Skip to content
arrow_back
ISM-1847policyASD Information Security Manual (ISM)

Reset KRBTGT Account Password Twice After Compromise or Yearly

Change the Active Directory KRBTGT service account password twice (allowing replication in between) if the domain is compromised, suspected of being compromised, or not changed in 12 months.

record_voice_over

Plain language

Microsoft Active Directory (the system that controls who can log in to your company's computers) relies on a special hidden account called KRBTGT to issue the digital "tickets" that prove a person is allowed access. If an attacker steals the secret password for this account, they can forge tickets and impersonate anyone for a very long time. This control says you must change that KRBTGT password twice in a row, with a pause between the two changes so the new value can spread to every server first, and you must do this if the domain is hacked, suspected of being hacked, or the password is more than 12 months old.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2025

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Credentials for the Kerberos Key Distribution Center's service account (KRBTGT) are changed twice, allowing for replication to all Microsoft AD DS domain controllers in-between each change, if the domain has been directly compromised, the domain is suspected of being compromised or they have not been changed in the past 12 months.
policyASD Information Security Manual (ISM)ISM-1847
priority_high

Why it matters

If the KRBTGT password is stale or only changed once after a breach, attackers can keep forging valid access tickets and impersonate any user for months, retaining full control of the domain.

settings

Operational notes

Always allow the first change to fully replicate before the second; resetting twice too quickly can break logins and Kerberos tickets across the organisation.

build

Implementation tips

  • The IT administrator should reset the KRBTGT account password using Microsoft's official KRBTGT reset script or a controlled manual reset, rather than ad-hoc tools, so the change is performed safely and consistently across the domain.
  • The IT administrator should perform the first password change, then wait until that change has fully replicated to every domain controller (the servers running Active Directory) before performing the second change, confirming replication with a tool such as repadmin before proceeding.
  • The systems team should set a recurring calendar reminder at most every 12 months to perform the double KRBTGT reset, so the password never ages beyond the 12-month limit even when no compromise has occurred.
  • The incident response lead should add an immediate double KRBTGT reset to the organisation's incident response plan as a mandatory step whenever the domain is confirmed compromised or is reasonably suspected of being compromised, so forged tickets are invalidated quickly.
  • The IT administrator should schedule the reset for a low-activity window and warn users in advance, because changing KRBTGT can briefly interrupt logins and Kerberos tickets, then verify normal authentication afterwards before closing the task.
fact_check

Audit / evidence tips

  • Askthe records of the two most recent KRBTGT password changesLook atthe date and time of each change and the gap between themGoodshows two changes performed in sequence with a deliberate pause for replication in between, not a single change
  • Askhow the organisation confirmed the first password change had replicated to all domain controllers before doing the secondLook atreplication confirmation output (for example from repadmin) or a documented checklistGoodpoints to evidence that replication completed before the second reset
  • Askthe date of the last KRBTGT reset and compare it to todayLook atwhether it falls within the past 12 monthsGoodshows the password is no older than 12 months, with a recurring schedule to keep it that way
  • Askwhether the KRBTGT password is reset as part of the incident response process when the domain is compromised or suspected compromisedLook atthe incident response plan and any past incident recordsGoodshows the double reset is a defined, mandatory step and has actually been done after a real or suspected incident
  • Askwho is authorised to perform the reset and what procedure they followLook atthe documented procedure or script usedGoodnames responsible staff and shows a repeatable, controlled method rather than an undocumented manual process
link

Cross-framework mappings

How ISM-1847 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

E8

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
E8-RA-ML2.5ISM-1847 requires organisations to change the KRBTGT service account credentials twice (with replication between changes) when compromise...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls