SpnManager/providers:26
Kerberos broken now? →
provider catalog

The 26 providers, and what each one covers.

Twenty service providers and six audit providers. Each row of providers.json drives the same sense, plan, test, execute-or-hand-off pipeline. Filter by platform, by whether the other machine holds a keytab, and by whether the provider writes to AD or audits and hands off.

platform
other machine
what it can do
26 of 26 providers
SQL.Engine
SQL Server Database Engine
SQL Server
expected shape
MSSQLSvc/{fqdn}:{port}
class MSSQLSvc
what it can do
registers the SPN itself
no keytab on the other machine
confirmed by SqlAuthScheme
a misconfiguration it catches
SPN on machine account when service runs as domain account — silent NTLM fallback
SQL.SSAS
SQL Server Analysis Services
SQL Server
expected shape
MSOLAPSvc.3/{host}[:{instance}]
class MSOLAPSvc.3
what it can do
registers the SPN itself
no keytab on the other machine
confirmed by SqlAuthScheme
a misconfiguration it catches
Port included in the SPN — never valid for SSAS; the colon suffix is the instance name
SQL.SSRS
SQL Server Reporting Services
SQL Server
expected shape
HTTP/{fqdn}
class HTTP
what it can do
registers the SPN itself
no keytab on the other machine
confirmed by HttpSpnego
a misconfiguration it catches
SPN registered for machine hostname when SSRS serves on a custom URL header
AD.IIS
IIS / Web Applications
Web
expected shape
HTTP/{host}[:{port}]
class HTTP
what it can do
registers the SPN itself
no keytab on the other machine
confirmed by HttpSpnego
a misconfiguration it catches
Kernel-mode auth with useAppPoolCredentials=false uses the machine account regardless of app pool identity
AD.ADFS
Active Directory Federation Services
Web
expected shape
HTTP/{federation-service-name}
class HTTP
what it can do
registers the SPN itself
no keytab on the other machine
confirmed by HttpSpnego
a misconfiguration it catches
WAP incorrectly given an SPN — WAP uses certificate auth, not Kerberos
AD.SharePoint
SharePoint Server
Web
expected shape
HTTP/{aam-url-host}
class HTTP
what it can do
registers the SPN itself
no keytab on the other machine
confirmed by HttpSpnego
a misconfiguration it catches
Missing Alternate Access Mapping URL variants
AD.RDP
Remote Desktop Services
Windows
expected shape
TERMSRV/{fqdn}
class TERMSRV
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
Machine renamed without re-running netdom — old FQDN SPN lingers
AD.SMB
SMB File Services
Windows
expected shape
HOST/{fqdn}, CIFS/{fqdn}
class HOST, CIFS
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
NAS device registering CIFS only, missing HOST
AD.WinRM
WinRM / PowerShell Remoting
Windows
expected shape
WSMAN/{fqdn}
class WSMAN
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
WSMAN SPN deleted by cleanup scripts — remoting falls back to NTLM
AD.DNS
DNS Server
Windows
expected shape
DNS/{fqdn}
class DNS
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
Orphaned old-FQDN SPN after a server rename
AD.PrintSpooler
Print Spooler / Print Server
Windows
expected shape
HOST/{fqdn}, RPCSS/{fqdn}
class HOST, RPCSS
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
Cluster print server VNN missing HOST/RPCSS on the cluster computer object
AD.Exchange
Exchange Server
Windows
expected shape
exchangeMDB/{fqdn}
class HTTP, exchangeMDB, exchangeRFR, exchangeAB
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
HTTP SPN for the load-balanced CAS namespace missing
AD.ADCS
Active Directory Certificate Services
Windows
expected shape
HTTP/{ces-cep-host}
class HTTP, RPCSS
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
CES/CEP under a domain account without an HTTP SPN
AD.DFS
DFS Namespaces
Windows
expected shape
HOST/{cname-alias}
class HOST, CIFS
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
Custom CNAME alias for a namespace root without HOST/CIFS SPNs
AD.AzureADSSO
Azure AD Seamless SSO
Cloud
expected shape
(AZUREADSSOACC$ — read only)
class HTTP
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
AZUREADSSOACC$ password not rotated (Azure AD Connect misconfigured)
AD.JavaSpnego
Java / Tomcat / JBoss / WildFly / Hadoop SPNEGO
Java
expected shape
HTTP/{fqdn}
class HTTP
what it can do
reports only, never writes
the other machine holds a keytab
no independent check yet
a misconfiguration it catches
SPN fixed in the directory but the keytab on the other machine never regenerated - the two now disagree about the key, and the service stops accepting tickets
AD.LinuxJoined
Linux joined to AD (realmd / sssd / adcli)
Linux
expected shape
HOST/{fqdn}
class HOST
what it can do
reports only, never writes
the other machine holds a keytab
no independent check yet
a misconfiguration it catches
Host-local /etc/krb5.keytab not refreshed after a key rotation
AD.OracleDb
Oracle Database Kerberos
Oracle
expected shape
oracle/{fqdn}
class oracle
what it can do
reports only, never writes
the other machine holds a keytab
no independent check yet
a misconfiguration it catches
RAC/SCAN: SPN registered on the wrong virtual name
AD.SAP
SAP SNC + SPNEGO Kerberos SSO
SAP
expected shape
SAP/{fqdn}, HTTP/{fqdn}
class SAP, HTTP
what it can do
reports only, never writes
the other machine holds a keytab
no independent check yet
a misconfiguration it catches
RC4/DES-only posture — AES is required for SAP Kerberos SSO
AD.ApplianceSso
Appliance SSO (F5 BIG-IP APM / Citrix NetScaler-ADC / KEMP LoadMaster)
Appliance
expected shape
HTTP/{vip-fqdn}
class HTTP
what it can do
reports only, never writes
the other machine holds a keytab
no independent check yet
a misconfiguration it catches
msDS-AllowedToDelegateTo not populated on the delegation account
Audit.Unconstrained
Unconstrained Delegation Audit
Forest audit
expected shape
TrustedForDelegation = true
class —
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
SQL service accounts set to unconstrained delegation for linked servers
Audit.KCD
Kerberos Constrained Delegation Audit
Forest audit
expected shape
msDS-AllowedToDelegateTo
class —
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
Delegation target lists an SPN not registered on any account
Audit.RBCD
Resource-Based Constrained Delegation Audit
Forest audit
expected shape
msDS-AllowedToActOnBehalfOfOtherIdentity
class —
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
Overly broad principal allowed to delegate to a sensitive resource
Audit.DuplicateSPN
Forest-Wide Duplicate SPN Scan
Forest audit
expected shape
setspn -X / -F -X
class —
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
SPN added to the new account, never removed from the old
Audit.EncryptionTypes
Kerberos Encryption Type Audit
Forest audit
expected shape
msDS-SupportedEncryptionTypes
class —
what it can do
reports only, never writes
no keytab on the other machine
no independent check yet
a misconfiguration it catches
Attribute unset — post-KB5021131 the DC assumes 0x27, not AES
Audit.KeytabDrift
Keytab Enctype/KVNO Drift Audit
Forest audit
expected shape
pwdLastSet + enc-type posture
class —
what it can do
reports only, never writes
the other machine holds a keytab
no independent check yet
a misconfiguration it catches
Password reset without regenerating the exported keytab — KRB_AP_ERR_MODIFIED
reading the capability column

SpnWrite

The provider can register the SPN itself when the caller has AD write rights, behind -WhatIf and -Confirm. Six providers: SQL Engine, SSAS, SSRS, IIS, ADFS, SharePoint. Each has a proof oracle that reads the negotiated mechanism back.

AuditOnly

The provider detects drift between the expected SPN set and AD, then generates a hand-off. Windows auto-registered services (RDP, SMB, WinRM, DNS, Print, Exchange, AD CS, DFS) audit because Windows owns those SPNs. Keytab families audit because the fix is not in AD.

The other machine holds a keytab

Java, Linux, Oracle, SAP, appliances, and the keytab-drift audit. Fixing the SPN in the directory without regenerating the keytab on the other machine leaves the service broken: the two end up holding different versions of the key, and a ticket signed with one will not be accepted by the other. That version number is the KVNO in the audit name above. These providers emit an operator runbook and never touch a secret. Safety model →

Without JavaScript this page shows all 26 rows unfiltered. The filters are progressive enhancement over the static list.