Skip to main content
Version: 2.2.1-preview

AD-SPN-13 - User SPN domain admin details should be retrievable

Overviewโ€‹

Detailed visibility into domain admin SPNs is critical for security incident response:

  • Immediate remediation: Know exactly which SPNs to remove
  • Service identification: Understand what services were improperly configured
  • Attack surface assessment: Evaluate the scope of exposure
  • Compliance violation: Domain admins should never have SPNs

Any SPN on a domain admin account is a critical finding requiring immediate action.

Security Recommendationโ€‹

Immediate actions required:

  1. Remove ALL SPNs from domain administrator accounts
  2. Investigate how and why SPNs were configured
  3. Create dedicated service accounts or gMSAs for the services
  4. Review domain admin membership and remove unnecessary accounts
  5. Implement monitoring for SPN changes to privileged accounts
  6. Consider this a potential security incident requiring investigation

How the Test Worksโ€‹

This test identifies domain administrator accounts and provides detailed information about any SPNs configured on them, including service class, host, FQDN status, and full SPN value for remediation.

  • Test-MtAdUserSpnDomainAdminCount - Counts SPNs on domain admins
  • Test-MtAdUserSpnTotalCount - Overall user SPN analysis
  • Test-MtAdUserSpnUnknownDetails - Unknown SPN details on all users

Test Metadataโ€‹

FieldValue
Test IDAD-SPN-13
SeverityCritical
SuiteActive Directory
CategoryAD.SPN
PowerShell testTest-MtAdUserSpnDomainAdminDetails
TagsAD, AD-SPN-13, AD.SPN

Sourceโ€‹

  • Pester test: tests/ad/spn/Test-MtAdUserSpnDomainAdminDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/spn/Test-MtAdUserSpnDomainAdminDetails.ps1