← Back to Projects
Business Systems House 2025
Enterprise Active Directory Kerberos Hardening & AES Enrolment
Active Directory Kerberos AES-256 GPO Security Hardening Service Principal Names (SPN)
Enterprise Active Directory Kerberos Hardening & AES Enrolment
Eliminated kerberoasting attack vectors across domain accounts by enforcing high-strength AES encryption for Kerberos service tickets.
Key Features & Implementation
- RC4 Cipher Deprecation: Disabled weak Kerberos RC4-HMAC cipher suites across domain controllers and member servers via GPO.
- Service Account AES Binding: Configured explicit AES-128 and AES-256 ticket encryption settings on all Kerberos SPN service accounts.
- TGT Lifetime Optimization: Reduced Kerberos Ticket Granting Ticket (TGT) maximum lifetime to 8 hours to minimize ticket theft exposure.