AD-SPN-05 - Computer SPN non-FQDN hosts should be retrievable
Overviewβ
SPNs should use fully qualified domain names (FQDNs) for the host portion to ensure proper Kerberos authentication across domain boundaries and to avoid ambiguity. Non-FQDN hosts can cause:
- Authentication failures: Kerberos may fail to find the correct service principal
- DNS resolution issues: Short names may not resolve correctly in all contexts
- Cross-domain problems: Non-FQDNs may not work across domain trusts
- Configuration drift: Indicates inconsistent SPN registration practices
Security Recommendationβ
Review SPNs with non-FQDN hosts:
- Determine if the SPN is still needed
- Update SPNs to use FQDN format (serviceclass/host.fqdn:port)
- Establish standards for SPN registration in your organization
- Use FQDNs consistently for all service principal names
How the Test Worksβ
This test parses all computer SPNs and checks if the host portion contains a dot (indicating FQDN format). SPNs without dots in the host portion are flagged as non-FQDN.
Related Testsβ
Test-MtAdUserSpnNonFqdnHosts- Checks user account SPNs for non-FQDN hostsTest-MtAdComputerSpnServiceClassCount- Overall SPN analysis
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-SPN-05 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.SPN |
| PowerShell test | Test-MtAdComputerSpnNonFqdnHosts |
| Tags | AD, AD-SPN-05, AD.SPN |
Sourceβ
- Pester test:
tests/ad/spn/Test-MtAdComputerSpnNonFqdnHosts.Tests.ps1 - PowerShell source:
powershell/public/ad/spn/Test-MtAdComputerSpnNonFqdnHosts.ps1

