AD-USER-05 - Delegation-enabled user count should be retrievable
Overviewโ
Delegation-capable user accounts can impersonate users to downstream services. If these accounts are over-privileged or poorly protected, they can become valuable pivot points for privilege escalation and lateral movement.
Security Recommendationโ
Limit delegation to only the accounts that need it, prefer constrained models, and protect delegated accounts with strong authentication, tiering, and monitoring.
How the Test Worksโ
This test retrieves Active Directory user data from Get-MtADDomainState and counts accounts where TrustedForDelegation or TrustedToAuthForDelegation is enabled. The results break out delegation types and show the overall count.
Related Testsโ
Test-MtAdUserNoPreAuthCountTest-MtAdUserKerberosDesOnlyCountTest-MtAdUserPasswordNeverExpiresCount
Related linksโ
- Microsoft Defender for Identity: Ensure privileged accounts are not delegated
- ANSSI Active Directory checkpoints: Unconstrained authentication delegation
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-USER-05 |
| Severity | High |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserDelegationAllowedCount |
| Tags | AD, AD-USER-05, AD.User |
Sourceโ
- Pester test:
tests/ad/user/Test-MtAdUserDelegationAllowedCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserDelegationAllowedCount.ps1


