AD-SPN-12 - User SPN domain admin count should be retrievable
Overviewβ
Domain administrator accounts with SPNs represent the highest possible Kerberoasting risk:
- Maximum privileges: Domain admins have unrestricted access to the entire domain
- Golden ticket risk: Compromising a domain admin can lead to complete domain compromise
- Service account misuse: Domain admin accounts should never be used as service accounts
- Password exposure: SPNs enable offline password cracking attempts
Zero domain admin accounts should have SPNs configured.
Security Recommendationβ
If domain admin accounts have SPNs:
- Immediate action: Remove all SPNs from domain admin accounts
- Investigate: Determine why SPNs were configured
- Migrate services: Move services to dedicated service accounts or gMSAs
- Audit: Review who has domain admin privileges
- Monitor: Implement alerts for SPN changes to privileged accounts
How the Test Worksβ
This test identifies domain administrator accounts (using the well-known RID 500) and checks if they have any SPNs configured. Any SPNs found on these accounts are flagged as critical security risks.
Related Testsβ
Test-MtAdUserSpnDomainAdminDetails- Detailed SPN information for domain adminsTest-MtAdUserSpnTotalCount- Overall user SPN countTest-MtAdUserSpnServiceClassCount- Service classes on user accounts
Related linksβ
- Microsoft Defender for Identity: Unsecure account attributes
- ANSSI Active Directory checkpoints: Privileged accounts with SPN
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-SPN-12 |
| Severity | Critical |
| Suite | Active Directory |
| Category | AD.SPN |
| PowerShell test | Test-MtAdUserSpnDomainAdminCount |
| Tags | AD, AD-SPN-12, AD.SPN |
Sourceβ
- Pester test:
tests/ad/spn/Test-MtAdUserSpnDomainAdminCount.Tests.ps1 - PowerShell source:
powershell/public/ad/spn/Test-MtAdUserSpnDomainAdminCount.ps1


