AD-DCOMP-03 - Non-DC computers with constrained delegation count should be retrievable
Overviewโ
- Constrained delegation (also known as "protocol transition" or S4U2Proxy) is safer than unconstrained delegation but still carries security risks. It allows a service to impersonate a user to specific services only, rather than any service in the domain.
Security Considerations:
- Limited Scope: Safer than unconstrained but still enables impersonation
- Configuration Complexity: Easy to misconfigure and accidentally grant excessive permissions
- Attack Surface: Each computer with constrained delegation expands the attack surface
- Legacy Protocol: Some implementations may fall back to less secure methods
Security Recommendationโ
-
Minimize Usage:
- Use only where absolutely necessary
- Regular review of all constrained delegation configurations
- Document business justification for each instance
-
Secure Configuration:
- Limit to specific SPNs (Service Principal Names)
- Use protocol transition only when required
- Regular auditing of delegation settings
-
Consider Modern Alternatives:
- Resource-Based Constrained Delegation: More flexible and easier to manage
- Group Managed Service Accounts (gMSA): Automatic password management
- Managed Identity: For cloud and hybrid scenarios
How the Test Worksโ
This test counts non-DC computers with the TrustedToAuthForDelegation flag enabled, which indicates:
- Constrained delegation is configured
- Protocol transition may be enabled
Related Testsโ
Test-MtAdComputerUnconstrainedDelegationCount- Overall unconstrained delegationTest-MtAdComputerNonDcUnconstrainedDelegationCount- Critical non-DC unconstrained delegationTest-MtAdUserDelegationConfiguredCount- User account delegation settings
Related linksโ
- Microsoft Defender for Identity: Unsecure Kerberos delegation
- ANSSI Active Directory checkpoints: Constrained authentication delegation to privileged service
- ANSSI Active Directory checkpoints: Constrained delegation with protocol transition to a privileged service
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DCOMP-03 |
| Severity | High |
| Suite | Active Directory |
| Category | AD.Security |
| PowerShell test | Test-MtAdComputerNonDcConstrainedDelegationCount |
| Tags | AD, AD-DCOMP-03, AD.Security |
Sourceโ
- Pester test:
tests/ad/security/Test-MtAdComputerNonDcConstrainedDelegationCount.Tests.ps1 - PowerShell source:
powershell/public/ad/security/Test-MtAdComputerNonDcConstrainedDelegationCount.ps1


