AD-USER-28 - User delegation configured count should be retrievable
Overviewโ
Delegation on user accounts can be especially risky because user identities are often easier to misuse than computer accounts. Service accounts configured for delegation can become powerful lateral movement pivots.
- Lateral movement risk: Delegation can expand the blast radius of compromise.
- Privilege abuse: User-based services with delegation deserve special scrutiny.
- Exposure tracking: Supports routine review of delegation-enabled identities.
Security Recommendationโ
- Minimize delegation on user accounts.
- Prefer modern and least-privileged service identity patterns.
- Review all delegation-enabled users for valid business justification.
- Prioritize removal of unnecessary unconstrained delegation.
How the Test Worksโ
This test counts user accounts with either TrustedForDelegation or TrustedToAuthForDelegation enabled and breaks out how many have each flag.
Related Testsโ
Test-MtAdUserDelegationDetailsTest-MtAdUserKnownServiceAccountDetails
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-USER-28 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserDelegationConfiguredCount |
| Tags | AD, AD-USER-28, AD.User |
Sourceโ
- Pester test:
tests/ad/user/Test-MtAdUserDelegationConfiguredCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserDelegationConfiguredCount.ps1

