Subscribe to the Non-Human & AI Identity Journal
Home FAQ Authentication, Authorisation & Trust How can security teams tell if Kerberoasting risk…
Authentication, Authorisation & Trust

How can security teams tell if Kerberoasting risk is increasing?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 11, 2026 Domain: Authentication, Authorisation & Trust

Look for more SPN-bearing accounts than you can justify, older service-account passwords, use of weak encryption such as RC4_HMAC, and LDAP activity that enumerates directory metadata. If service identities have no owner, no rotation discipline, or broad privilege across multiple applications, the environment is moving toward higher Kerberoasting exposure.

Why This Matters for Security Teams

Kerberoasting risk is not a binary condition. It rises as the directory becomes easier to enumerate, service accounts become harder to govern, and attackers have more material to work with after a foothold. The practical warning signs are often visible long before a compromise, especially in environments where service principal names, weak encryption, and stale account ownership accumulate together. NHI Management Group’s Top 10 NHI Issues and the NIST Cybersecurity Framework 2.0 both point to the same operational reality: identity exposure grows when visibility and control do not keep pace with service sprawl.

For security teams, the question is not whether Kerberoasting is possible in Active Directory. It is whether the environment is making ticket requests easier to harvest, crack, and reuse by leaving legacy crypto in place and allowing service identities to drift out of governance. The 2024 research in The 2024 ESG Report: Managing Non-Human Identities shows how often organisations already face NHI compromise conditions, which is why service-account hygiene matters so much in practice. In practice, many security teams encounter Kerberoasting indicators only after password spraying, directory reconnaissance, or lateral movement has already started.

How It Works in Practice

Kerberoasting exposure increases when attackers can query Active Directory for service accounts tied to SPNs, request service tickets, and target the underlying secret offline. That risk is driven less by one setting than by the combination of discoverability, cryptographic weakness, and account sprawl. The moment an attacker can enumerate SPNs and the environment still allows RC4_HMAC or similarly weak fallback paths, the cost of attack drops sharply. Current guidance suggests treating this as an identity governance problem, not just a protocol problem.

Operationally, security teams should watch for a few patterns at once:

  • Growth in SPN-bearing accounts without a matching business owner or ticketed change record.
  • Service accounts with passwords older than the organisation’s rotation standard, or with no rotation at all.
  • LDAP queries that reveal directory metadata at unusual scale, especially from non-administrative hosts.
  • Accounts that retain broad privilege across multiple applications or domains.
  • Encryption downgrade patterns where modern Kerberos options are available but not enforced.

Practitioners should also map these findings against baseline identity controls in NIST SP 800-53 Rev 5 Security and Privacy Controls, especially around access enforcement, auditability, and credential lifecycle management. The same logic aligns with the Ultimate Guide to NHIs, which frames weak ownership and poor rotation as recurring drivers of identity exposure.

These controls tend to break down in large AD forests with many legacy applications because service ownership, encryption policy, and password governance are usually managed by different teams.

Common Variations and Edge Cases

Tighter service-account control often increases operational overhead, requiring organisations to balance hardening against application uptime and support complexity. That tradeoff is real, especially in estates where older middleware cannot tolerate rapid password rotation or modern Kerberos settings. Best practice is evolving, but there is no universal standard for this yet on how fast all service identities should move to stronger encryption and shorter secret lifetimes.

Some environments will show elevated Kerberoasting risk even when the number of SPNs is stable. For example, risk can rise if service accounts are reused across multiple workloads, if delegated administration hides true ownership, or if monitoring does not distinguish normal directory queries from reconnaissance. In those cases, the issue is less about count and more about blast radius. A single over-privileged service identity can become a reusable foothold across several systems.

Security teams should also be careful not to assume that password complexity alone solves the problem. Longer passwords help, but they do not eliminate exposure if secrets never rotate, RC4 remains enabled, or service accounts are granted standing privilege beyond their real function. The most useful indicator is a pattern of stale identity hygiene combined with discoverability and privilege concentration. That combination is the point at which Kerberoasting risk becomes materially higher, even if no attack has yet been detected.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Kerberoasting risk rises when service-account credentials are stale or poorly rotated.
NIST CSF 2.0PR.AC-4Least privilege and access governance limit the blast radius of cracked service accounts.
NIST SP 800-63Credential lifecycle discipline supports stronger assurance for service identities.
NIST Zero Trust (SP 800-207)3.1Zero trust reduces reliance on implicit trust for AD service identities.
NIST AI RMFGOVERNIdentity risk should be governed with accountable ownership and monitoring.

Apply stronger identity proofing and lifecycle controls to accounts that authenticate infrastructure.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org