Skip to main content
Version: 2.2.1-preview

AD-SPN-07 - User SPN service class count should be retrievable

Overviewโ€‹

Understanding the service classes of SPNs on user accounts helps security teams:

  • Identify service types: Know what services are running under user credentials
  • Assess risk: Some service classes (like MSSQLSvc) are higher-value targets
  • Detect anomalies: Unexpected service classes may indicate unauthorized services
  • Plan migrations: Identify candidates for migration to gMSAs

User accounts with database or application service SPNs are particularly sensitive.

Security Recommendationโ€‹

Review service classes on user accounts:

  • Database services (MSSQLSvc, oracle, postgres) should use gMSAs
  • Web services (HTTP, HTTPS) should run under service accounts or gMSAs
  • Legacy service classes may indicate outdated applications
  • Document all user accounts with SPNs and their purposes

How the Test Worksโ€‹

This test retrieves all user objects with SPNs, extracts the service class from each SPN, and counts the distinct service classes in use.

  • Test-MtAdUserSpnServiceClassUsage - Detailed breakdown of service class usage
  • Test-MtAdUserSpnTotalCount - Total count of user SPNs
  • Test-MtAdComputerSpnServiceClassCount - Computer account service classes

Test Metadataโ€‹

FieldValue
Test IDAD-SPN-07
SeverityInfo
SuiteActive Directory
CategoryAD.SPN
PowerShell testTest-MtAdUserSpnServiceClassCount
TagsAD, AD-SPN-07, AD.SPN

Sourceโ€‹

  • Pester test: tests/ad/spn/Test-MtAdUserSpnServiceClassCount.Tests.ps1
  • PowerShell source: powershell/public/ad/spn/Test-MtAdUserSpnServiceClassCount.ps1