AD-USER-14 - User SPN count should be retrievable
Overviewโ
User accounts with ServicePrincipalName values are typically used as service accounts. These accounts are important because they may be susceptible to Kerberoasting and often have broad or persistent access.
- Kerberoasting exposure: User SPNs are a common attack target
- Service account discovery: Helps inventory service identities in the domain
- Hardening priority: Supports review of password hygiene, delegation, and logon restrictions
Security Recommendationโ
- Review every user account with an SPN and confirm it is a legitimate service account
- Prefer managed service account options where possible
- Ensure service accounts use strong credential and monitoring controls
How the Test Worksโ
This test counts user objects where the ServicePrincipalName attribute contains one or more values.
Related Testsโ
Test-MtAdUserKnownServiceAccountCount- Identifies service accounts by naming conventionTest-MtAdUserAdminCountCount- Highlights protected user accounts that may need extra scrutiny
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-USER-14 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserSpnSetCount |
| Tags | AD, AD-USER-14, AD.User |
Sourceโ
- Pester test:
tests/ad/user/Test-MtAdUserSpnSetCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserSpnSetCount.ps1

