Skip to main content
AD Academy
Delegation in Active Directory
Advanced15 minLast updated: Topic 2 of 4

Unconstrained Delegation

The server holds a full TGT of everyone who connects to it — and the danger in that.

Not read

What you will learn here

  • A typical attack path
  • Defense
  • The server holds a full TGT of everyone who connects to it — and the danger in that.

Worth reading first:What is Delegation

When a computer is configured as Trusted for , every user who connects to it sends it a copy of their . The TGT is stored in memory (LSASS) — and anyone who gains local privileges on the server can steal it and impersonate the user across the entire domain.

התוקף הוא Local Admin על שרת שמסומן TRUSTED_FOR_DELEGATION. שלב 1: הפעלת Printer Bug כדי לאלץ את ה־Domain Controller להתחבר לשרת. שלב 2: ה־DC מתחבר חזרה ומשאיר את ה־TGT של חשבון המחשב DC$ בזיכרון LSASS. שלב 3: התוקף גונב את הכרטיס ומבצע Pass-the-Ticket. שלב 4: DCSync ושליטה מלאה בדומיין. הגנה: Protected Users, סימון חשבון כרגיש, וביטול ההאצלה.

A typical attack path

  • The attacker locates a server with (the TRUSTED_FOR_DELEGATION flag).
  • They obtain Local Admin privileges on that server.
  • They force a to connect to the server (for example using the Printer Bug / MS-RPRN).
  • The of the DC's computer account is stored in memory and stolen.
  • With the DC's , can be performed and the domain taken over.

Defense

  • Disable wherever possible and move to or .
  • Mark sensitive accounts as Account is sensitive and cannot be delegated.
  • Add administrator accounts to the Protected Users group.
  • Monitor Event ID 4769 and unusual ticket requests from delegated servers.
Architecture and Theory — Under the Hood

In an Unconstrained server, the client sends its within an Authenticator field, and the server stores it in LSASS memory. From this moment, the server can impersonate any service on the network until the ticket expires.

  • The condition for sending a : the ticket is ok-as-delegate and the user is not Sensitive.
  • Every is Unconstrained by definition — this is normal and built-in.
  • Tickets remain in memory even after the user logs off — up to 10 hours by default.
Practical Configuration (PowerShell / GUI)
# Find servers with Unconstrained (except DCs)
Get-ADComputer -Filter {TrustedForDelegation -eq $true -and PrimaryGroupID -ne 516} -Properties TrustedForDelegation

# Disable and switch to Constrained
Set-ADComputer WEB01 -TrustedForDelegation $false
Set-ADComputer WEB01 -Add @{'msDS-AllowedToDelegateTo'='MSSQLSvc/sql01.corp.com:1433'}
powershell
Real-world Scenarios in an Organization
  • Legacy servers from 2008 that were configured as Unconstrained and remained so.
  • Audit controls: an Unconstrained server should be classified as Tier 0 — equivalent to a DC.
Diagnosis and Troubleshooting
# Are there foreign tickets in server memory?
klist sessions
# Monitoring: Multiple Event 4769 from one computer account to many destinations = suspicious
bash
Glossary and Quick Command Line
  • Printer Bug / SpoolSample — forcing authentication from a DC.
  • Rubeus monitor — listening for incoming TGTs.
  • Mitigation: Protected Users + AccountNotDelegated + disabling Spooler.

Check yourself

Why is Unconstrained Delegation especially dangerous?

Was this page helpful?