CTD-000085

Regular AD user with permission to link GPOs

High
Active Directory
Defense Evasion Execution Persistence Privilege Escalation
v24

Signature Identity

CTD-000085
Threat ID
24
Version
IOC-IOE
Indicator Type

Threat Description

A threat actor with permissions to link Group Policy objects at the AD site, Domain controllers OU, or domain can elevate their permissions.

NOTE: Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. Privileged users are defined in Active Directory as users with AdminCount=1. By design, Active Directory uses this attribute to protect members of administrative groups.

According to security best practices, it is not recommended to reuse admin accounts; instead, these accounts must be de-provisioned. If an account has administrative permissions, it may also gain access to other resources using these permissions and retain this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.

MITRE ATT&CK: Attack Tactics

Defense Evasion Execution Persistence Privilege Escalation

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

Review activities of a user utilizing Change History in Cayosoft Guardian.

To disable a suspicious user utilizing Active Directory Users and Computers (ADUC)

  1. Open the Active Directory Users and Computers MMC snap-in.
  2. Right-click the user object and select Properties from the context menu.
  3. Click the Account tab.
  4. To disable the account, check Account is disabled checkbox. 

Frequently Asked Questions

What does Regular AD user with permission to link GPOs mean?

Regular AD user with permission to link GPOs refers to an Active Directory user account granted the ability to link Group Policy objects at the site, Domain controllers OU, or domain level. This privilege allows the user to modify group membership and permissions.

Regular AD user with permission to link GPOs is rated high severity because an attacker can exploit this privilege to elevate their permissions by modifying group membership, even after being removed from administrative groups. This allows them to maintain access and perform actions outside of their intended role.

Attackers can exploit the privilege granted to regular AD users by modifying group membership to elevate their permissions, allowing them to access resources they wouldn't normally have access to. This can be done through various means, including adding themselves to administrative groups or modifying group policy settings.

Cayosoft Guardian detects regular AD users with permission to link GPOs by continuously monitoring Active Directory for changes in group membership and permissions. When a user is found to have this privilege, Guardian flags it as a security issue so administrators can take action.

Cayosoft Guardian helps reduce the risk by alerting administrators to disable or remove users with this privilege, and providing ongoing monitoring to detect any changes in group membership or permissions. This ensures that unnecessary access points are closed and reduces the risk of privilege escalation.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Infrastructure
Attack Tactics
Defense Evasion Execution Persistence Privilege Escalation
Defend Tactics
Domain Account Monitoring
Indicator Types
IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical