Following an NTLMv2 enforcement change, the Active Directory team needed to understand the authentication behaviour of the servers in scope. I analysed Windows security events to check for observed Kerberos activity across that defined server set.
I worked through a SecurityEvent export exceeding 100 MB and reduced it to a server-level summary. Keeping the result tied to each server made the review useful for the change team, rather than leaving them with a large event export or an aggregate count.
I confirmed Kerberos activity on all 13 servers and reported that finding to the Active Directory team. The conclusion established the observed authentication behaviour in scope; determining which applications still depended on NTLM would require a separate assessment.
Closer to the work
The authentication question
The review followed NTLMv2 enforcement and asked whether Kerberos activity was present on the 13 servers in scope. I used the SecurityEvent export to answer that operational question for the Active Directory team.
Open this detail ↗Server-level event analysis
I examined the exported Windows security-event data server by server and condensed more than 100 MB into a concise summary. The method kept the conclusion traceable to the server set included in the change review.
Open this detail ↗What the change review established
All 13 servers showed Kerberos activity. This established the presence of Kerberos following the change. A complete account of application authentication dependencies or remaining NTLM use would need a broader review.
Open this detail ↗Skills established through this work