Area 09 / 12
Passwords & Service Accounts
Service accounts with weak, static passwords and a Service Principal Name are exactly what Kerberoasting hunts for. This area replaces them with group managed service accounts, applies fine-grained password policies, blocks weak passwords and rolls out Windows LAPS for local administrators.
Start the pathLearning path
0/4 done- 01Service account hardening: gMSA, SPNs and LAPSA practical guide to replacing risky service accounts with gMSA/dMSA, cleaning SPN exposure, fine-grained password policies, and Windows LAPS.
- 02Migrating service accounts to gMSA and dMSAStep-by-step migration from static service accounts to gMSA and Windows Server 2025 dMSA: KDS root key, retrieval rights, per-app notes and rollback.
- 03Deploying Windows LAPS: schema, permissions, policyDeploy Windows LAPS end to end: schema update, OU permissions, encryption, AD vs Entra backup, GPO settings, legacy LAPS migration and verification.
- 04AD password policy that works: length, FGPP, blocklistsBuild an Active Directory password policy on NIST guidance: long passphrases, fine-grained password policies, banned and breached password checks, no rotation.