Skip to main content
Version: 2.2.1-preview

AD-USER-05 - Delegation-enabled user count should be retrievable

Overviewโ€‹

Delegation-capable user accounts can impersonate users to downstream services. If these accounts are over-privileged or poorly protected, they can become valuable pivot points for privilege escalation and lateral movement.

Security Recommendationโ€‹

Limit delegation to only the accounts that need it, prefer constrained models, and protect delegated accounts with strong authentication, tiering, and monitoring.

How the Test Worksโ€‹

This test retrieves Active Directory user data from Get-MtADDomainState and counts accounts where TrustedForDelegation or TrustedToAuthForDelegation is enabled. The results break out delegation types and show the overall count.

  • Test-MtAdUserNoPreAuthCount
  • Test-MtAdUserKerberosDesOnlyCount
  • Test-MtAdUserPasswordNeverExpiresCount

Test Metadataโ€‹

FieldValue
Test IDAD-USER-05
SeverityHigh
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserDelegationAllowedCount
TagsAD, AD-USER-05, AD.User

Sourceโ€‹

  • Pester test: tests/ad/user/Test-MtAdUserDelegationAllowedCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserDelegationAllowedCount.ps1