AD-SPN-06 - User SPN total count should be retrievable
Overviewโ
User accounts with Service Principal Names (SPNs) are high-value targets for attackers because:
- Kerberoasting: Attackers can request service tickets for these SPNs and attempt to crack them offline
- Service account exposure: User accounts with SPNs often have elevated privileges
- Password policy gaps: Service accounts may have weaker password policies than expected
- Shadow service accounts: Unknown user accounts with SPNs may indicate unauthorized services
Understanding the scope of user SPNs helps assess your Kerberoasting attack surface.
Security Recommendationโ
Minimize user accounts with SPNs:
- Use Group Managed Service Accounts (gMSAs) instead of user accounts for services
- Regularly audit user accounts with SPNs
- Ensure service accounts have strong, regularly rotated passwords
- Consider using Managed Service Accounts (MSAs) where possible
- Remove SPNs from accounts that no longer need them
How the Test Worksโ
This test retrieves all user objects from Active Directory, extracts their SPNs, and counts the total number of SPNs configured on user accounts.
Related Testsโ
Test-MtAdUserSpnServiceClassCount- Counts distinct service classes on usersTest-MtAdUserSpnDomainAdminCount- Identifies SPNs on domain admin accountsTest-MtAdComputerSpnTotalCount- Counts computer account SPNs
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-SPN-06 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.SPN |
| PowerShell test | Test-MtAdUserSpnTotalCount |
| Tags | AD, AD-SPN-06, AD.SPN |
Sourceโ
- Pester test:
tests/ad/spn/Test-MtAdUserSpnTotalCount.Tests.ps1 - PowerShell source:
powershell/public/ad/spn/Test-MtAdUserSpnTotalCount.ps1

