Skip to main content
Version: 2.2.1-preview

AD-SPN-09 - User SPN unknown service class count should be retrievable

Overview​

Unknown SPN service classes on user accounts require immediate attention because:

  • High risk: User accounts with SPNs are Kerberoasting targets
  • Shadow IT: Unknown services may bypass security controls
  • Misconfigurations: Could indicate improper SPN registration
  • Compliance issues: Unauthorized services violate security policies

User accounts are preferred targets for Kerberoasting, making unknown SPNs on these accounts particularly concerning.

Security Recommendation​

Investigate all unknown SPNs on user accounts:

  • Determine the service owner and business justification
  • Verify if the service requires a user account or can use gMSA
  • Check for misconfigurations or typos
  • Remove unauthorized SPNs immediately
  • Document approved custom SPNs

How the Test Works​

This test compares discovered user SPN service classes against a database of known SPNs and flags any unrecognized service classes for investigation.

  • Test-MtAdUserSpnUnknownDetails - Detailed information about unknown user SPNs
  • Test-MtAdComputerSpnUnknownCount - Unknown SPNs on computer accounts
  • Test-MtAdUserSpnServiceClassCount - All user SPN service classes

Test Metadata​

FieldValue
Test IDAD-SPN-09
SeverityInfo
SuiteActive Directory
CategoryAD.SPN
PowerShell testTest-MtAdUserSpnUnknownCount
TagsAD, AD-SPN-09, AD.SPN

Source​

  • Pester test: tests/ad/spn/Test-MtAdUserSpnUnknownCount.Tests.ps1
  • PowerShell source: powershell/public/ad/spn/Test-MtAdUserSpnUnknownCount.ps1