<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: Do You Need to Update KRBTGT Account Password?	</title>
	<atom:link href="https://www.kjctech.net/do-you-need-to-update-krbtgt-account-password/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kjctech.net/do-you-need-to-update-krbtgt-account-password/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=do-you-need-to-update-krbtgt-account-password</link>
	<description></description>
	<lastBuildDate>Tue, 24 Jan 2023 18:20:55 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>
		By: www.kjctech.net krbtgt login - Login Directly		</title>
		<link>https://www.kjctech.net/do-you-need-to-update-krbtgt-account-password/comment-page-1/#comment-256427</link>

		<dc:creator><![CDATA[www.kjctech.net krbtgt login - Login Directly]]></dc:creator>
		<pubDate>Thu, 08 Sep 2022 11:00:20 +0000</pubDate>
		<guid isPermaLink="false">https://www.kjctech.net/?p=4266#comment-256427</guid>

					<description><![CDATA[[&#8230;] Do You Need to Update KRBTGT Account Password? &#124; KC’s Blog [&#8230;]]]></description>
			<content:encoded><![CDATA[<p>[&#8230;] Do You Need to Update KRBTGT Account Password? | KC’s Blog [&#8230;]</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: David Calvin		</title>
		<link>https://www.kjctech.net/do-you-need-to-update-krbtgt-account-password/comment-page-1/#comment-215951</link>

		<dc:creator><![CDATA[David Calvin]]></dc:creator>
		<pubDate>Fri, 23 Oct 2020 13:41:38 +0000</pubDate>
		<guid isPermaLink="false">https://www.kjctech.net/?p=4266#comment-215951</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.kjctech.net/do-you-need-to-update-krbtgt-account-password/comment-page-1/#comment-210453&quot;&gt;Rob Rech&lt;/a&gt;.

Thanks for the extra info. i highly doubt author cares past they view count.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.kjctech.net/do-you-need-to-update-krbtgt-account-password/comment-page-1/#comment-210453">Rob Rech</a>.</p>
<p>Thanks for the extra info. i highly doubt author cares past they view count.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Monitoring with PowerShell: AD KRBTGT &#38; making your own canaries - CyberDrain		</title>
		<link>https://www.kjctech.net/do-you-need-to-update-krbtgt-account-password/comment-page-1/#comment-213145</link>

		<dc:creator><![CDATA[Monitoring with PowerShell: AD KRBTGT &#38; making your own canaries - CyberDrain]]></dc:creator>
		<pubDate>Mon, 06 Jul 2020 07:05:04 +0000</pubDate>
		<guid isPermaLink="false">https://www.kjctech.net/?p=4266#comment-213145</guid>

					<description><![CDATA[[&#8230;] easy. Both are somewhat security oriented. The first part of the blog we will tackle monitoring the KRBTGT password. This needs to be reset on a regular schedule to ensure bad actors can&#8217;t abuse [&#8230;]]]></description>
			<content:encoded><![CDATA[<p>[&#8230;] easy. Both are somewhat security oriented. The first part of the blog we will tackle monitoring the KRBTGT password. This needs to be reset on a regular schedule to ensure bad actors can&#8217;t abuse [&#8230;]</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Rob Rech		</title>
		<link>https://www.kjctech.net/do-you-need-to-update-krbtgt-account-password/comment-page-1/#comment-210453</link>

		<dc:creator><![CDATA[Rob Rech]]></dc:creator>
		<pubDate>Fri, 27 Mar 2020 19:36:50 +0000</pubDate>
		<guid isPermaLink="false">https://www.kjctech.net/?p=4266#comment-210453</guid>

					<description><![CDATA[A few more thoughts on this article:
&quot;A Reddit user raised this great question today that I am not aware of. So I did a little research and here is the breakdown of what it is.&quot; I would suggest doing more research and updating your article.  As a Microsoft MVP, people may take your article at face value.  If someone follows as is, its dangerous for their domain.

&quot;Note that changing the KRBTGT account password in a 2008 (or higher) DFL will not cause replication issues.&quot;  A warning needs to be made here, that Functionality Level 2008 is REQUIRED to be able to support changing the KRBTGT password.  if the functionality level is say 2003, Kerberos only supports using the current password, not the previous password.  Changing the password with 2003 will not only result in replication issues, it will invalidate all tickets on the domain, forcing everyone and all servers to reboot.  That&#039;s a much greater impact than just breaking replication.  Changing the password with older functionality level than 2008 is tantamount to the Breach Recovery mode.  

Notes should also be made about RODCs using a separate password than RWDCs.]]></description>
			<content:encoded><![CDATA[<p>A few more thoughts on this article:<br />
&#8220;A Reddit user raised this great question today that I am not aware of. So I did a little research and here is the breakdown of what it is.&#8221; I would suggest doing more research and updating your article.  As a Microsoft MVP, people may take your article at face value.  If someone follows as is, its dangerous for their domain.</p>
<p>&#8220;Note that changing the KRBTGT account password in a 2008 (or higher) DFL will not cause replication issues.&#8221;  A warning needs to be made here, that Functionality Level 2008 is REQUIRED to be able to support changing the KRBTGT password.  if the functionality level is say 2003, Kerberos only supports using the current password, not the previous password.  Changing the password with 2003 will not only result in replication issues, it will invalidate all tickets on the domain, forcing everyone and all servers to reboot.  That&#8217;s a much greater impact than just breaking replication.  Changing the password with older functionality level than 2008 is tantamount to the Breach Recovery mode.  </p>
<p>Notes should also be made about RODCs using a separate password than RWDCs.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Rob		</title>
		<link>https://www.kjctech.net/do-you-need-to-update-krbtgt-account-password/comment-page-1/#comment-210452</link>

		<dc:creator><![CDATA[Rob]]></dc:creator>
		<pubDate>Fri, 27 Mar 2020 19:21:59 +0000</pubDate>
		<guid isPermaLink="false">https://www.kjctech.net/?p=4266#comment-210452</guid>

					<description><![CDATA[I&#039;ll expand, regarding the &quot;Breach Recovery&quot; you have to wait until all DCs have replicated before you make the second change.  After they have been validated to be in sync, make the change again to invalidate any open kerberos tickets.  At that point, all systems on the network will disconnect and require reauthentication / reboots.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ll expand, regarding the &#8220;Breach Recovery&#8221; you have to wait until all DCs have replicated before you make the second change.  After they have been validated to be in sync, make the change again to invalidate any open kerberos tickets.  At that point, all systems on the network will disconnect and require reauthentication / reboots.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Rob		</title>
		<link>https://www.kjctech.net/do-you-need-to-update-krbtgt-account-password/comment-page-1/#comment-201402</link>

		<dc:creator><![CDATA[Rob]]></dc:creator>
		<pubDate>Fri, 12 Jul 2019 13:33:07 +0000</pubDate>
		<guid isPermaLink="false">https://www.kjctech.net/?p=4266#comment-201402</guid>

					<description><![CDATA[Regarding your &quot;Maintenance Change&quot;, if the Kerberos password is changed before all user and service tickets expire (10 hours by default), then all workstatiions and servers will need to be rebooted.  The recommendation is to review Group Policy Default Domain Policy\ Computer Configuration\ Policies\Windows Settings\Security Settings\ Account Policies\Kerberos Policy: Max lifetime for service and user tickets setting.  After changing the password once, wait until this time period elapses then reset a second time.]]></description>
			<content:encoded><![CDATA[<p>Regarding your &#8220;Maintenance Change&#8221;, if the Kerberos password is changed before all user and service tickets expire (10 hours by default), then all workstatiions and servers will need to be rebooted.  The recommendation is to review Group Policy Default Domain Policy\ Computer Configuration\ Policies\Windows Settings\Security Settings\ Account Policies\Kerberos Policy: Max lifetime for service and user tickets setting.  After changing the password once, wait until this time period elapses then reset a second time.</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
