Skip to main content
Version: 2.2.1-preview

AD-SPN-02 - Computer SPN service class usage should be retrievable

Overviewโ€‹

Understanding the distribution of SPN service classes across your computer infrastructure provides valuable security insights:

  • Service inventory: See what services are deployed across your environment
  • Risk assessment: Identify high-value targets (like database services with SPNs)
  • Compliance tracking: Ensure only approved services are configured
  • Anomaly detection: Spot unusual service classes that may indicate shadow IT or misconfigurations

Services with SPNs are targets for Kerberoasting attacks, so knowing which services exist helps prioritize security efforts.

Security Recommendationโ€‹

Review the service class breakdown regularly:

  • Validate that all services with SPNs are authorized
  • Ensure sensitive services (MSSQLSvc, etc.) have additional protections
  • Remove SPNs for decommissioned services
  • Consider implementing SPN attribution monitoring for critical services

How the Test Worksโ€‹

This test analyzes all computer SPNs, groups them by service class, and provides a count and percentage for each service class. This gives you a clear view of your Kerberos-authenticated service landscape.

  • Test-MtAdComputerSpnServiceClassCount - Counts distinct service classes
  • Test-MtAdComputerSpnUnknownCount - Identifies unrecognized service classes
  • Test-MtAdUserSpnServiceClassUsage - Shows user account SPN service class usage

Test Metadataโ€‹

FieldValue
Test IDAD-SPN-02
SeverityInfo
SuiteActive Directory
CategoryAD.SPN
PowerShell testTest-MtAdComputerSpnServiceClassUsage
TagsAD, AD-SPN-02, AD.SPN

Sourceโ€‹

  • Pester test: tests/ad/spn/Test-MtAdComputerSpnServiceClassUsage.Tests.ps1
  • PowerShell source: powershell/public/ad/spn/Test-MtAdComputerSpnServiceClassUsage.ps1