AD-USER-07 - No pre-authentication user count should be retrievable
Overviewβ
Accounts that do not require Kerberos pre-authentication are directly exposed to AS-REP roasting. Attackers can request offline-crackable material without first proving knowledge of the password.
Security Recommendationβ
Require pre-authentication for all accounts unless there is a justified exception. Review and remove legacy settings that disable this protection.
How the Test Worksβ
This test retrieves Active Directory user data from Get-MtADDomainState and counts users where DoesNotRequirePreAuth = $true or the corresponding userAccountControl bit is set.
Related Testsβ
Test-MtAdUserDelegationAllowedCountTest-MtAdUserKerberosDesOnlyCountTest-MtAdUserPasswordNotRequiredCount
Related linksβ
- Microsoft Defender for Identity: Unsecure account attributes
- ANSSI Active Directory checkpoints: Kerberos preauthentication disabled
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-07 |
| Severity | High |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserNoPreAuthCount |
| Tags | AD, AD-USER-07, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserNoPreAuthCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserNoPreAuthCount.ps1


