Logo Vibhu Bhatnagar — PowerShell & Infrastructure Engineer
  • Home
  • About
  • Skills
  • Experiences
  • More
    Education Projects PowerShell Modules Articles Recent Posts Accomplishments
  • Posts
  • Notes
  • Hire Me
  • GitHub
  • Dark Theme
    Light Theme Dark Theme System Theme
Logo Inverted Logo
  • Tags
  • Active Directory
  • AI
  • AI Tools
  • Audit
  • Automation
  • Azure
  • Azure AD
  • Design Systems
  • Developer Tools
  • DFSR
  • Diagnostics
  • Documentation
  • Entra ID
  • FRS
  • GPO
  • Intune
  • IT Governance
  • Kerberos
  • M365
  • MCP
  • Microsoft 365
  • Migration
  • Module
  • MSP
  • Naming Conventions
  • NTP
  • Onboarding
  • Performance
  • PowerShell
  • Printers
  • RDP
  • Registry
  • Remote Management
  • RMM
  • Security
  • Server
  • SetupDiag
  • SharePoint
  • SPMT
  • SPN
  • Sysadmin
  • SYSTEM
  • SYSVOL
  • Troubleshooting
  • Update
  • Upgrade
  • W32tm
  • Windows
  • Windows Admin
  • Windows Administration
  • Windows Server
  • WinRM
Hero Image
The Security Concepts Behind AD and Entra ID

The Point Ten security concepts sit underneath almost everything that goes wrong in Windows and cloud environments. Each one is a form of trust — Windows or Entra ID issuing a token, a ticket, or a permission and then trusting it without double-checking. Attackers don’t invent new categories of attack; they find a way to get one of these ten things issued to them, forge it, or steal it. This post walks through each one in plain language, with a real example, the flaw that makes it exploitable, how to spot abuse, and how to close the gap.

  • Active Directory
  • Azure
  • Entra ID
  • Security
  • Kerberos
Tuesday, July 21, 2026 | 23 minutes Read
Hero Image
Migrate a Kerberos SPN to a New Service Account

What This Covers How to move a Kerberos Service Principal Name (SPN) from one account to another — the manual step migrations, server renames, and account swaps don’t do for you. Before You Start Domain Admin or delegated Validated write to servicePrincipalName rights on both the old and new accounts setspn.exe (built into Windows Server, RSAT-AD-Tools on clients) The exact SPN string you’re moving — run setspn -Q <SPN> if you’re not sure who currently holds it A maintenance window: clients holding cached Kerberos tickets against the old SPN mapping will keep failing until tickets expire or are purged Steps Step 1: Inventory all SPNs on an account Before touching anything, see the full picture — every SPN a given service or machine account currently holds:

  • Active Directory
  • Windows Server
  • Kerberos
  • SPN
Monday, July 20, 2026 | 4 minutes Read
Navigation
  • About
  • Skills
  • Experiences
  • Education
  • Projects
  • PowerShell Modules
  • Articles
  • Recent Posts
  • Accomplishments
  • GitHub
Contact me:
  • vibhu@pwsh.in
  • Facebook: vibhu@pwsh.in
  • Vibhu2
  • Vibhu Bhatnagar
  • +91 8979989222
  • Reddit: VibhuPwsh
  • Twitter: VibhuBhatn54299

Liability Notice: The views and opinions expressed on this blog are my own and do not represent those of my employer. All content is provided for informational purposes only.


Toha Theme Logo Toha
© 2026 Vibhu Bhatnagar. All rights reserved.
Powered by Hugo Logo