allows a service to act on behalf of the user who connected to it. A classic example: a Web server receives a request from the user and needs to access an SQL server on their behalf. Without Delegation, the Web server accesses SQL under its own identity — and the user's permissions are not enforced.
The three types
- — the server receives the user's full and can impersonate them to any service. The oldest and most dangerous type.
- (KCD) — the server can impersonate the user only to a predefined list of SPNs (msDS-AllowedToDelegateTo).
- Resource-Based () — the target resource decides who is allowed to impersonate it (msDS-AllowedToActOnBehalfOfOtherIdentity).
שלוש שכבות מהמסוכן לבטוח: Unconstrained — השרת מקבל TGT מלא ויכול להתחזות לכל שירות בדומיין. Constrained (KCD) — ההאצלה מוגבלת לרשימת SPN במאפיין msDS-AllowedToDelegateTo. Resource-Based (RBCD) — המשאב עצמו מחליט מי רשאי להתחזות, דרך msDS-AllowedToActOnBehalfOfOtherIdentity. ככל שההיקף צר יותר, שטח התקיפה קטן יותר.