Skip to content

Glossary

Unconstrained delegation

Unconstrained delegation lets a server cache and reuse any user's full Kerberos TGT, creating a high-value target for attackers.

Unconstrained delegation is a legacy Kerberos delegation model that allows a trusted server to impersonate any user who authenticates to it for access to any other resource in the domain. To do this, the domain controller embeds a copy of the user's Ticket Granting Ticket (TGT) inside the service ticket presented to that server, and the server caches it in memory for reuse on the user's behalf, without any restriction on which downstream services it can be used against.

This matters because compromising a server configured with unconstrained delegation can yield the cached TGTs of every user who has authenticated to it, including domain administrators, effectively handing an attacker their full credentials. The recommended mitigation is eliminating unconstrained delegation wherever possible in favor of constrained or resource-based constrained delegation, marking sensitive accounts as "cannot be delegated," and closely monitoring servers still configured this way.

See Active Directory delegation.