AD-SPN-11 - User SPN non-FQDN hosts should be retrievable
Overviewβ
User account SPNs with non-FQDN hosts can cause:
- Authentication failures: Kerberos may fail to resolve short names
- Cross-domain issues: Non-FQDNs don't work across domain trusts
- Service disruptions: Applications may fail to authenticate
- Configuration drift: Indicates inconsistent SPN management
Since user accounts with SPNs are already high-value targets, ensuring proper FQDN configuration is essential.
Security Recommendationβ
Review and fix non-FQDN user SPNs:
- Update SPNs to use fully qualified domain names
- Establish SPN registration standards
- Use FQDNs consistently for all service principal names
- Consider this as part of a migration to gMSAs
How the Test Worksβ
This test parses all user SPNs and checks if the host portion contains a dot (indicating FQDN format). SPNs without dots in the host portion are flagged as non-FQDN.
Related Testsβ
Test-MtAdComputerSpnNonFqdnHosts- Checks computer SPNs for non-FQDN hostsTest-MtAdUserSpnTotalCount- Overall user SPN analysis
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-SPN-11 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.SPN |
| PowerShell test | Test-MtAdUserSpnNonFqdnHosts |
| Tags | AD, AD-SPN-11, AD.SPN |
Sourceβ
- Pester test:
tests/ad/spn/Test-MtAdUserSpnNonFqdnHosts.Tests.ps1 - PowerShell source:
powershell/public/ad/spn/Test-MtAdUserSpnNonFqdnHosts.ps1

