Unconstrained Kerberos Delegation Configured - Active Directory Privilege Escalation Risk

Detects modifications to computer or user accounts in Active Directory where the 'Trusted for Delegation' flag is enabled. Enabling unconstrained delegation allows a compromised account to request and cache Ticket Granting Tickets (TGTs) for any user authenticating to the service, enabling potential privilege escalation and lateral movement.