CTD-000150

Dangerous enrollment permission on authentication certificate templates

Critical
Active Directory Certificate Services (ADCS)
Credential Access Privilege Escalation
v11

Signature Identity

CTD-000150
Threat ID
11
Version
IOE
Indicator Type

Threat Description

Misconfigured permissions on certificate templates for Windows authentication can pose significant security risks. If unprivileged users are granted permission to request certificates where they can supply arbitrary subject information, they could potentially obtain certificates for any user, including high-privilege accounts like domain admins.

To mitigate this risk, reviewing and adjusting the delegations on these certificate templates is crucial. Specifically, ensure that permissions are not granted to broad groups such as Authenticated Users, Domain Users, or Domain Computers. Instead, permissions should be limited to specific, trusted accounts, and additional security measures should be implemented, such as manager approval or required authorized signatures.

MITRE ATT&CK: Attack Tactics

Credential Access Privilege Escalation

D3FEND: Defend Tactics

Network Traffic Analysis

Remediation

  1. Open the Certificate Templates console (certtmpl.msc).
  2. For each template right-click to select Properties.
  3. Select Security tab.
  4. Remove unexpected permissions.

Frequently Asked Questions

What does Dangerous enrollment permission on authentication certificate templates mean?

Dangerous enrollment permission on authentication certificate templates allows unprivileged users to request certificates with arbitrary subject information, potentially obtaining high-privilege certificates like those for domain admins.

This misconfiguration enables attackers to obtain high-privilege certificates, leading to unauthorized access and potential compromise of identity infrastructure through identity impersonation. The mechanism behind this risk is the excessive delegation of enrollment privileges to untrusted accounts.

Attackers exploit misconfigured certificate templates by requesting certificates with arbitrary subject information, potentially obtaining high-privilege certificates like those for domain admins. This allows them to escalate privileges and gain unauthorized access to sensitive resources through identity impersonation.

Cayosoft Guardian detects misconfigured certificate templates by continuously monitoring the permissions on these templates across Active Directory Certificate Services. When unexpected permissions are found, Guardian flags it as a security issue so administrators can review and adjust delegations to restrict excessive enrollment privileges.

Cayosoft Guardian helps reduce the risk by alerting administrators to misconfigured permissions, allowing them to review and adjust delegations in the Certificate Templates console. This ensures that permissions are limited to specific, trusted accounts and additional security measures are implemented to prevent unauthorized access.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory Certificate Services (ADCS)
Themes
Privileged Access Management
Attack Tactics
Credential Access Privilege Escalation
Defend Tactics
Network Traffic Analysis
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical