AD-SPN-02 - Computer SPN service class usage should be retrievable
Overviewโ
Understanding the distribution of SPN service classes across your computer infrastructure provides valuable security insights:
- Service inventory: See what services are deployed across your environment
- Risk assessment: Identify high-value targets (like database services with SPNs)
- Compliance tracking: Ensure only approved services are configured
- Anomaly detection: Spot unusual service classes that may indicate shadow IT or misconfigurations
Services with SPNs are targets for Kerberoasting attacks, so knowing which services exist helps prioritize security efforts.
Security Recommendationโ
Review the service class breakdown regularly:
- Validate that all services with SPNs are authorized
- Ensure sensitive services (MSSQLSvc, etc.) have additional protections
- Remove SPNs for decommissioned services
- Consider implementing SPN attribution monitoring for critical services
How the Test Worksโ
This test analyzes all computer SPNs, groups them by service class, and provides a count and percentage for each service class. This gives you a clear view of your Kerberos-authenticated service landscape.
Related Testsโ
Test-MtAdComputerSpnServiceClassCount- Counts distinct service classesTest-MtAdComputerSpnUnknownCount- Identifies unrecognized service classesTest-MtAdUserSpnServiceClassUsage- Shows user account SPN service class usage
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-SPN-02 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.SPN |
| PowerShell test | Test-MtAdComputerSpnServiceClassUsage |
| Tags | AD, AD-SPN-02, AD.SPN |
Sourceโ
- Pester test:
tests/ad/spn/Test-MtAdComputerSpnServiceClassUsage.Tests.ps1 - PowerShell source:
powershell/public/ad/spn/Test-MtAdComputerSpnServiceClassUsage.ps1

