Share via

How many KRBTGT account we should have in active directory domain and forest

LULU-6701 341 Reputation points
2023-12-13T11:07:23.51+00:00

Hello Expert community,

How many krbtgt account we should have on each domain and forest ?

There is any impact on Entra ID if we delete it ?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments

Answer accepted by question author

  1. Thameur-BOURBITA 36,526 Reputation points Moderator
    2023-12-13T11:31:26.41+00:00

    Hi @LULU

    How many krbtgt account we should have on each domain and forest ?

    You should have one krbtgt account for all Read and write domain controller on each domain.

    You can also have many krbtgt accounts if you have a RODC promoted in your domain. Because a RODC create its own krbtgt account and not use the existing one alreday used by R/W domain controlers.

    There is any impact on Entra ID if we delete it ?

    It's not recommended to remove krbtgt account because you will impact kerberos authentication on all your domain not only Entra ID.

    This is a critical account and you should reset its password at lease ywo time per year for security reason.


    Please don't forget to accept helpful answer

    Was this answer helpful?

    2 people found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.