Eliminate Password in Active Directory

๐Ÿ”’ Secure Bits ๐Ÿ’ก
๐—ช๐—ฎ๐—ป๐˜ ๐˜๐—ผ ๐—ฒ๐—น๐—ถ๐—บ๐—ถ๐—ป๐—ฎ๐˜๐—ฒ ๐—ฝ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ๐˜€ for Domain Admins in Active Directory?

You canโ€”but only with ๐—ฐ๐—ฒ๐—ฟ๐˜๐—ถ๐—ณ๐—ถ๐—ฐ๐—ฎ๐˜๐—ฒ-๐—ฏ๐—ฎ๐˜€๐—ฒ๐—ฑ ๐—น๐—ผ๐—ด๐—ผ๐—ป, properly implemented.
Smart cards (e.g. YubiKey 5 NFC) let you remove passwords entirelyโ€”even for privileged accounts.

๐—•๐˜‚๐˜ ๐—ถ๐˜ ๐—ต๐—ฎ๐˜€ ๐˜๐—ผ ๐—ฏ๐—ฒ ๐˜€๐—ฒ๐˜ ๐˜‚๐—ฝ ๐—ฟ๐—ถ๐—ด๐—ต๐˜:
๐Ÿ”น Authentication uses PKINIT (Kerberos with certificates). The private key never leaves the smart card.
๐Ÿ”น AD requires three cert templates:
โ€ข Kerberos Authentication (Domain Controllers)
โ€ข Enrollment Agent (admin issuing certs)
โ€ข SmartCardLogon (end users)
๐Ÿ”น DCs get certs via auto-enrollment (GPO).
๐Ÿ”น Admins use tools like certmgr.msc + YubiKey Manager to enroll users.
๐Ÿ”น Drivers (Minidriver) must be installed locally and on RDP targets.
๐Ÿ”น Set a Smart Card Removal Policy to lock/log off on key pull.
๐Ÿ”น Flag accounts with Smart card is required for interactive logon to block password fallback.
โ€ข Optional: Set 120-character random passwords for disabled accounts with the same check.

๐—š๐—ฒ๐˜ ๐—ฟ๐—ถ๐—ฑ ๐—ผ๐—ณ ๐—ฝ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ๐˜€ – โœ…

Have you already deployed passwordless logon in AD? What worked (or broke)? ๐Ÿ‘‡

๐—”๐˜‚๐˜๐—ต๐—ผ๐—ฟ: Martin Handl โ€“ full article: https://iqunit.com/smartcard-logon-teil-1/