A transit engineer finds unconstrained delegation configured on a server account. How should this be treated in the assessment narrative?
Select an answer to reveal the explanation.
Short Explanation
Unconstrained delegation is like giving a server a blank 'impersonate anyone' sticky note. Even without walking through abuse steps on the report, call out the misconfig class — it is a big identity risk theme.
Full Explanation
Dangerous Kerberos delegation settings, including unconstrained delegation on server accounts, are a well-known Active Directory risk class. They can enable powerful impersonation paths when abused and therefore deserve clear reporting as a misconfiguration theme. The finding stands on configuration risk even when step-by-step exploit detail is omitted from deliverables. It does not mean Kerberos is obsolete, nor does it alone authorize undirected domain-controller compromise.