CTD-000001

AD domain account’s password set to never expire

Medium
Active Directory
Credential Access
v5

Signature Identity

CTD-000001
Threat ID
5
Version
IOE
Indicator Type

Threat Description

A user account whose password never expires poses a threat to your Active Directory environment. Password rotation reduces the risk and effectiveness of password-based attacks and exploits by shortening the timeframe during which a compromised password may be valid. A threat actor might obtain a password and use it until the password is valid.

NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.

According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Credential Rotation

Remediation

  1. Set the password to expire and force the user to change their password on the next login:
    1. Click Start.
    2. Open Windows Administrative Tools.
    3. Click Active Directory Users and Computers.
    4. Find the user account.
    5. Open it.
    6. On the Account tab uncheck Password never expires.
    7. Enable User must change password at next logon.
    8. Press OK.
  2. Implement regular password rotation for all users.

Frequently Asked Questions

What does AD domain account's password set to never expire mean?

In Active Directory, setting an account's password to never expire means that the password remains valid indefinitely. This allows attackers who obtain a password to use it until the password is changed.

An unexpired password does not grant administrative control, but it enables attackers to maintain persistence and reuse compromised credentials. This increases the risk of successful attacks due to prolonged access and credential reuse.

An attacker who obtains a non-expiring password can use it until the password is changed, allowing them to maintain access to the affected account and reuse compromised credentials. This increases the risk of successful attacks by providing prolonged access.

Cayosoft Guardian continuously monitors the password expiration settings for user accounts across Active Directory, detecting when a password is not set to expire. When an unexpired password is found, Guardian flags it as a security issue so administrators can take action.

Cayosoft Guardian alerts administrators when a non-expiring password is detected, allowing them to set passwords to expire and force users to change their passwords on the next login. This limits the time attackers have to use compromised credentials, reducing the effectiveness of password-based attacks.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access
Defend Tactics
Credential Rotation
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical