Skip to main content
AD Academy
Delegation in Active Directory
Advanced15 minLast updated: Topic 3 of 4

Constrained Delegation (KCD)

Delegation restricted to a list of services, and what Protocol Transition is.

Not read

What you will learn here

  • Two modes
  • Defense
  • Delegation restricted to a list of services, and what Protocol Transition is.

Worth reading first:Unconstrained Delegation

In you explicitly define which SPNs the server is allowed to impersonate, via the msDS-AllowedToDelegateTo attribute. This is much safer than Unconstrained, but still not free of risk.

שרת Web עם KCD מבקש מה־KDC כרטיס בשם המשתמש (S4U2Self), ואז מבקש כרטיס לשירות המטרה (S4U2Proxy). ה־KDC בודק את msDS-AllowedToDelegateTo לפני שהוא מנפיק כרטיס ל־MSSQLSvc. סיכון: Service Name Substitution — רכיב השירות בכרטיס אינו נאכף, ולכן ניתן להחליף SPN לשירות אחר על אותו שרת. הגנה: הימנעות מ־Protocol Transition, שימוש ב־gMSA, ולא להאציל לחשבונות Tier 0.

Two modes

  • Use only — the user must authenticate to the service via Kerberos (S4U2Proxy only).
  • Use any authentication protocol (Protocol Transition) — the service can issue a ticket on the user's behalf even without the user authenticating via (S4U2Self). This is the dangerous mode.

The risk: the in the list defines a service, but the service component in the ticket is not truly enforced. An attacker who controls an account with and Protocol Transition can perform Service Name Substitution and access additional services on the same target server.

Defense

  • Avoid Protocol Transition unless there's no other option.
  • Grant delegation only to dedicated service accounts with long passwords (gMSA).
  • Never delegate to services running on Tier 0 (DC, ADFS, PKI).
  • Periodically review all objects with msDS-AllowedToDelegateTo.
Architecture and Theory — Under the Hood

restricts impersonation to a defined list of SPNs. But the restriction is on the — not on the service. Whoever controls the account can request a ticket for any SPN on the same target computer.

  • Only — requires a real ticket from the user, no proactive impersonation.
  • Protocol Transition — The server can impersonate an identity by itself via S4U2Self. The dangerous setting.
  • A single approved for CIFS effectively opens access also to HOST, and RPCSS on the same computer.
Practical Configuration (PowerShell / GUI)
# הגדרה מאובטחת: Kerberos Only בלבד
Set-ADUser svc_web -Add @{'msDS-AllowedToDelegateTo'='HTTP/app01.corp.com'}
Set-ADAccountControl svc_web -TrustedToAuthForDelegation $false

# ביקורת: מי מוגדר Protocol Transition
Get-ADObject -LDAPFilter '(userAccountControl:1.2.840.113556.1.4.803:=16777216)' -Properties samAccountName
powershell
Real-world Scenarios in an Organization
  • Application server accessing a file share on behalf of the user.
  • Internal portal against Exchange or SQL.
Diagnosis and Troubleshooting
  • KDC_ERR_BADOPTION — The requested is not in the list or is misspelled.
  • Duplicate in the domain → authentication fails completely. Check with setspn -X.
setspn -X
setspn -L svc_web
bash
Glossary and Quick Command Line
  • S4U2Self = Get a ticket on behalf of a user.
  • S4U2Proxy = Forward it to the target.
  • Substitution — Built-in weakening of .

Check yourself

Which attribute defines classic Constrained Delegation?

Was this page helpful?