Active Directory

How to increase the Kerberos ticket time?

To increase the Kerberos ticket time, you need to modify the Maximum lifetime for user ticket and Maximum lifetime for user ticket renewal policies in the Group Policy Editor. These policies can be found under Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Kerberos Policy.

The Ticket-Granting Ticket (TGT) time-to-live (TTL) is the maximum amount of time that a TGT can be used to request additional tickets. The default TGT TTL is 10 hours.

To configure or change the TGT time by Group Policy, you can follow these steps:

  • Open the Group Policy Management console and create or edit a Group Policy Object (GPO).
  • Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Kerberos Policy.

TGT-Time-by-group-policy

  • Double-click “Maximum lifetime for user ticket renewal” and select the “Define this policy setting” option.
  • Enter the desired TGT TTL value in hours in the “Maximum lifetime for user ticket renewal” field.

TGT-value-10-hours

  • Click “OK” to save the changes.

Note that increasing the Kerberos ticket time may have security implications, as it increases the risk of unauthorized access if a ticket is stolen or compromised. Therefore, it is important to balance security and usability when setting these policies.

So, that’s all in this blog. I will meet you soon with next stuff. Have a nice day!!!

Guys please don’t forget to like and share the post. Also join our WindowsTechno Community and where you can post your queries/doubts and our experts will address them.

You can also share the feedback on below windows techno email id.

If you have any questions, feel free to contact us onadmin@windowstechno.com also follow us on facebook@windowstechno to get updates about new blog posts.

How useful was this post?

Click on a star to rate it!

As you found this post useful...

Follow us on social media!

Was this article helpful?
YesNo

Vipan Kumar

He is an Active Directory Engineer. He has been working in IT industry for more than 10 years. He is dedicated and enthusiastic information technology expert who always ready to resolve any technical problem. If you guys need any further help on subject matters, feel free to contact us on admin@windowstechno.com Please subscribe our Facebook page as well website for latest article. https://www.facebook.com/windowstechno

Leave a Reply

Check Also
Close
Back to top button