Skip to main content
Version: 2.2.1-preview

AD-SPN-08 - User SPN service class usage should be retrievable

Overviewโ€‹

A detailed breakdown of SPN service classes on user accounts enables:

  • Risk prioritization: Identify high-value targets like database services
  • Service inventory: Understand what services run under user credentials
  • Compliance assessment: Ensure services meet security standards
  • Migration planning: Prioritize which services to move to gMSAs first

Database and application services on user accounts pose the highest Kerberoasting risk.

Security Recommendationโ€‹

Based on service class usage:

  • Prioritize migrating database services (MSSQLSvc, oracle) to gMSAs
  • Audit HTTP/HTTPS services running under user accounts
  • Investigate custom or unknown service classes
  • Document legitimate service accounts and their purposes

How the Test Worksโ€‹

This test analyzes all user SPNs, groups them by service class, and provides a count and percentage for each service class, helping you understand your user service account landscape.

  • Test-MtAdUserSpnServiceClassCount - Counts distinct service classes
  • Test-MtAdUserSpnUnknownCount - Identifies unrecognized service classes
  • Test-MtAdComputerSpnServiceClassUsage - Computer account service class usage

Test Metadataโ€‹

FieldValue
Test IDAD-SPN-08
SeverityInfo
SuiteActive Directory
CategoryAD.SPN
PowerShell testTest-MtAdUserSpnServiceClassUsage
TagsAD, AD-SPN-08, AD.SPN

Sourceโ€‹

  • Pester test: tests/ad/spn/Test-MtAdUserSpnServiceClassUsage.Tests.ps1
  • PowerShell source: powershell/public/ad/spn/Test-MtAdUserSpnServiceClassUsage.ps1