How can I change the ticket lifetime used by Kerberos?

A. The default lifetime for a Kerberos ticket is defined by the group policy for the domain which is 10 hours by default. It can be changed as follows but 10 hours will normally suffice (unless people work very long days):

  1. Start the Active Directory Users and Computers MMC snap-in (Start - Programs - Administrative Tools - Active Directory Users and Computers)
  2. Right click on the domain and select Properties from the context menu
  3. Select the 'Group Policy' tab
  4. Select the domain group policy object and click Edit
  5. Expand the Computer Configuration root then Weindows Settings - Security Settings - Kerberos Policy
  6. Double click the time you wish to change, modify and click OK
    Click here to view image
  7. Close the group policy editor

To force the GPO change to take effect you can run

C:\&gt; <b>secedit /refreshpolicy machine_policy /enforce</b>

Hide comments


  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.