Skip to main content
AD Academy
Delegation in Active Directory
Intermediate12 minLast updated: Topic 1 of 4

What is Delegation

Why a server needs to impersonate a user, and what that means from a security standpoint.

Not read

What you will learn here

  • The three types
  • How to find accounts with Delegation
  • Why a server needs to impersonate a user, and what that means from a security standpoint.

allows a service to act on behalf of the user who connected to it. A classic example: a Web server receives a request from the user and needs to access an SQL server on their behalf. Without Delegation, the Web server accesses SQL under its own identity — and the user's permissions are not enforced.

The three types

  • — the server receives the user's full and can impersonate them to any service. The oldest and most dangerous type.
  • (KCD) — the server can impersonate the user only to a predefined list of SPNs (msDS-AllowedToDelegateTo).
  • Resource-Based () — the target resource decides who is allowed to impersonate it (msDS-AllowedToActOnBehalfOfOtherIdentity).

שלוש שכבות מהמסוכן לבטוח: Unconstrained — השרת מקבל TGT מלא ויכול להתחזות לכל שירות בדומיין. Constrained (KCD) — ההאצלה מוגבלת לרשימת SPN במאפיין msDS-AllowedToDelegateTo. Resource-Based (RBCD) — המשאב עצמו מחליט מי רשאי להתחזות, דרך msDS-AllowedToActOnBehalfOfOtherIdentity. ככל שההיקף צר יותר, שטח התקיפה קטן יותר.

How to find accounts with Delegation

# Accounts with Unconstrained Delegation
Get-ADComputer -Filter {TrustedForDelegation -eq $true} -Properties TrustedForDelegation

# Accounts with Constrained Delegation
Get-ADObject -Filter {msDS-AllowedToDelegateTo -like "*"} -Properties msDS-AllowedToDelegateTo
powershell
Architecture and Theory — Under the Hood

was born from the Double Hop problem: a Web server receives a user's ticket, but the ticket is only valid for the Web service itself. To access SQL on another server on behalf of the user, explicit impersonation permission is required.

  • S4U2Self — The service requests a ticket for itself from the KDC on behalf of any user.
  • S4U2Proxy — The service uses this ticket to request a ticket for the target service.
  • TrustedForDelegation / TrustedToAuthForDelegation — flags in userAccountControl that determine what is allowed.
  • msDS-AllowedToDelegateTo — the list of SPNs to which impersonation is allowed ().
  • msDS-AllowedToActOnBehalfOfOtherIdentity — the reverse: the target defines who is authorized ().
Practical Configuration (PowerShell / GUI)
# Mapping all Delegation types in the domain
Get-ADObject -LDAPFilter '(|(msDS-AllowedToDelegateTo=*)(userAccountControl:1.2.840.113556.1.4.803:=524288)(msDS-AllowedToActOnBehalfOfOtherIdentity=*))' -Properties samAccountName,msDS-AllowedToDelegateTo

# Sensitive accounts - complete impersonation blocking
Set-ADUser -Identity da_admin -AccountNotDelegated $true
Add-ADGroupMember -Identity 'Protected Users' -Members da_admin
powershell
Real-world Scenarios in an Organization
  • IIS + SQL: an internal application running under the user's identity against the database.
  • SharePoint and Reporting Services — classic consumers.
  • Old printers and file servers configured as Unconstrained years ago and forgotten — a common security debt.
Diagnosis and Troubleshooting
  • No for the target service → S4U2Proxy fails with KDC_ERR_S_PRINCIPAL_UNKNOWN.
  • Member of Protected Users or marked Sensitive → impersonation will be intentionally blocked.
  • Real-time check: klist on the intermediate server — does a forwardable ticket for the target appear?
klist purge; klist get MSSQLSvc/sql01.corp.com:1433
bash
Glossary and Quick Command Line
  • Double Hop — User → Server A → Server B.
  • UAC bit 524288 (0x80000) = Unconstrained.
  • UAC bit 16777216 (0x1000000) = Protocol Transition.
  • Protected Users = blanket protection against impersonation and .

Check yourself

What is the purpose of Delegation in AD?

Was this page helpful?