AD-FORS-03 - SPN suffixes count should be retrievable
Overviewโ
SPN (Service Principal Name) suffixes simplify Service Principal Name management in complex Active Directory environments. They are important for:
- Service Authentication: SPNs are used by Kerberos to authenticate services; suffixes provide flexibility in how services are registered
- Multi-Domain Services: Organizations hosting services across multiple DNS namespaces use SPN suffixes to simplify SPN registration
- Service Migration: SPN suffixes enable service migration between domains without changing service configurations
- Security Assessment: Understanding SPN suffix configuration helps identify potential Kerberos authentication attack surfaces
Security Recommendationโ
Review SPN suffix configuration regularly:
- Ensure only legitimate organizational DNS domains are configured as SPN suffixes
- Remove unused SPN suffixes that may have been added for completed projects
- Verify that SPN suffixes align with the organization's service hosting strategy
- Monitor for unauthorized SPN suffix additions which could indicate compromise
How the Test Worksโ
This test retrieves the SPN suffixes configured at the forest level using the Get-ADForest cmdlet. It counts the number of custom SPN suffixes and reports the configuration status. The default forest domain is available for SPN registration by default and is not counted as a custom suffix.
Related Testsโ
Test-MtAdUpnSuffixesCount- Checks UPN suffix configuration for user authenticationTest-MtAdUpnSuffixesDetails- Provides detailed UPN suffix information
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-FORS-03 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Forest |
| PowerShell test | Test-MtAdSpnSuffixesCount |
| Tags | AD, AD-FORS-03, AD.Forest |
Sourceโ
- Pester test:
tests/ad/domain/Test-MtAdSpnSuffixesCount.Tests.ps1 - PowerShell source:
powershell/public/ad/domain/Test-MtAdSpnSuffixesCount.ps1

