Forum Discussion

Deleted's avatar
Deleted
Jul 23, 2019

Enable Unconstrained Kerberos Delegation

Hi there,

 

By default the group ''Account Operators'' is often used, despite that Microsoft recommend it to keep it empty, but this group has wide permissions in the domain. All the users in Account Operators could enable the Unconstrained Kerberos Delegation on servers, because they are granted the GenericAll permission on these computer objects.

 

I tried to find some additional information about it to see if ATA picks this up. I couldn't find it, but there could be a chance that I just overlooked it. So I was wondering if you guys would detect, when someone decided to turn this setting on?

 

 

Here is the event log that will be generated.

 

 

 

Resources