP for that account without any credentials, and the response contains data encrypted with the account's password-derived key, which can then be attacked offline.
This matters because it lets an unauthenticated or low-privileged attacker who merely knows a valid username obtain crackable material for that account, bypassing normal lockout and logging tied to failed logon attempts. The key mitigation is ensuring pre-authentication remains enabled for all accounts (it should never be disabled without a specific, documented reason), enforcing strong password policies, and alerting on AS-REP requests for accounts flagged with this setting.
See Kerberos hardening.