An Active Directory (AD) domain network service located on a domain controller (DC) that runs as part of the DC’s Local Security Authority (LSA) process. It supplies session tickets and temporary session keys to user and computer principals in an AD domain and is required for the DC to control the domain and accept authentication and ticket-granting requests. The KDC provides the ‘Authentication Service (AS)’ and the ‘Ticket-Granting Services (TGS).’