AD-SPN-10 - User SPN unknown service class details should be retrievable
Overviewβ
Detailed information about unknown user SPNs is critical for security:
- Immediate action required: User SPNs are prime Kerberoasting targets
- Accountability: Know exactly which users have unknown SPNs
- Investigation: Track down service owners quickly
- Risk assessment: Determine if high-privilege users have unknown SPNs
Unknown SPNs on privileged user accounts represent the highest risk.
Security Recommendationβ
For each unknown user SPN:
- Contact the user or their manager to understand the service
- Verify if the service is legitimate and necessary
- If legitimate, document it and consider migrating to gMSA
- If unauthorized, remove the SPN immediately
- Check if the account has been compromised
How the Test Worksβ
This test analyzes all user SPNs, identifies unknown service classes, and provides detailed information about which users have these SPNs.
Related Testsβ
Test-MtAdUserSpnUnknownCount- Counts unknown service classes on usersTest-MtAdUserSpnDomainAdminDetails- Checks domain admin SPNs specificallyTest-MtAdComputerSpnUnknownDetails- Unknown computer SPN details
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-SPN-10 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.SPN |
| PowerShell test | Test-MtAdUserSpnUnknownDetails |
| Tags | AD, AD-SPN-10, AD.SPN |
Sourceβ
- Pester test:
tests/ad/spn/Test-MtAdUserSpnUnknownDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/spn/Test-MtAdUserSpnUnknownDetails.ps1

