CTD-000079

Privileged AD user not protected from using unsecure authentication methods

High
Active Directory
Credential Access
v23

Signature Identity

CTD-000079
Threat ID
23
Version
IOE
Indicator Type

Threat Description

The Protected Users group allows minimizing credential exposure for privileged accounts. Accounts that are members of the Protected Users group that authenticate to a domain controller are unable to:
  • Authenticate with NTLM authentication.
  • Use DES or RC4 encryption types in Kerberos pre-authentication.
  • Be delegated with unconstrained or constrained delegation.
  • Renew the Kerberos TGTs beyond the initial four-hour lifetime.
  • Non-configurable settings to the TGTs expiration are established for every account in the Protected Users group. Normally, the domain controller sets the TGTs lifetime and renewal, based on the domain policies, Maximum lifetime for user ticket and Maximum lifetime for user ticket renewal. For the Protected Users group, 600 minutes is set for these domain policies. Using Protected Users for privileged user accounts limits attack surface, eliminating some of the attack paths that can be employed by a threat actor.

    NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.

    According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.

    MITRE ATT&CK: Attack Tactics

    Credential Access

    D3FEND: Defend Tactics

    Application Configuration Hardening

    Remediation

    To add users to Protected users group:

    1. Open Active Directory Users and Computers tool.
    2. Go to Server Manager > Tools > Active Directory Users and Computers.
    3. Under Users, find the Protected Users group.
    4. Double click to open the group properties.
    5. On the members tab, add the users or groups.

    Frequently Asked Questions

    What does Privileged AD user not protected from using unsecure authentication methods mean?

    Privileged Active Directory users are allowed to use insecure authentication protocols, such as NTLM or DES/RC4 encryption types in Kerberos pre-authentication. This allows attackers to exploit these weaknesses and access the users' credentials.

    This vulnerability enables attackers to obtain privileged accounts' credentials, which can be used for lateral movement within the domain. The exposure of these credentials increases the risk of unauthorized access and compromise due to the attacker's ability to bypass authentication mechanisms.

    Attackers can use insecure authentication protocols to obtain privileged accounts' credentials, which can be used for password cracking or other forms of credential access attacks. This allows the attacker to gain elevated privileges and move laterally within the domain by exploiting the exposed credentials.

    Cayosoft Guardian continuously monitors the authentication settings for privileged Active Directory users, detecting when they are allowed to use insecure authentication protocols. When a vulnerable account is found, Guardian flags it as a security issue and provides visibility into the affected accounts.

    Cayosoft Guardian alerts administrators to disable insecure authentication protocols for privileged users, limiting the exposure and making it more difficult for attackers to access privileged accounts' credentials. This reduces the risk of credential access attacks and lateral movement within the domain by supporting investigation and response efforts.

    Stop AD Threats As They Happen

    Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

    Classification
    Systems
    Active Directory
    Themes
    Account protection Privileged Access Management
    Attack Tactics
    Credential Access
    Defend Tactics
    Application Configuration Hardening
    Indicator Types
    IOE
    Related Threats
    CTD-000139
    Kerberos Constrained Delegation: krbtgt Risks
    Critical
    CTD-000122
    Active Directory Schema Update Permission Risks
    Critical