Stop AD Threats As They Happen
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
Computers that utilize gMSAs request the current password from Active Directory to initiate services. The gMSAs can be configured to allow computer accounts to access the password. A potential security issue arises when a threat actor takes control of a computer hosting a service that uses a gMSA, or an account with the necessary permissions to request a gMSA password, thereby compromising the gMSA.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.
D3FEND: Defend Tactics
A regular Active Directory (AD) object, such as a user or group, that has been granted permission to retrieve the password of a Group Managed Service Account (gMSA), allowing it to access the gMSA's credentials without needing the actual password.
This scenario is rated high severity because an attacker can use the object's permissions to retrieve and use the gMSA's credentials, granting unauthorized access to domain resources and sensitive data. Specifically, this occurs when a regular AD object has been granted the 'Read' permission on the gMSA's password attribute (msDS-GroupManagedServiceAccountPassword), allowing it to obtain the password without needing the actual credentials.
Attackers exploit this vulnerability by using the object's permissions to obtain and utilize the gMSA's credentials, allowing them to access domain resources without needing the actual password. This can be done through various means, such as using the obtained password to authenticate to domain resources or using it to create new accounts with elevated privileges.
Cayosoft Guardian continuously monitors Active Directory for changes or anomalies indicating unauthorized access to gMSA credentials, flagging such issues as security concerns and alerting administrators. Specifically, it detects when a regular AD object has been granted the 'Read' permission on the gMSA's password attribute (msDS-GroupManagedServiceAccountPassword), which is not intended for standard AD objects.
Cayosoft Guardian provides visibility into these permissions, alerting administrators when they are misconfigured or exploited, enabling teams to quickly identify and address potential security issues before attackers can utilize them. This is achieved through continuous monitoring and anomaly detection, which provide real-time insights into Active Directory configurations and help administrators stay ahead of potential threats.
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack