Skip to main content
AD Academy
Delegation in Active Directory
Advanced16 minLast updated: Topic 4 of 4

Resource-Based Constrained Delegation (RBCD)

Delegation determined by the resource itself — and why it's a popular attack path.

Not read

What you will learn here

  • Why attackers love RBCD
  • Defense
  • Delegation determined by the resource itself — and why it's a popular attack path.

Worth reading first:Constrained Delegation (KCD)

In , the decision moves to the resource: the target computer defines in the msDS-AllowedToActOnBehalfOfOtherIdentity attribute who is allowed to impersonate it. The administrative advantage: Admin permissions are not needed to configure delegation — control over the target object is enough.

שלב 1: ניצול MachineAccountQuota כדי ליצור חשבון מחשב EVIL-PC$ בשליטת התוקף. שלב 2: עם הרשאת GenericWrite על TARGET-PC כותבים את msDS-AllowedToActOnBehalfOfOtherIdentity כך ש־EVIL-PC$ רשאי להתחזות. שלב 3: בקשת S4U מפיקה כרטיס בתור Administrator וגישה מלאה ל־TARGET-PC. הגנה: MachineAccountQuota=0, ניטור אירוע 5136, ו־Protected Users. BloodHound מסייע לאתר הרשאות כתיבה על אובייקטי מחשב.

Why attackers love RBCD

  • By default, every domain user can join up to 10 computers () and create a computer account under their control.
  • If the attacker has write permission on the target computer object — they set on it in favor of the account they created.
  • They then request an S4U ticket and impersonate the local Administrator on that computer.
# Check who is allowed to impersonate a specific computer
Get-ADComputer TARGET-PC -Properties PrincipalsAllowedToDelegateToAccount

# Clear suspicious RBCD setting
Set-ADComputer TARGET-PC -PrincipalsAllowedToDelegateToAccount $null
powershell

Defense

  • Lower to 0 and delegate computer joining to a dedicated team.
  • Check write permissions (GenericWrite / WriteDACL) on computer objects — helps map this.
  • Monitor changes to the msDS-AllowedToActOnBehalfOfOtherIdentity attribute (Event ID 5136).
  • Place sensitive accounts in Protected Users and mark them as unable to be delegated.
Architecture and Theory — Under the Hood

In , control shifts to the target: the computer holds the msDS-AllowedToActOnBehalfOfOtherIdentity attribute — a binary Security Descriptor with a list of authorized SIDs. A management advantage, but a security risk if someone has write permissions on the computer object.

  • Anyone with GenericWrite / WriteDacl / GenericAll on a computer — can write the attribute and take control of it.
  • The attacker needs an account with an . =10 allows any user to create a computer.
  • No Admin or Reboot required — which is why it's a preferred technique in Red Team.
Practical Configuration (PowerShell / GUI)
# Legitimate Definition
Set-ADComputer FILE01 -PrincipalsAllowedToDelegateToAccount (Get-ADComputer WEB01)

# Audit - Who is allowed to act on behalf of whom
Get-ADComputer -Filter * -Properties PrincipalsAllowedToDelegateToAccount |
  Where-Object { $_.PrincipalsAllowedToDelegateToAccount }

# Block computer creation by regular users
Set-ADDomain -Identity corp.com -Replace @{'ms-DS-MachineAccountQuota'='0'}
powershell
Real-world Scenarios in an Organization
  • Migrating applications to a new SQL without touching the application account.
  • Moving from an old web server to a new one — the target itself authorizes the new server.
Diagnosis and Troubleshooting
  • Attribute change does not take effect for ~15 minutes due to ticket cache — klist purge speeds it up.
Glossary and Quick Command Line
  • PrincipalsAllowedToDelegateToAccount — The friendly form of the attribute.
  • Rubeus s4u — The classic tool for exploitation.
  • Protects: Authentication Policies + Silos.

Check yourself

Who determines the permission in Resource-Based Constrained Delegation?

Was this page helpful?