Skip to main content
Version: 2.2.1-preview

AD-SPN-10 - User SPN unknown service class details should be retrievable

Overview​

Detailed information about unknown user SPNs is critical for security:

  • Immediate action required: User SPNs are prime Kerberoasting targets
  • Accountability: Know exactly which users have unknown SPNs
  • Investigation: Track down service owners quickly
  • Risk assessment: Determine if high-privilege users have unknown SPNs

Unknown SPNs on privileged user accounts represent the highest risk.

Security Recommendation​

For each unknown user SPN:

  1. Contact the user or their manager to understand the service
  2. Verify if the service is legitimate and necessary
  3. If legitimate, document it and consider migrating to gMSA
  4. If unauthorized, remove the SPN immediately
  5. Check if the account has been compromised

How the Test Works​

This test analyzes all user SPNs, identifies unknown service classes, and provides detailed information about which users have these SPNs.

  • Test-MtAdUserSpnUnknownCount - Counts unknown service classes on users
  • Test-MtAdUserSpnDomainAdminDetails - Checks domain admin SPNs specifically
  • Test-MtAdComputerSpnUnknownDetails - Unknown computer SPN details

Test Metadata​

FieldValue
Test IDAD-SPN-10
SeverityInfo
SuiteActive Directory
CategoryAD.SPN
PowerShell testTest-MtAdUserSpnUnknownDetails
TagsAD, AD-SPN-10, AD.SPN

Source​

  • Pester test: tests/ad/spn/Test-MtAdUserSpnUnknownDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/spn/Test-MtAdUserSpnUnknownDetails.ps1