STIGQter STIGQter: STIG Summary: Active Directory Domain Security Technical Implementation Guide Version: 3 Release: 7 Benchmark Date: 01 Apr 2026:

Delegation of privileged accounts must be prohibited.

DISA Rule

SV-243470r959010_rule

Vulnerability Number

V-243470

Group Title

SRG-OS-000480

Rule Version

AD.0005

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Open Active Directory Users and Computers. View the properties of all privileged accounts. Under the Account tab, select "Account is sensitive and cannot be delegated" in the Account Options section.

Check Contents

Review the properties of all privileged accounts in Active Directory Users and Computers. Under the Account tab, verify "Account is sensitive and cannot be delegated" is selected in the Account Options section. If delegation is not prohibited for any privileged account, this is a finding.

Vulnerability Number

V-243470

Documentable

False

Rule Version

AD.0005

Severity Override Guidance

Review the properties of all privileged accounts in Active Directory Users and Computers. Under the Account tab, verify "Account is sensitive and cannot be delegated" is selected in the Account Options section. If delegation is not prohibited for any privileged account, this is a finding.

Check Content Reference

M

Target Key

5406