Remove a Service Principal Name (SPN) from the user to mitigate the risk.

List SPNS

get-aduser -Identity administrator -Properties serviceprincipalnames | foreach { $_.serviceprincipalnames }

Clear SPNS

Set-ADUser -Identity admin-x -ServicePrincipalNames $null

You can’t use setspn as only works with Hostname

FindDomainForAccount: Call to DsGetDcNameWithAccountW failed with return value 0x00000525
Could not find account admin-x

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading...