2. Read the *servicePrincipalName* property and take the longest value prefixed with "HOST/" that doesn't have any more /'s in it. - For objects with multiple "Host/" values, can you identify actual fully-qualified host name? I've noticed that DCs will have a "DNS/" SPN value, but that value is not present on workstations and member servers.