Key Distribution Center: runs on each DC and issues Kerberos tickets, both ticket-granting and service tickets.
Also called Key Distribution Center.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains KDC in context, with comparison tables and the common traps.
Terms in this definition
- Agents (classic) API
First-generation Foundry Agent Service API, based on threads, messages and runs. It is deprecated, replaced by conversations and responses, and retires on 31 March 2027.
- Kerberos
Authentication protocol based on tickets, native to Windows and Active Directory. Azure Files, Entra Domain Services and application proxy KCD all support it.
Related terms
- DefaultDomainSupportedEncTypes
Registry setting on the KDC that defines which Kerberos encryption types apply to accounts without msDS-SupportedEncryptionTypes; 0x18 limits them to AES256 and AES128.
- msDS-SupportedEncryptionTypes
A bitmask attribute on an account recording which Kerberos encryption types, for example AES or RC4, it can handle. When it is left empty, the KDC uses the domain's default instead.
- TGS
The ticket-granting service: whenever a client shows a valid TGT, this part of the Kerberos KDC on every domain controller hands it a service ticket.