Avertissement pour cause de tickets Kerberos volumineux
Vérifié avec Windows 11 25H2 — mis à jour le 30 juillet 2026
Pris en charge sur : Au minimum Windows Server 2012, Windows 8 ou Windows RT
Chemin dans la console GPO
Configuration ordinateur\Modèles d'administration\Système\KDC Description
Ce paramètre de stratégie vous permet de configurer la taille à partir de laquelle les tickets Kerberos déclenchent l’événement d’avertissement émis durant l’authentification Kerberos. Les avertissements de taille de ticket sont consignés dans le journal système. Si vous activez ce paramètre de stratégie, vous pouvez définir le seuil au-dessus duquel les avertissements sont signalés pour les tickets Kerberos. Si vous définissez un seuil trop élevé, des échecs d’authentification peuvent se produire, même si aucun événement d’avertissement n’est consigné dans le journal. Si vous définissez un seuil trop bas, le journal contiendra trop de tickets pour que leur analyse soit intéressante. Cette valeur doit être égale à celle définie pour la stratégie Kerberos « Définir la taille maximale de mémoire tampon de jeton de contexte SSPI Kerberos » ou à la valeur MaxTokenSize la plus petite utilisée dans votre environnement si vous n’effectuez pas la configuration avec la stratégie de groupe. Si vous désactivez ce paramètre de stratégie ou ne le configurez pas, la valeur de seuil par défaut est 12 000 octets, ce qui correspond à la taille maximale de jeton Kerberos (MaxTokenSize) par défaut pour Windows 7, Windows Server 2008 R2 et versions antérieures.
Registre
Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters Nom de valeur : EnableTicketSizeThreshold
Activé : EnableTicketSizeThreshold = 1
Désactivé : EnableTicketSizeThreshold = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_kdc/TicketSizeThreshold Documentation Microsoft Learn Données de correspondance : Microsoft Learn (CC BY 4.0)
Générateur d'exports
BETAConfigurez l'état, la portée et les options, puis générez les sorties .reg, PowerShell, Intune et SCCM — ou ajoutez le paramètre à une collection multi-paramètres.
Ces exports écrivent le registre — ce n'est pas une GPO managée. ⓘ
Fichier .reg
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Avertissement pour cause de tickets Kerberos volumineux
; State: Enabled
; Supported on: Au minimum Windows Server 2012, Windows 8 ou Windows RT
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters]
"EnableTicketSizeThreshold"=dword:00000001
"TicketSizeThreshold"=dword:00002ee0 Autres formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Avertissement pour cause de tickets Kerberos volumineux
# State: Enabled
# Supported on: Au minimum Windows Server 2012, Windows 8 ou Windows RT
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EnableTicketSizeThreshold' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'TicketSizeThreshold' -Value 12000 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_kdc/TicketSizeThreshold
Data type: String
Value:
<enabled/>
<data id="TicketSizeThreshold" value="12000"/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Avertissement pour cause de tickets Kerberos volumineux
# State: Enabled
# Supported on: Au minimum Windows Server 2012, Windows 8 ou Windows RT
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters' -Name 'EnableTicketSizeThreshold' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters' -Name 'TicketSizeThreshold' -Expected 12000 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Avertissement pour cause de tickets Kerberos volumineux
# State: Enabled
# Supported on: Au minimum Windows Server 2012, Windows 8 ou Windows RT
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EnableTicketSizeThreshold' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'TicketSizeThreshold' -Value 12000 -Type DWord Scripts SCCM
# Exported from gporais.com
# Policy: Avertissement pour cause de tickets Kerberos volumineux
# State: Enabled
# Supported on: Au minimum Windows Server 2012, Windows 8 ou Windows RT
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Avertissement pour cause de tickets Kerberos volumineux
# State: Enabled
# Supported on: Au minimum Windows Server 2012, Windows 8 ou Windows RT
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters' -Name 'EnableTicketSizeThreshold' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters' -Name 'TicketSizeThreshold' -Expected 12000 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Avertissement pour cause de tickets Kerberos volumineux
# State: Enabled
# Supported on: Au minimum Windows Server 2012, Windows 8 ou Windows RT
$path = 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Policies\System\KDC\Parameters'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'EnableTicketSizeThreshold' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'TicketSizeThreshold' -Value 12000 -Type DWord Vous construisez une collection multi-paramètres ? Ajoutez ce paramètre et générez des exports combinés (.reg, PowerShell, GPO).