A city finds unconstrained Kerberos authentication delegation enabled on a web server account. Why is that significant?
Select an answer to reveal the explanation.
Short Explanation
Unconstrained delegation on a web box is like giving the front desk a master key that copies every visitor's badge. Compromise that server and impersonation options explode. Review and remove dangerous delegation on app tiers.
Full Explanation
Unconstrained delegation allows a compromised service to impersonate users more broadly than necessary, amplifying the value of controlling that host. Web and application servers are common, Internet-facing or user-facing targets where this misconfiguration is especially costly. Delegation attributes are actionable, not mere decoration, and they can appear on member servers. Flag and prioritize remediation of dangerous delegation on non-DC application accounts.