Skip to content

Glossary

Resource-based constrained delegation

Resource-based constrained delegation (RBCD) lets a resource define which accounts may impersonate users to it, which attackers can abuse if misconfigured.

Resource-Based Constrained Delegation (RBCD) is a Kerberos delegation model, introduced with Windows Server 2012, where the trust decision is configured on the target resource itself, via its msDS-AllowedToActOnBehalfOfOtherIdentity attribute, rather than on the front-end account requesting delegation. This design was intended to give resource owners more control, but it also means that anyone with write access to that attribute on a computer object can grant an arbitrary account the right to impersonate other users against it.

This matters because attackers who obtain the ability to create or control computer objects (any authenticated user can create up to ten by default, through ms-DS-MachineAccountQuota) can configure RBCD on a target machine and then impersonate privileged users to compromise it, all without ever touching a password. Mitigation includes restricting who can create computer objects or modify this attribute, auditing changes to it, and treating any unexpected RBCD configuration as a compromise indicator.

See Active Directory delegation.