Skip to main content
Version: 2.2.1-preview

AD-DCOMP-03 - Non-DC computers with constrained delegation count should be retrievable

Overviewโ€‹

  • Constrained delegation (also known as "protocol transition" or S4U2Proxy) is safer than unconstrained delegation but still carries security risks. It allows a service to impersonate a user to specific services only, rather than any service in the domain.

Security Considerations:

  • Limited Scope: Safer than unconstrained but still enables impersonation
  • Configuration Complexity: Easy to misconfigure and accidentally grant excessive permissions
  • Attack Surface: Each computer with constrained delegation expands the attack surface
  • Legacy Protocol: Some implementations may fall back to less secure methods

Security Recommendationโ€‹

  1. Minimize Usage:

    • Use only where absolutely necessary
    • Regular review of all constrained delegation configurations
    • Document business justification for each instance
  2. Secure Configuration:

    • Limit to specific SPNs (Service Principal Names)
    • Use protocol transition only when required
    • Regular auditing of delegation settings
  3. Consider Modern Alternatives:

    • Resource-Based Constrained Delegation: More flexible and easier to manage
    • Group Managed Service Accounts (gMSA): Automatic password management
    • Managed Identity: For cloud and hybrid scenarios

How the Test Worksโ€‹

This test counts non-DC computers with the TrustedToAuthForDelegation flag enabled, which indicates:

  • Constrained delegation is configured
  • Protocol transition may be enabled
  • Test-MtAdComputerUnconstrainedDelegationCount - Overall unconstrained delegation
  • Test-MtAdComputerNonDcUnconstrainedDelegationCount - Critical non-DC unconstrained delegation
  • Test-MtAdUserDelegationConfiguredCount - User account delegation settings

Test Metadataโ€‹

FieldValue
Test IDAD-DCOMP-03
SeverityHigh
SuiteActive Directory
CategoryAD.Security
PowerShell testTest-MtAdComputerNonDcConstrainedDelegationCount
TagsAD, AD-DCOMP-03, AD.Security

Sourceโ€‹

  • Pester test: tests/ad/security/Test-MtAdComputerNonDcConstrainedDelegationCount.Tests.ps1
  • PowerShell source: powershell/public/ad/security/Test-MtAdComputerNonDcConstrainedDelegationCount.ps1