In you explicitly define which SPNs the server is allowed to impersonate, via the msDS-AllowedToDelegateTo attribute. This is much safer than Unconstrained, but still not free of risk.
שרת Web עם KCD מבקש מה־KDC כרטיס בשם המשתמש (S4U2Self), ואז מבקש כרטיס לשירות המטרה (S4U2Proxy). ה־KDC בודק את msDS-AllowedToDelegateTo לפני שהוא מנפיק כרטיס ל־MSSQLSvc. סיכון: Service Name Substitution — רכיב השירות בכרטיס אינו נאכף, ולכן ניתן להחליף SPN לשירות אחר על אותו שרת. הגנה: הימנעות מ־Protocol Transition, שימוש ב־gMSA, ולא להאציל לחשבונות Tier 0.
Two modes
- Use only — the user must authenticate to the service via Kerberos (S4U2Proxy only).
- Use any authentication protocol (Protocol Transition) — the service can issue a ticket on the user's behalf even without the user authenticating via (S4U2Self). This is the dangerous mode.
The risk: the in the list defines a service, but the service component in the ticket is not truly enforced. An attacker who controls an account with and Protocol Transition can perform Service Name Substitution and access additional services on the same target server.
Defense
- Avoid Protocol Transition unless there's no other option.
- Grant delegation only to dedicated service accounts with long passwords (gMSA).
- Never delegate to services running on Tier 0 (DC, ADFS, PKI).
- Periodically review all objects with msDS-AllowedToDelegateTo.