AD-SPN-08 - User SPN service class usage should be retrievable
Overviewโ
A detailed breakdown of SPN service classes on user accounts enables:
- Risk prioritization: Identify high-value targets like database services
- Service inventory: Understand what services run under user credentials
- Compliance assessment: Ensure services meet security standards
- Migration planning: Prioritize which services to move to gMSAs first
Database and application services on user accounts pose the highest Kerberoasting risk.
Security Recommendationโ
Based on service class usage:
- Prioritize migrating database services (MSSQLSvc, oracle) to gMSAs
- Audit HTTP/HTTPS services running under user accounts
- Investigate custom or unknown service classes
- Document legitimate service accounts and their purposes
How the Test Worksโ
This test analyzes all user SPNs, groups them by service class, and provides a count and percentage for each service class, helping you understand your user service account landscape.
Related Testsโ
Test-MtAdUserSpnServiceClassCount- Counts distinct service classesTest-MtAdUserSpnUnknownCount- Identifies unrecognized service classesTest-MtAdComputerSpnServiceClassUsage- Computer account service class usage
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-SPN-08 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.SPN |
| PowerShell test | Test-MtAdUserSpnServiceClassUsage |
| Tags | AD, AD-SPN-08, AD.SPN |
Sourceโ
- Pester test:
tests/ad/spn/Test-MtAdUserSpnServiceClassUsage.Tests.ps1 - PowerShell source:
powershell/public/ad/spn/Test-MtAdUserSpnServiceClassUsage.ps1

