Stop AD Threats As They Happen
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
In a hybrid scenario, identities are synchronized from the on-premises AD to Microsoft Entra ID, with the on-premises AD being the authoritative source. Normally, lateral movement from the compromised on-premises AD to Microsoft Entra ID is more common, as information flows from on-premises to the cloud.
However, the Cloud Kerberos Trust model creates trust from the on-premises AD to Microsoft Entra ID, allowing authentication based on information from Microsoft Entra ID. A threat actor who obtains Global Admin privileges in Microsoft Entra ID can abuse this trust to escalate their privileges to Domain Admin. This means that the attacker, starting with control over Microsoft Entra ID, can gain control over the on-premises AD and potentially compromise the entire environment.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.
D3FEND: Defend Tactics
To prevent privileged accounts in Active Directory from using passwordless authentication methods through the Cloud Kerberos Trust:
An Active Directory (AD) domain with an unsecured Cloud Kerberos Trust configuration is a hybrid environment where the trust model between Microsoft Entra ID and on-premises AD is misconfigured, allowing authentication based on information from Microsoft Entra ID. This creates a risk because an attacker with Global Admin privileges in Microsoft Entra ID can use this trust to access sensitive resources.
This misconfiguration enables unauthorized access to highly privileged accounts and groups, allowing attackers to move laterally within the on-premises AD environment. The attacker can bypass traditional authentication mechanisms, gaining control over sensitive resources.
An attacker who has Global Admin privileges in Microsoft Entra ID can use the misconfigured trust to access highly privileged accounts and groups. This allows them to move laterally within the on-premises AD environment, potentially gaining control over sensitive resources.
Cayosoft Guardian continuously monitors the state of the Cloud Kerberos Trust model across your hybrid Active Directory environment, detecting misconfigured trusts and flagging them as security issues. This ensures administrators are aware of unnecessary risks and can take corrective action.
Cayosoft Guardian helps reduce the risk by providing visibility into misconfigured trusts, allowing administrators to identify and address unnecessary risks. This supports investigation and response efforts, helping teams respond quickly to potential security incidents.
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack