AD-USER-06 - DES-only Kerberos user count should be retrievable
Overviewโ
DES is an obsolete Kerberos encryption type with known cryptographic weakness. Accounts limited to DES-only support should be considered legacy debt and prioritized for cleanup.
Control Typeโ
Detective
Security Recommendationโ
Move DES-only accounts to stronger Kerberos encryption types such as AES and eliminate dependencies on deprecated protocols. Validate application compatibility before enforcement.
How the Test Worksโ
This test retrieves Active Directory user data from Get-MtADDomainState and counts accounts whose Kerberos settings indicate DES usage. It checks KerberosEncryptionType when available and falls back to UseDESKeyOnly.
Related Testsโ
Test-MtAdUserDelegationAllowedCountTest-MtAdUserReversibleEncryptionCountTest-MtAdUserNoPreAuthCount
Related linksโ
- Microsoft Defender for Identity: Unsecure account attributes
- ANSSI Active Directory checkpoints: Use of Kerberos with weak encryption
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-USER-06 |
| Severity | High |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserKerberosDesOnlyCount |
| Tags | AD, AD-USER-06, AD.User |
Sourceโ
- Pester test:
tests/ad/user/Test-MtAdUserKerberosDesOnlyCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserKerberosDesOnlyCount.ps1


