Kerberos unconstrained delegation is one of those Active Directory configurations that can sit quietly for years and still create a disproportionate amount of risk. It is often introduced to make a legacy application work, then left in place because nobody wants to disturb a fragile dependency. From a defender’s point of view, that makes it…
First seen on securityboulevard.com
Jump to article: securityboulevard.com/2026/08/testing-for-kerberos-unconstrained-delegation-abuse-in-active-directory/
![]()

