Forum Discussion
Deleted
Jul 23, 2019Enable Unconstrained Kerberos Delegation
Hi there,
By default the group ''Account Operators'' is often used, despite that Microsoft recommend it to keep it empty, but this group has wide permissions in the domain. All the users in Account Operators could enable the Unconstrained Kerberos Delegation on servers, because they are granted the GenericAll permission on these computer objects.
I tried to find some additional information about it to see if ATA picks this up. I couldn't find it, but there could be a chance that I just overlooked it. So I was wondering if you guys would detect, when someone decided to turn this setting on?
Here is the event log that will be generated.
- EliOfek
Microsoft
Deleted , as far as I know there is no such detection.
Tali Ash , Can you confirm?
you can find a list of alert types in this link:
https://docs.microsoft.com/en-us/azure-advanced-threat-protection/suspicious-activity-guide
This is updated from time to time when we add more detections.
- Deleted
EliOfekDo you consider to add this detection rule to it?