AD-COMP-10 - Computer delegation details should be retrievable
Overviewβ
Detailed visibility into Kerberos delegation configurations is essential for security because:
- Risk prioritization: Unconstrained delegation poses significantly higher risk than constrained delegation
- Attack path analysis: Understanding delegation relationships helps identify potential lateral movement paths
- Compliance requirements: Many security frameworks require documentation of delegation configurations
- Incident response: Knowing which systems have delegation helps during security investigations
Computers with unconstrained delegation should be treated as high-value targets requiring enhanced monitoring and protection.
Security Recommendationβ
For each computer with delegation enabled:
- Verify necessity: Confirm the delegation is required for business operations
- Minimize scope: Replace unconstrained with constrained delegation where possible
- Implement tiering: Ensure tier 0 systems (Domain Controllers) never have unconstrained delegation
- Monitor closely: Systems with delegation should have enhanced logging and monitoring
- Document exceptions: Maintain a registry of systems requiring delegation with business justifications
- Regular review: Quarterly review of delegation configurations
How the Test Worksβ
This test provides a detailed breakdown of:
- Computers with unconstrained delegation (highest risk)
- Computers with constrained delegation and protocol transition
- Per-computer details including name, enabled status, and distinguished name
Related Testsβ
Test-MtAdComputerDelegationCount- Provides summary counts of delegationTest-MtAdComputerDormantCount- Identifies stale accounts that may have delegation
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-COMP-10 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Computer |
| PowerShell test | Test-MtAdComputerDelegationDetails |
| Tags | AD, AD-COMP-10, AD.Computer |
Sourceβ
- Pester test:
tests/ad/computer/Test-MtAdComputerDelegationDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/computer/Test-MtAdComputerDelegationDetails.ps1

