Skip to content

Delegation Mitigation

Intermediate users should understand that mitigating DCSync and delegation risks requires a combination of strict access controls, protocol hardening, and continuous monitoring. This section outlines actionable strategies to reduce the attack surface associated with these vulnerabilities.


Limiting Delegation Permissions

Constrained Delegation as a Mitigation

Unconstrained delegation should be avoided wherever possible. Instead, use Kerberos constrained delegation, which restricts a service to impersonate only specific users or services.
Example: Configure a service account to delegate only to a specific application via its Service Principal Name (SPN):

Set-ADAccountControl -Identity "svc-secure" -TrustPassword $true
This enables constrained delegation, limiting the service's ability to impersonate users.

Auditing and Monitoring Service Accounts

Regularly audit service accounts for excessive permissions. Use tools like Azure AD Privileged Identity Management (PIM) or Microsoft 365 Defender to track and restrict overprivileged accounts.
Example: Identify service accounts with unconstrained delegation using PowerShell:

Get-ADObject -Filter {objectClass -eq "user"} | Select-Object Name, @{Name="Delegation";Expression={$_.UserAccountControl -band 0x40000}}


Kerberos Constrained Delegation Best Practices

Secure SPN Configuration

Ensure all SPNs are explicitly defined and tied to specific service accounts. Avoid wildcard SPNs (e.g., http/*) which can lead to unintended delegation.
Example: Configure an SPN for a service:

Set-ADServiceAccount -Identity "svc-secure" -PrincipalsAllowedToImpersonate "DOMAIN\user1","DOMAIN\user2"

Protocol Hardening

Disable legacy protocols like NTLM and enforce Kerberos for all authentication. This reduces the risk of downgrade attacks.
Example: Enforce Kerberos via Group Policy:

gpedit.msc > Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > Network Security: LAN Manager authentication level
Set this to Kerberos only.


Additional Mitigations

Least Privilege for Service Accounts

Use Group Managed Service Accounts (gMSAs) or Managed Service Accounts (MSAs) for critical services. These accounts are automatically managed and reduce the risk of credential exposure.
Example: Create a gMSA:

New-ADServiceAccount -Name "gmsa-secure" -DNSName "secure.service.domain" -PrincipalsAllowedToImpersonate "DOMAIN\user1"

Regular Patching and Updates

Ensure all systems are patched against known vulnerabilities (e.g., CVE-2021-40444). Misconfigured or outdated systems are prime targets for DCSync exploitation.


Key takeaways

  • Replace unconstrained delegation with Kerberos constrained delegation, restricting impersonation to specific users/services.
  • Audit service accounts regularly and disable unnecessary permissions.
  • Enforce Kerberos authentication and disable legacy protocols like NTLM.
  • Use gMSAs/MSAs for service accounts to centralize management and reduce credential risks.
  • Apply patches promptly to address vulnerabilities that could enable DCSync or delegation abuse.