Migrate a Kerberos SPN to a New Service Account
What This Covers How to move a Kerberos Service Principal Name (SPN) from one account to another — the manual step migrations, server renames, and account swaps don’t do for you.
Before You Start Domain Admin or delegated Validated write to servicePrincipalName rights on both the old and new accounts setspn.exe (built into Windows Server, RSAT-AD-Tools on clients) The exact SPN string you’re moving — run setspn -Q <SPN> if you’re not sure who currently holds it A maintenance window: clients holding cached Kerberos tickets against the old SPN mapping will keep failing until tickets expire or are purged Steps Step 1: Inventory all SPNs on an account Before touching anything, see the full picture — every SPN a given service or machine account currently holds: