Skip to content

Glossary

krbtgt

krbtgt is the built-in AD account whose key signs and encrypts every Kerberos ticket-granting ticket issued by the domain's domain controllers.

Every Active Directory domain has a disabled user account named krbtgt. The Key Distribution Center on each writable domain controller uses the keys derived from its password to encrypt and sign ticket-granting tickets (TGTs), which is what lets any DC trust a TGT issued by another. Read-only domain controllers each get their own krbtgt_NNNNN account so that a stolen RODC cannot mint tickets valid on writable DCs. The password is set randomly at domain creation and, in many environments, has never been changed since.

It matters because anyone who obtains the krbtgt hash — typically via DCSync or a stolen NTDS.dit — can forge golden tickets for any identity, with any group membership, that remain valid until the key changes. Rotate the krbtgt password periodically, and twice (with replication in between) after any suspected domain compromise, because the account keeps its previous key as well. Use a tested script, verify replication before each reset, and monitor for TGTs with anomalous lifetimes.

See Rotating krbtgt safely and Kerberos hardening.