Active Directory Domain Services authentication and Kerberos hardening

Advanced
Administrator
Identity and Access Administrator
Windows Server

Learn how to troubleshoot and strengthen Windows authentication in Active Directory environments.

Learning objectives

In this module, you'll:

  • Explain how Security Support Provider Interface (SSPI), Negotiate, NTLM, and Kerberos interact.
  • Trace Kerberos authentication from Ticket Granting Ticket (TGT) issuance through service ticket presentation and authorization.
  • Diagnose Service Principal Names (SPN), delegation, PAC, encryption type, and NTLM fallback issues.
  • Plan a staged migration from NTLM to Kerberos.
  • Audit and remediate RC4 usage before and after Windows Server 2025 domain controller deployment.
  • Plan for PKINIT agility, Kerberos encryption policy, SMB NTLM blocking, and password-change hardening.

Prerequisites

  • Familiarity with Kerberos, NTLM, SPNs, and Windows security logs.