krbtgt_AzureAD password rotation

Andreas 1,331 Reputation points
2024-03-19T09:46:04.5066667+00:00

Hi,

Hybrid environment.

We have an account named krbtgt_AzureAD, with the description "Azure AD Kerberos Server user account for this domain". Do we need to rotate the password for this user like we do for the onprem krbtgt ? Is there any documentation from MS regarding this like this one https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/forest-recovery-guide/ad-forest-recovery-reset-the-krbtgt-password ?

/R

Andreas

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Thameur-BOURBITA 36,261 Reputation points Moderator
    2024-03-19T10:18:45.6133333+00:00

    Hi @Andreas

    You can follow the article below to Reset the password for KRBTGT_AzureAD :

    Rotate the Microsoft Entra Kerberos server key

    TODO: Periodically reset the password for the KRBTGT_AzureAD account when using Hybrid Cloud Trust


    Please don't forget to accept helpful answer

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.