mrstrong Posted June 26, 2025 Posted June 26, 2025 Whilst "tidying" up some users with powershell I think I may have messed up big time. It looks like I've disabled the krbtgt user account and moved it into a "Disabled" OU. Apparently this account is crucial for kerberos 🤯 Nothing seems to have broke yet but can anyone advise ? E.g. should I just re-enable it and move it? Which OU should it be in ?
Koldov Posted June 26, 2025 Posted June 26, 2025 (edited) Isn't it supposed to be disabled...? Mine is! BTW it's in Domain > Users Edited June 26, 2025 by Koldov 1
SteveM555 Posted June 26, 2025 Posted June 26, 2025 I'm pretty sure it should already be disabled to prevent it from being logged into, and yeah - Just in the standard AD Users OU. 1
CHiLL Posted June 26, 2025 Posted June 26, 2025 Our "krbtgt" user is disabled and seemingly cannot be reenabled. 1
Koldov Posted June 26, 2025 Posted June 26, 2025 Quick internet search says OU* is irrelevant. https://www.reddit.com/r/sysadmin/comments/yyp1s6/krbtgt_user_was_moved_into_another_ou_issues/ *Depending on if you have anything that looks for an account in a specific OU, like a password change script. 1
HarkNowHear Posted June 26, 2025 Posted June 26, 2025 Can leave it disabled, but remember to reset the password regularly - use one of the MS scripts to manage the process. 1
Jaan Posted June 26, 2025 Posted June 26, 2025 Here's veeams take on it. https://community.veeam.com/blogs-and-podcasts-57/reset-the-kbrtgt-account-password-8842 1
mrstrong Posted June 26, 2025 Author Posted June 26, 2025 (edited) Phew, thanks all I'd been disabling accounts and moving them e.g. Get-ADUser -Filter {(Enabled -eq $False)} | Move-ADObject -TargetPath "OU=Disabled,OU=Accounts,DC=ourdomain,DC=local" so it was probably already disabled and just got moved I'll move it back Edited June 26, 2025 by mrstrong 1
ITGuyNW Posted June 26, 2025 Posted June 26, 2025 Yeah it stays disabled. Its there as a background thing. You should be cycling the keys every six months for security. 1
Olliedawg Posted June 26, 2025 Posted June 26, 2025 Just checked ours and the last change date was 2006... jeez adding that to the job list
Davit2005 Posted June 26, 2025 Posted June 26, 2025 (edited) 59 minutes ago, mrstrong said: Phew, thanks all I'd been disabling accounts and moving them e.g. Get-ADUser -Filter {(Enabled -eq $False)} | Move-ADObject -TargetPath "OU=Disabled,OU=Accounts,DC=ourdomain,DC=local" so it was probably already disabled and just got moved I'll move it back The command is filtering for disabled users i.e. Enabled -eq $False . So in it self not disabling the account. A more safer option would be to set OUs i.e. Service Accounts, Staff Accounts, Student Accounts etc and filter on the OUs that contain those users and not any user in AD otherwise you could end up in a right mess. Edited June 26, 2025 by Davit2005 1
CrootUK Posted June 26, 2025 Posted June 26, 2025 (edited) Just remmber when you change the password which you can just do through aduc to leave it 24 hours before doing the next change. (Two changes are needed to expire all existing tokens) Edited June 26, 2025 by CrootUK 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now