logo
search
Security Policy Errors

Should Delegation Be Disabled on Domain Controller Accounts?

Amos GikundaAmos Gikunda Sep 27, 2026 869 views

Question details

The user needs to know whether to follow the Microsoft Secure Score recommendation to disable delegation on domain controller accounts and if it will affect Active Directory.

Should Delegation Be Disabled on Domain Controller Accounts?
Product
Active Directory
Device & OS
Windows Server 2022
Scenario
Reviewing security posture and Microsoft Secure Score recommendations for network domain controllers.
Observed behavior
Microsoft Secure Score suggests disabling delegation on two Windows Server 2022 domain controller computer accounts, raising concerns about potential disruptions.
Before you start

Before modifying delegation settings on your domain controllers, ensure you have a complete backup of your Active Directory state and understand your environment's authentication flows.

Solution 1Recommended

Consult Microsoft Identity Specialists

Because modifying domain controller delegation can impact authentication services, consulting Microsoft Azure and identity specialists is the safest path.

Unconstrained delegation on domain controllers poses a significant security risk, allowing potential attackers to harvest credentials if the machine is compromised. However, disabling it abruptly without verifying service dependencies can break authentication for services relying on Kerberos delegation within your network.

1
Access the Microsoft Azure Q&A Portal

Open your web browser and navigate to the official Microsoft Azure Q&A forum at https://learn.microsoft.com/en-us/answers/tags/133/azure.

2
Post Your Specific Server Configuration

Create a new thread detailing your Windows Server 2022 environment, mentioning the exact Microsoft Secure Score warning. Ask the specialists to help evaluate the potential impact on your specific Active Directory setup before making changes.

Consult Microsoft Identity Specialists
Why does Secure Score flag this?: By default, standard domain controllers do not require unconstrained delegation to function properly. Restricting it prevents unauthorized credential harvesting, but caution is necessary if third-party tools are installed directly on the server.
Free Microsoft Office alternative

Enhance Your Daily Productivity with WPS Office

While you focus on securing complex Active Directory environments, streamline your IT documentation and daily reporting with WPS Office. It provides a lightweight, fast, and familiar workspace that perfectly complements your workflow.

  1. 1. Download the Installer: Visit the official WPS Office website to download the free installation package.
  2. 2. Run the Setup: Execute the downloaded file and follow the brief on-screen instructions to install the software.
  3. 3. Start Documenting: Launch WPS Office to instantly open, edit, and save your Microsoft Office files securely.
Fully compatible with Microsoft Office formats (.docx, .xlsx, .pptx) for seamless document sharing.Lightweight design ensures fast performance without consuming excessive system resources.Familiar user interface makes transitioning to WPS Office effortless.Built-in PDF toolkit makes reviewing and signing IT security policies easy.
microsoft office alternative - wps office

Frequently Asked Questions

What is Kerberos unconstrained delegation?

Kerberos unconstrained delegation is a feature that allows a service to impersonate a user to any other service on the network. If enabled on a compromised machine, an attacker could extract ticket-granting tickets (TGTs), which is why security audits flag it as a risk.

Will disabling delegation break my domain controller?

For standard Active Directory operations, domain controllers do not require computer account delegation. However, if you run other roles, applications, or custom services directly on the domain controller, they might experience authentication failures.

How can I view delegation settings on a domain controller?

Open 'Active Directory Users and Computers' (ADUC), locate your Domain Controllers organizational unit, right-click the computer account, and select 'Properties'. Navigate to the 'Delegation' tab to review the current configuration.