AD-CFG-03 - SPN mappings should be retrievable
Overviewβ
SPN mappings are used to support legacy or non-FQDN client behavior by mapping service principal names to the correct Kerberos realm/host context. While this can improve compatibility, misconfigured SPN mappings can create security and reliability issues, such as:
- Authentication inconsistencies (Kerberos vs. fallback behaviors)
- Clients receiving unexpected service identity resolution
- Increased exposure to credential forwarding / downgrade-style scenarios if legacy behavior is unintentionally permitted
Security Recommendationβ
- Keep SPN mappings as minimal as possibleβonly those required for supported legacy interoperability.
- Periodically review and remove stale mappings tied to retired hostnames/services.
- Validate that SPN mappings resolve to the correct target identities (FQDN/realm) for all required workloads.
How the Test Worksβ
This test inspects the SPN mapping configuration exposed by AD, extracts the configured mappings, and provides a count/visibility metric so administrators can identify whether mappings exist that should not be present.
Related Testsβ
Test-MtAdWellKnownSecurityPrincipalsCount- Identifies additional security principal surface that should be consistent with Kerberos hardening.
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-CFG-03 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Config |
| PowerShell test | Test-MtAdSpnMappings |
| Tags | AD, AD-CFG-03, AD.Config |
Sourceβ
- Pester test:
tests/ad/config/Test-MtAdSpnMappings.Tests.ps1 - PowerShell source:
powershell/public/ad/config/Test-MtAdSpnMappings.ps1

