AD-USER-06 - DES-only Kerberos user count should be retrievable
Overviewβ
DES is an obsolete Kerberos encryption type with known cryptographic weakness. Accounts limited to DES-only support should be considered legacy debt and prioritized for cleanup.
Security Recommendationβ
Move DES-only accounts to stronger Kerberos encryption types such as AES and eliminate dependencies on deprecated protocols. Validate application compatibility before enforcement.
How the Test Worksβ
This test retrieves Active Directory user data from Get-MtADDomainState and counts accounts whose Kerberos settings indicate DES usage. It checks KerberosEncryptionType when available and falls back to UseDESKeyOnly.
Related Testsβ
Test-MtAdUserDelegationAllowedCountTest-MtAdUserReversibleEncryptionCountTest-MtAdUserNoPreAuthCount
Related linksβ
- Microsoft Defender for Identity: Unsecure account attributes
- ANSSI Active Directory checkpoints: Use of Kerberos with weak encryption
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-06 |
| Severity | High |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserKerberosDesOnlyCount |
| Tags | AD, AD-USER-06, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserKerberosDesOnlyCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserKerberosDesOnlyCount.ps1


