Skip to main content
Version: 2.2.1-preview

AD-SPN-12 - User SPN domain admin count should be retrievable

Overview​

Domain administrator accounts with SPNs represent the highest possible Kerberoasting risk:

  • Maximum privileges: Domain admins have unrestricted access to the entire domain
  • Golden ticket risk: Compromising a domain admin can lead to complete domain compromise
  • Service account misuse: Domain admin accounts should never be used as service accounts
  • Password exposure: SPNs enable offline password cracking attempts

Zero domain admin accounts should have SPNs configured.

Security Recommendation​

If domain admin accounts have SPNs:

  • Immediate action: Remove all SPNs from domain admin accounts
  • Investigate: Determine why SPNs were configured
  • Migrate services: Move services to dedicated service accounts or gMSAs
  • Audit: Review who has domain admin privileges
  • Monitor: Implement alerts for SPN changes to privileged accounts

How the Test Works​

This test identifies domain administrator accounts (using the well-known RID 500) and checks if they have any SPNs configured. Any SPNs found on these accounts are flagged as critical security risks.

  • Test-MtAdUserSpnDomainAdminDetails - Detailed SPN information for domain admins
  • Test-MtAdUserSpnTotalCount - Overall user SPN count
  • Test-MtAdUserSpnServiceClassCount - Service classes on user accounts

Test Metadata​

FieldValue
Test IDAD-SPN-12
SeverityCritical
SuiteActive Directory
CategoryAD.SPN
PowerShell testTest-MtAdUserSpnDomainAdminCount
TagsAD, AD-SPN-12, AD.SPN

Source​

  • Pester test: tests/ad/spn/Test-MtAdUserSpnDomainAdminCount.Tests.ps1
  • PowerShell source: powershell/public/ad/spn/Test-MtAdUserSpnDomainAdminCount.ps1