Skip to main content
Version: 2.2.1-preview

AD-USER-28 - User delegation configured count should be retrievable

Overviewโ€‹

Delegation on user accounts can be especially risky because user identities are often easier to misuse than computer accounts. Service accounts configured for delegation can become powerful lateral movement pivots.

  • Lateral movement risk: Delegation can expand the blast radius of compromise.
  • Privilege abuse: User-based services with delegation deserve special scrutiny.
  • Exposure tracking: Supports routine review of delegation-enabled identities.

Security Recommendationโ€‹

  • Minimize delegation on user accounts.
  • Prefer modern and least-privileged service identity patterns.
  • Review all delegation-enabled users for valid business justification.
  • Prioritize removal of unnecessary unconstrained delegation.

How the Test Worksโ€‹

This test counts user accounts with either TrustedForDelegation or TrustedToAuthForDelegation enabled and breaks out how many have each flag.

  • Test-MtAdUserDelegationDetails
  • Test-MtAdUserKnownServiceAccountDetails

Test Metadataโ€‹

FieldValue
Test IDAD-USER-28
SeverityInfo
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserDelegationConfiguredCount
TagsAD, AD-USER-28, AD.User

Sourceโ€‹

  • Pester test: tests/ad/user/Test-MtAdUserDelegationConfiguredCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserDelegationConfiguredCount.ps1