Stop AD Threats As They Happen
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
Certain versions of Windows Server 2016 Adprep had an issue granting excessive permissions Full Control to the Enterprise Key Admins group. Without the fix applied, this group had permission to replicate all changes from Active Directory, allowing a threat actor with membership to perform the DCSync attack in some environments.
The only other group granted Full Control over the domain root object, besides the SYSTEM principal, is Enterprise Admins. This is also true for child domains. However, the Enterprise Admins group is part of the protected groups safeguarded by AdminSDHolder.
In contrast, the Enterprise Key Admins group is treated like a regular group in the domain. By default, Account Operators are granted explicit Full Control over the Enterprise Key Admins group, allowing many other users to potentially exploit these permissions.
Additionally, the Enterprise Key Admins group has inheritance enabled, which means other possible OU admins might have access to modify its membership. Without the extra protection afforded to other high-privilege groups like Builtin Admins (BA), Domain Admins (DA), and Enterprise Admins (EA), the Enterprise Key Admins group is an easier target for malicious users aiming to compromise the entire forest.
D3FEND: Defend Tactics
To modify permissions with the Active Directory Users and Computers snap-in:
company.com.In an Active Directory environment, the Enterprise Key Admins group having full access to the domain root object grants excessive permissions. This allows a threat actor with membership in this group to perform DCSync attacks and compromise the forest.
This condition is rated critical because it enables an attacker to bypass authentication mechanisms, obtain unauthorized access to sensitive data and systems, escalate privileges, move laterally, and access credentials.
An attacker with membership in the Enterprise Key Admins group can use their excessive permissions to perform DCSync attacks. This allows them to obtain unauthorized access to sensitive data and systems, as well as escalate privileges and move laterally.
Cayosoft Guardian continuously monitors the permissions of the Enterprise Key Admins group across the Active Directory environment. When excessive permissions are detected, Guardian flags it as a security issue and provides visibility into the affected objects.
Cayosoft Guardian helps reduce the risk by alerting administrators to modify permissions, remove excessive access, and assist in investigation and response efforts. Additionally, Guardian supports ongoing monitoring to quickly detect if the issue is reintroduced.
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack