Skip to main content
Version: 2.2.1-preview

AD-USER-06 - DES-only Kerberos user count should be retrievable

Overview​

DES is an obsolete Kerberos encryption type with known cryptographic weakness. Accounts limited to DES-only support should be considered legacy debt and prioritized for cleanup.

Security Recommendation​

Move DES-only accounts to stronger Kerberos encryption types such as AES and eliminate dependencies on deprecated protocols. Validate application compatibility before enforcement.

How the Test Works​

This test retrieves Active Directory user data from Get-MtADDomainState and counts accounts whose Kerberos settings indicate DES usage. It checks KerberosEncryptionType when available and falls back to UseDESKeyOnly.

  • Test-MtAdUserDelegationAllowedCount
  • Test-MtAdUserReversibleEncryptionCount
  • Test-MtAdUserNoPreAuthCount

Test Metadata​

FieldValue
Test IDAD-USER-06
SeverityHigh
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserKerberosDesOnlyCount
TagsAD, AD-USER-06, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserKerberosDesOnlyCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserKerberosDesOnlyCount.ps1