Skip to main content
Version: 2.2.1-preview

AD-USER-14 - User SPN count should be retrievable

Overviewโ€‹

User accounts with ServicePrincipalName values are typically used as service accounts. These accounts are important because they may be susceptible to Kerberoasting and often have broad or persistent access.

  • Kerberoasting exposure: User SPNs are a common attack target
  • Service account discovery: Helps inventory service identities in the domain
  • Hardening priority: Supports review of password hygiene, delegation, and logon restrictions

Security Recommendationโ€‹

  • Review every user account with an SPN and confirm it is a legitimate service account
  • Prefer managed service account options where possible
  • Ensure service accounts use strong credential and monitoring controls

How the Test Worksโ€‹

This test counts user objects where the ServicePrincipalName attribute contains one or more values.

  • Test-MtAdUserKnownServiceAccountCount - Identifies service accounts by naming convention
  • Test-MtAdUserAdminCountCount - Highlights protected user accounts that may need extra scrutiny

Test Metadataโ€‹

FieldValue
Test IDAD-USER-14
SeverityInfo
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserSpnSetCount
TagsAD, AD-USER-14, AD.User

Sourceโ€‹

  • Pester test: tests/ad/user/Test-MtAdUserSpnSetCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserSpnSetCount.ps1