Back to Projects
Business Systems House 2025

Enterprise Active Directory Kerberos Hardening & AES Enrolment

Enterprise Active Directory Kerberos Hardening & AES Enrolment
Active Directory Kerberos AES-256 GPO Security Hardening Service Principal Names (SPN)

Enterprise Active Directory Kerberos Hardening & AES Enrolment

Eliminated kerberoasting attack vectors across domain accounts by enforcing high-strength AES encryption for Kerberos service tickets.

Key Features & Implementation

  • RC4 Cipher Deprecation: Disabled weak Kerberos RC4-HMAC cipher suites across domain controllers and member servers via GPO.
  • Service Account AES Binding: Configured explicit AES-128 and AES-256 ticket encryption settings on all Kerberos SPN service accounts.
  • TGT Lifetime Optimization: Reduced Kerberos Ticket Granting Ticket (TGT) maximum lifetime to 8 hours to minimize ticket theft exposure.
ROOT ACCESS GRANTED