Area 03 / 12
Delegation
Kerberos delegation lets a service act as a user, and misconfigured delegation lets an attacker act as anyone — including a domain admin. This area finds and removes unconstrained delegation, tightens constrained and resource-based delegation, and marks privileged accounts as sensitive so they can never be delegated.
Start the pathLearning path
0/4 done- 01Active Directory delegation: finding and fixing risky trustsAudit unconstrained, constrained, and resource-based constrained delegation in Active Directory, and lock down privileged accounts against abuse.
- 02Remove unconstrained delegation from AD serversFind every non-DC account trusted for unconstrained delegation, map what depends on it, and migrate to constrained delegation or RBCD without outages.
- 03Constrained delegation and RBCD done safely in ADConfigure KCD and RBCD without new attack paths: protocol transition, SPN scoping, and auditing who can write msDS-AllowedToActOnBehalfOfOtherIdentity.
- 04Set ms-DS-MachineAccountQuota to 0 and delegate joinsStop any domain user from creating computer accounts: set ms-DS-MachineAccountQuota to 0, find who relies on it, and delegate domain join to an OU.