Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should IAM teams prioritise Kerberoasting remediation versus…
Governance, Ownership & Risk

How should IAM teams prioritise Kerberoasting remediation versus other AD hardening work?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Prioritise the service accounts that combine SPNs, weak passwords, and high privilege, especially where the associated server or application has already been retired. That gives the fastest reduction in attacker leverage because it removes both the ticketing path and the offline cracking opportunity from the most exposed accounts.

Why Kerberoasting Should Be Remediated as a High-Exposure AD Problem

Kerberoasting is not just another hardening task, it is a direct path from directory misconfiguration to offline password cracking against service accounts that still matter operationally. The fastest wins come from accounts with SPNs, weak or reused passwords, and elevated privileges, because those accounts give attackers both an authentication surface and a high-value post-crack payoff.

In practical terms, the question is not whether to eliminate every Kerberoastable account before doing anything else, but which exposed accounts materially expand attacker leverage. The more an account can be used for service authentication, and the more privilege it carries, the more it belongs at the front of the queue.

That is why service account hygiene is central to the remediation decision, and why a Service Account Security Guide is a better navigation point than treating Kerberoasting as a generic AD tuning issue. The remediation target is the account class that can still be ticketed, cracked offline, and then reused for lateral movement or privilege abuse.

What to Fix Before the Broader AD Backlog

The first pass should be exposure-driven. Retired applications, dormant servers, and orphaned service accounts with SPNs are ideal candidates because they often retain privileges long after the business dependency is gone. Removing or disabling those accounts can eliminate the attack path entirely, which is more valuable than making a low-risk directory tweak elsewhere.

Next, prioritise accounts where password strength, privilege scope, and exposure intersect. A low-privilege account with an SPN is undesirable, but a high-privilege account with a weak password is a materially different risk because compromise can become domain-level impact much faster. That is the AD hardening work that most directly changes attacker outcomes.

This prioritisation also fits broader Active Directory and Entra ID Hardening Guide guidance, because tiering, privileged groups, delegation, and service accounts interact. If a Kerberoastable account sits on a path to tier zero or sensitive administrative function, remediation should outrank cosmetic hardening elsewhere.

How to Sequence Kerberoasting Work Against Other AD Controls

Use a risk-based sequence rather than a one-for-one cleanup of every directory weakness. Start with exposed service accounts, then move to password policy and rotation for the accounts that remain, then reduce privilege and remove unnecessary SPNs, and only after that spend time on lower-yield AD hygiene that does not materially change attacker leverage.

That sequencing is easier to sustain when teams can see how Kerberoasting fits into the broader identity attack chain. The Identity Threat Detection and Response (ITDR) Guide helps frame the attack as credential access that can lead to persistence and lateral movement, which is exactly why cracked service-account credentials should be treated as a control priority, not a narrow password issue.

For environments that want a control-oriented benchmark, a CIS Benchmarks baseline is useful for the surrounding hardening work, but it should not distract from the accounts that are most exploitable today. The control objective is to reduce usable attack surface first, then standardise the rest.

Risk and Threat Considerations

Kerberoasting matters because it turns ordinary directory exposure into an offline cracking problem. Attackers do not need immediate authentication success if they can request service tickets, extract material for cracking, and test passwords outside the visibility of normal account lockout or login monitoring.

Failure mechanism: Weak, reused, or long-lived service account passwords combined with SPNs create a ticketing path that can be harvested at scale and cracked offline, especially when privileged or legacy accounts are left in place.

Impact: Once an attacker recovers one of those credentials, the blast radius can extend from a single service to lateral movement, delegated access abuse, or high-value privilege escalation, especially if the account was tied to a retired or poorly governed system.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-07 — Long-Lived SecretsKerberoastable service accounts often depend on static passwords that are easy to crack.
NHI-05 — Overprivileged NHIHigh-privilege service accounts amplify the impact of a successful Kerberoasting crack.
NHI-01 — Improper OffboardingRetired servers and orphaned service accounts are prime Kerberoasting remediation targets.
Recommendation — Rotate or remove long-lived service credentials before less exposed AD hardening tasks. Right-size privileged service accounts before investing in lower-risk directory cleanup. Deactivate or remove stale service accounts tied to retired applications and hosts.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementService-account passwords and rotation are central to reducing Kerberoasting exposure.
AC-6 — Least PrivilegeReducing service-account privilege limits post-crack attacker reach.
AU-2 — Event LoggingKerberoasting-related ticketing and follow-on use should be observable in logs.
Recommendation — Enforce stronger lifecycle controls and rotation for service account authenticators. Trim service account permissions to the minimum required for the service to function. Log service-account activity that helps detect ticket abuse and suspicious use.
CIS Controls v8CIS-5 — Account ManagementKerberoasting remediation depends on finding, owning, and disabling risky service accounts.
CIS-6 — Access Control ManagementPrivilege reduction is a key part of lowering Kerberoasting impact.
Recommendation — Inventory and remediate risky service accounts before broadening AD hardening work. Restrict service-account access to the smallest workable privilege set.

Practitioner Guidance

What to prioritise: Start with service accounts that are both crackable and consequential, meaning SPN-bearing accounts with weak passwords, high privilege, broad logon rights, or no active business owner. If the associated system is retired, removal or disablement should usually outrank password-only remediation.

What to verify: Confirm whether the account is still required, whether it can be converted to a managed or rotated secret model, and whether its privilege scope matches the actual service need. If you cannot name the owner or the dependency, treat that as a remediation signal rather than a reason to defer.

Practitioner takeaway: Kerberoasting remediation should be judged by attacker leverage, not by how tidy the directory looks. Fix the accounts that can be cracked into meaningful access first, then use the broader AD backlog to close the remaining structural gaps.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org