Skip to main content
Version: 2.3.0

AD-USER-06 - DES-only Kerberos user count should be retrievable

Overviewโ€‹

DES is an obsolete Kerberos encryption type with known cryptographic weakness. Accounts limited to DES-only support should be considered legacy debt and prioritized for cleanup.

Control Typeโ€‹

Detective

Security Recommendationโ€‹

Move DES-only accounts to stronger Kerberos encryption types such as AES and eliminate dependencies on deprecated protocols. Validate application compatibility before enforcement.

How the Test Worksโ€‹

This test retrieves Active Directory user data from Get-MtADDomainState and counts accounts whose Kerberos settings indicate DES usage. It checks KerberosEncryptionType when available and falls back to UseDESKeyOnly.

  • Test-MtAdUserDelegationAllowedCount
  • Test-MtAdUserReversibleEncryptionCount
  • Test-MtAdUserNoPreAuthCount

Test Metadataโ€‹

FieldValue
Test IDAD-USER-06
SeverityHigh
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserKerberosDesOnlyCount
TagsAD, AD-USER-06, AD.User

Sourceโ€‹

  • Pester test: tests/ad/user/Test-MtAdUserKerberosDesOnlyCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserKerberosDesOnlyCount.ps1