AD-SPN-13 - User SPN domain admin details should be retrievable
Overviewโ
Detailed visibility into domain admin SPNs is critical for security incident response:
- Immediate remediation: Know exactly which SPNs to remove
- Service identification: Understand what services were improperly configured
- Attack surface assessment: Evaluate the scope of exposure
- Compliance violation: Domain admins should never have SPNs
Any SPN on a domain admin account is a critical finding requiring immediate action.
Security Recommendationโ
Immediate actions required:
- Remove ALL SPNs from domain administrator accounts
- Investigate how and why SPNs were configured
- Create dedicated service accounts or gMSAs for the services
- Review domain admin membership and remove unnecessary accounts
- Implement monitoring for SPN changes to privileged accounts
- Consider this a potential security incident requiring investigation
How the Test Worksโ
This test identifies domain administrator accounts and provides detailed information about any SPNs configured on them, including service class, host, FQDN status, and full SPN value for remediation.
Related Testsโ
Test-MtAdUserSpnDomainAdminCount- Counts SPNs on domain adminsTest-MtAdUserSpnTotalCount- Overall user SPN analysisTest-MtAdUserSpnUnknownDetails- Unknown SPN details on all users
Related linksโ
- Microsoft Defender for Identity: Unsecure account attributes
- ANSSI Active Directory checkpoints: Privileged accounts with SPN
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-SPN-13 |
| Severity | Critical |
| Suite | Active Directory |
| Category | AD.SPN |
| PowerShell test | Test-MtAdUserSpnDomainAdminDetails |
| Tags | AD, AD-SPN-13, AD.SPN |
Sourceโ
- Pester test:
tests/ad/spn/Test-MtAdUserSpnDomainAdminDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/spn/Test-MtAdUserSpnDomainAdminDetails.ps1


