Skip to main content
Version: 2.2.1-preview

AD-USER-29 - User delegation details should be retrievable

Overview​

Delegation details on user accounts help defenders quickly identify high-risk service identities and prioritize cleanup.

  • Risk prioritization: Unconstrained delegation is usually more dangerous than protocol transition alone.
  • Account review: User-based service accounts with SPNs and delegation need strong justification.
  • Incident response: Detailed visibility speeds triage during suspected Kerberos abuse.

Security Recommendation​

  • Review each delegation-enabled user for business need, owner, and scope.
  • Remove unnecessary delegation settings.
  • Replace legacy service users with safer identity patterns where possible.
  • Monitor delegation-enabled accounts for unusual logon or ticket activity.

How the Test Works​

This test lists each user with TrustedForDelegation or TrustedToAuthForDelegation enabled and labels the effective delegation type based on the available account flags.

  • Test-MtAdUserDelegationConfiguredCount
  • Test-MtAdUserKnownServiceAccountDetails

Test Metadata​

FieldValue
Test IDAD-USER-29
SeverityInfo
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserDelegationDetails
TagsAD, AD-USER-29, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserDelegationDetails.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserDelegationDetails.ps1