CTD-000112

AD Domain where Enterprise Key Admins group has full access to the domain

Critical
Active Directory
Credential Access Lateral Movement
v16

Signature Identity

CTD-000112
Threat ID
16
Version
IOE
Indicator Type

Threat Description

Certain versions of Windows Server 2016 Adprep had an issue granting excessive permissions Full Control to the Enterprise Key Admins group. Without the fix applied, this group had permission to replicate all changes from Active Directory, allowing a threat actor with membership to perform the DCSync attack in some environments.

The only other group granted Full Control over the domain root object, besides the SYSTEM principal, is Enterprise Admins. This is also true for child domains. However, the Enterprise Admins group is part of the protected groups safeguarded by AdminSDHolder.
In contrast, the Enterprise Key Admins group is treated like a regular group in the domain. By default, Account Operators are granted explicit Full Control over the Enterprise Key Admins group, allowing many other users to potentially exploit these permissions.

Additionally, the Enterprise Key Admins group has inheritance enabled, which means other possible OU admins might have access to modify its membership. Without the extra protection afforded to other high-privilege groups like Builtin Admins (BA), Domain Admins (DA), and Enterprise Admins (EA), the Enterprise Key Admins group is an easier target for malicious users aiming to compromise the entire forest.

MITRE ATT&CK: Attack Tactics

Credential Access Lateral Movement

D3FEND: Defend Tactics

User Account Permissions

Remediation

To modify permissions with the  Active Directory Users and Computers snap-in:

  1. On the View menu, click Advanced Features.
  2. Right-click the domain object, e.g., company.com.
  3. Click Properties.
  4. On the Security tab, find the Enterprise Key Admins group.
  5. Select it.
  6. Click Remove.
  7. Click Apply.
  8. Click OK.
  9. Close the snap-in.

Frequently Asked Questions

What does AD Domain where Enterprise Key Admins group has full access to the domain mean?

In an Active Directory environment, the Enterprise Key Admins group having full access to the domain root object grants excessive permissions. This allows a threat actor with membership in this group to perform DCSync attacks and compromise the forest.

This condition is rated critical because it enables an attacker to bypass authentication mechanisms, obtain unauthorized access to sensitive data and systems, escalate privileges, move laterally, and access credentials.

An attacker with membership in the Enterprise Key Admins group can use their excessive permissions to perform DCSync attacks. This allows them to obtain unauthorized access to sensitive data and systems, as well as escalate privileges and move laterally.

Cayosoft Guardian continuously monitors the permissions of the Enterprise Key Admins group across the Active Directory environment. When excessive permissions are detected, Guardian flags it as a security issue and provides visibility into the affected objects.

Cayosoft Guardian helps reduce the risk by alerting administrators to modify permissions, remove excessive access, and assist in investigation and response efforts. Additionally, Guardian supports ongoing monitoring to quickly detect if the issue is reintroduced.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Forest-wide
Attack Tactics
Credential Access Lateral Movement
Defend Tactics
User Account Permissions
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical