AD-USER-05 - Delegation-enabled user count should be retrievable
Overviewβ
Delegation-capable user accounts can impersonate users to downstream services. If these accounts are over-privileged or poorly protected, they can become valuable pivot points for privilege escalation and lateral movement.
Control Typeβ
Detective
Security Recommendationβ
Limit delegation to only the accounts that need it, prefer constrained models, and protect delegated accounts with strong authentication, tiering, and monitoring.
How the Test Worksβ
This test retrieves Active Directory user data from Get-MtADDomainState and counts accounts where TrustedForDelegation or TrustedToAuthForDelegation is enabled. The results break out delegation types and show the overall count.
Related Testsβ
Test-MtAdUserNoPreAuthCountTest-MtAdUserKerberosDesOnlyCountTest-MtAdUserPasswordNeverExpiresCount
Related linksβ
- Microsoft Defender for Identity: Ensure privileged accounts are not delegated
- ANSSI Active Directory checkpoints: Unconstrained authentication delegation
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-05 |
| Severity | High |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserDelegationAllowedCount |
| Tags | AD, AD-USER-05, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserDelegationAllowedCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserDelegationAllowedCount.ps1


