DefSec.blog

DefSec.blog – Random IT Stuff, Cybersecurity, Active Directory

Menu
  • Cybersecurity
  • Active Directory
  • Azure Active Directory
Menu

Category: Azure Active Directory

Roll over the Kerberos decryption key of the “AZUREADSSO” computer account

Posted on January 22, 2023January 27, 2023 by th3alch3m1st

It’s is very important to regularly (every 30 days) roll over the Kerberos key for the AZUREADSSO computer account. This account represents your Azure AD in your on-prem AD. Permissions needed to perform this operation – on-prem Domain Administrator(DA) and Azure AD Global Administrator(GA) Assuming your environment consists of a single AD forest:

Read more
  • Active Directory (4)
  • Azure Active Directory (1)
  • Cybersecurity (4)
  • IT Stuff (1)

Recent Posts

  • How to remove domain applied GPO settings

    February 8, 2023
  • Disable IPv6 to prevent DNS spoofing

    February 5, 2023
  • Disable Link-Local Multicast Name Resolution(LLMNR) via Group Policy

    January 27, 2023
  • How to reset the Directory Services Restore Mode administrator account password in Windows Server

    January 22, 2023
  • Disclaimer
  • Contact
©2023 DefSec.blog