Stop AD Threats As They Happen
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
Non-configurable settings to the TGTs expiration are established for every account in the Protected Users group. Normally, the domain controller sets the TGTs lifetime and renewal, based on the domain policies, Maximum lifetime for user ticket and Maximum lifetime for user ticket renewal. For the Protected Users group, 600 minutes is set for these domain policies. Using Protected Users for privileged user accounts limits attack surface, eliminating some of the attack paths that can be employed by a threat actor.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.
D3FEND: Defend Tactics
To add users to Protected users group:
Privileged Active Directory users are allowed to use insecure authentication protocols, such as NTLM or DES/RC4 encryption types in Kerberos pre-authentication. This allows attackers to exploit these weaknesses and access the users' credentials.
This vulnerability enables attackers to obtain privileged accounts' credentials, which can be used for lateral movement within the domain. The exposure of these credentials increases the risk of unauthorized access and compromise due to the attacker's ability to bypass authentication mechanisms.
Attackers can use insecure authentication protocols to obtain privileged accounts' credentials, which can be used for password cracking or other forms of credential access attacks. This allows the attacker to gain elevated privileges and move laterally within the domain by exploiting the exposed credentials.
Cayosoft Guardian continuously monitors the authentication settings for privileged Active Directory users, detecting when they are allowed to use insecure authentication protocols. When a vulnerable account is found, Guardian flags it as a security issue and provides visibility into the affected accounts.
Cayosoft Guardian alerts administrators to disable insecure authentication protocols for privileged users, limiting the exposure and making it more difficult for attackers to access privileged accounts' credentials. This reduces the risk of credential access attacks and lateral movement within the domain by supporting investigation and response efforts.
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack