Active › Module 7 › Lesson 2
gMSA SPN Hygiene
Group Managed Service Accounts and SPN hygiene — reduce Kerberoast surface on $LAB_AD with strong managed passwords and SPN audit.
Visual · t25_gmsa_spn_hygiene
gMSA + SPN hygiene = service account hardening. $LAB_AD literacy. Original Cyberlium.
Opening
Kerberoasting hunts weak service passwords — gMSA and SPN hygiene starve the hunt on your lab forest.
gMSA (Group Managed Service Account) literacy: Windows manages password rotation for service accounts in authorized groups — reduces long-lived weak passwords targeted by Kerberoasting (Module 5 named). SPN hygiene: register SPNs only where needed, remove stale SPNs, prefer gMSA/sMSA over user accounts with SPNs, use long random passwords if gMSA unavailable, restrict who can read service account passwords. Defenders: audit SPNs (setspn -Q), monitor 4769 for anomalous TGS requests, enforce AES for Kerberos. Cyberlium applies hygiene checklist to YOUR $LAB_AD service accounts — NOT Kerberoast cookbooks on stranger domains, NOT cracking real enterprise SPN lists from leaks. Lab row: one misconfigured SPN account on lab with gMSA migration recommendation.
1. gMSA benefits
Automatic password management, constrained delegation support, reduced Kerberoast ROI.
Requires Windows Server 2012+ domain functional level literacy — note lab version.
Command guide
Try these commands — gMSA benefits
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
Microsoft gMSA — https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/group-managed-service-accounts/group-managed-service-accounts-overview (SPN hygiene) Kerberoast mitigation — https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4769 (4769 monitoring) adsecurity.org — https://adsecurity.org/ (service account hardening literacy)
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl
macOS: Built-in
Windows: Built-in (PowerShell: Invoke-WebRequest)
═══ LINUX / macOS ═══
Command — copy this
export LAB_AD=${LAB_AD:-$HOME/cyberlium-lab/t25-ad}
cat > "$LAB_AD/notes/gmsa-spn-hygiene.txt" <<'EOF'
gMSA: managed passwords, no interactive login — prefer over user SPNs
SPN hygiene: remove SPNs from user accounts; use long random service passwords
audit: Event 4769 volume, accounts with both SPN and interactive logon
EOFCommand — copy this
grep -E 'gMSA|SPN|4769' "$LAB_AD/notes/gmsa-spn-hygiene.txt" curl -sS https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/group-managed-service-accounts/group-managed-service-accounts-overview | head -8
Primary tools to practice this lesson: curl, grep. Reference sites: Microsoft gMSA (https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/group-managed-service-accounts/group-managed-service-accounts-overview); Kerberoast mitigation (https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4769); adsecurity.org (https://adsecurity.org/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. SPN audit checklist
List SPN accounts on $LAB_AD, flag user accounts with SPNs, plan gMSA or strong password.
Remove duplicate and orphaned SPNs — defender ticket, not roast target list export.
3. Refused
No Kerberoast tool output from stranger AD as homework evidence.
Hygiene output is remediation plan — not cracked TGS hashes published.
4. What you ship: gMSA SPN hygiene checklist
gMSA definition + six SPN audit steps + one lab misconfig fix row.
5. What you record before the next lesson
gMSA SPN hygiene checklist path.
6. Wrong vs right: stranger-domain attacks vs lab AD literacy
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Kerberoast stranger domain SPNs and submit hash list for credit.
Right
gMSA SPN hygiene checklist on $LAB_AD. Next: LSA Credential Guard.
Mission: gMSA SPN hygiene checklist
1) Define gMSA one line. 2) Write six SPN audit steps. 3) One lab misconfig + fix. 4) NEVER stranger Kerberoast homework.
Stuck? Ask Cyberlium AI Mentor
Ask Mentor: “User account with SPN — migrate path?”
Knowledge Check
APPLY: gMSA helps reduce:
Multiple choice
Knowledge Check
APPLY: True or False: Kerberoast stranger AD for hygiene lab credit.
True or False
Knowledge Check
APPLY: SPN hygiene includes:
Multiple choice