PS > Get-KDSRootKey
AttributeOfWrongFormat :
KeyValue : {4, 125, 72, 5...}
EffectiveTime : 7/19/2020 12:59:18 PM
CreationTime : 7/19/2020 11:04:10 PM
IsFormatValid : True
DomainController : CN=DC01,OU=Domain Controllers,DC=ad,DC=innova,DC=io
ServerConfiguration : Microsoft.KeyDistributionService.Cmdlets.KdsServerConfiguration
KeyId : ea453322-08b9-e230-f4f2-96826b120924
VersionNumber : 1
With Active Directory user objects comes the burden with password management. With many business critical applications dependent on user objects, the ability to get a maintenance window to change a password can be a hard battle for an Active Directory administrator or application owner. When that user object is used by many applications, the burden is magnified to near impossibility because of the downtime required. These “service account” passwords become institutional knowledge and reused over time on systems that the password was not originally intended. What Innova Solutions architects discover time-and-time again at our clients are those application-based user objects set with their password to never expire. The previously mentioned simple password never expires report will bring these user objects to the surface if they exist in your organization.