CTD-000140

Constrained authentication delegation to a domain controller service

Critical
Active Directory
Defense Evasion Lateral Movement Privilege Escalation
v13

Signature Identity

CTD-000140
Threat ID
13
Version
IOE
Indicator Type

Threat Description

This indicator looks for principals (computers or users) that have constrained delegation enabled for a service running on a domain controller. If an attacker can create such a delegation, they can authenticate to that service using any user that is not protected against delegation.

A threat actor can gain control over a domain controller service account configured for constrained authentication delegation and exploit this access to escalate privileges within the network. By compromising this service account, which is trusted for constrained authentication delegation, the threat can impersonate users and access sensitive resources as specified by the delegation settings. This level of control can be leveraged to perform lateral movements, escalate privileges, and potentially gain domain administrator rights, thus significantly compromising the security and integrity of the entire network.

MITRE ATT&CK: Attack Tactics

Defense Evasion Lateral Movement Privilege Escalation

D3FEND: Defend Tactics

Credential Hardening Domain Account Monitoring

Remediation

  1. Review objects in findings. This configuration is usually associated with an application.
  2. Determine the application using this configuration and understand the requirements. If there is no need for an application, this could be an artifact from a previous compromise and should be removed immediately. If the application requires this configuration, you must ensure it is properly configured.
  3. Open Active Directory Users and Computers.
  4. Locate the domain controller.
  5. Right-click on the account.
  6. Select Properties.
  7. Navigate to the Delegation tab.
  8. Choose Do not trust this computer for delegation.
  9. Click Apply to save the changes.

Frequently Asked Questions

What does Constrained authentication delegation to a domain controller service mean?

This configuration allows an attacker to exploit the Kerberos protocol's delegation mechanism, enabling them to access sensitive resources as specified by the delegation settings.

It enables attackers to exploit Kerberos protocol vulnerabilities, gain control over a trusted service account, and escalate privileges within the network. This level of access can be leveraged for lateral movements and potentially gaining domain administrator rights.

Attackers can impersonate users and access sensitive resources by exploiting the Kerberos protocol's delegation mechanism, obtaining a ticket-granting ticket (TGT) for a user account, and escalating privileges within the network.

Cayosoft Guardian continuously monitors the configuration of domain controller service accounts for constrained authentication delegation and Kerberos protocol settings. When this configuration is found, Guardian flags it as a security issue so administrators are aware of the potential threat.

Cayosoft Guardian alerts administrators to review and correct the configuration, providing ongoing monitoring to ensure prompt issue resolution. This limits the potential for attackers to exploit this vulnerability.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection Kerberos
Attack Tactics
Defense Evasion Lateral Movement Privilege Escalation
Defend Tactics
Credential Hardening Domain Account Monitoring
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical