Skip to main content
Version: 2.3.0

AD-USER-05 - Delegation-enabled user count should be retrievable

Overview​

Delegation-capable user accounts can impersonate users to downstream services. If these accounts are over-privileged or poorly protected, they can become valuable pivot points for privilege escalation and lateral movement.

Control Type​

Detective

Security Recommendation​

Limit delegation to only the accounts that need it, prefer constrained models, and protect delegated accounts with strong authentication, tiering, and monitoring.

How the Test Works​

This test retrieves Active Directory user data from Get-MtADDomainState and counts accounts where TrustedForDelegation or TrustedToAuthForDelegation is enabled. The results break out delegation types and show the overall count.

  • Test-MtAdUserNoPreAuthCount
  • Test-MtAdUserKerberosDesOnlyCount
  • Test-MtAdUserPasswordNeverExpiresCount

Test Metadata​

FieldValue
Test IDAD-USER-05
SeverityHigh
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserDelegationAllowedCount
TagsAD, AD-USER-05, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserDelegationAllowedCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserDelegationAllowedCount.ps1