SpnManager Kerberos SPN auditing and repair for Active Directory

Adoption guide

A 203-page guide covering every phase of using SpnManager, from deciding whether it applies to your estate through to running it on a schedule, followed by the full command reference.

One document covering every phase of using SpnManager, written for a mixed audience — the same six views you will find on each command page, so management, practitioners, and whoever signs off on new software can each read the part that answers their question.

Download the adoption guide (PDF)

Part 1 — phase by phase

  • Deciding whether this applies to you. The four symptoms that mean it probably does, and the cases where it does not.
  • Prerequisites. What you need, and why you should start with a read-only account.
  • Your first audit. The commands that change nothing.
  • Reading what it found. The five stages, and which one is the only one that writes.
  • Hand-off. Getting the fix without granting write rights — including why registering an SPN alone does not fix Kerberos for keytab-backed services.
  • Reconcile. Letting it make the change, preview first.
  • Scheduling. Three modes, six logical groups, three schedulers.
  • Operating it. Exit codes, what to alert on, and what the run reports keep.

Part 2 — command reference

Every command, in full. The same pages published in the online reference, included so the guide stands alone offline — useful when the person reviewing it is not the person with access to the environment.

A note on what it claims

Every count in the guide — the number of commands, the number of providers, which commands write to the directory — is generated from the product itself when the document is built, not typed by hand. If the product changes and the guide is rebuilt, the numbers change with it.