Domain sign-in: Kerberos, time and cached logons
What happens when a domain user signs in, why clock differences break it, and why a laptop can sign in off the network but still can't reach anything.
- Level
- Intermediate
- Length
- About 45 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 1 Oct 2026
Skills you'll practise
- Describe the main steps of a Kerberos sign-in and service access
- Diagnose clock-skew failures and fix time the right way
- Explain cached logons and why they hide network problems
Course outline
- 1.Domain sign-in: Kerberos, time and cached logonsVideo · 6 min
- 2.Kerberos in plain wordsLesson · 14 min
- 3.Reading klist and Kerberos eventsLesson · 14 min
- 4.Names, SPNs and when Windows falls back to NTLMLesson · 12 min
- 5.Domain sign-in: Kerberos, time and cached logons: knowledge checkKnowledge check · 25 questions
- 6.Laptop can't open shares after a repairScenario
- 7.Final exam6 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Microsoft Learn: Kerberos authentication overview
- Microsoft Learn: Maximum tolerance for computer clock synchronization
- Microsoft Learn: How the Windows Time service works
- Microsoft Learn: Interactive logon: Number of previous logons to cache
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.