CTD-000172

Active directory dangerous user rights assignments on domain controllers

High
Active Directory
Defense Evasion Persistence Privilege Escalation
v14

Signature Identity

CTD-000172
Threat ID
14
Version
IOC-IOE
Indicator Type

Threat Description

A user right assignment in Windows controls powerful local privileges such as “Log on as a service”, “Act as part of the operating system”, or “Debug programs”, etc. If these privileges are granted to non-administrative users or groups on domain controllers, a threat actor can use them to escalate privileges, establish persistence, or bypass authentication mechanisms.

Domain controllers should only grant sensitive rights to trusted security principals (typically Administrators, SYSTEM, or domain-specific service accounts). Assigning dangerous rights to non-standard accounts can allow lateral movement, impersonation, or even complete domain compromise.

MITRE ATT&CK: Attack Tactics

Defense Evasion Persistence Privilege Escalation

D3FEND: Defend Tactics

D3-APA (Access Policy Administration)

Remediation

  1. Open Server Manager > Tools > Group Policy Management.
  2. Press Win + R, type gpmc.msc, and press Enter.
  3. Navigate to the desired OU (Organizational Unit) or domain.
  4. Right-click and choose:
    1. Create a GPO in this domain, and Link it here to create a new one, or Edit to edit an existing GPO.
  5. In the GPO Editor, go to Computer Configuration > Policies Windows Settings > Security Settings > Local Policies > User Rights Assignment.
    GPO configuration examples
    Policy nameSetting
    ‘Manage auditing and security log’ with ExchangeBUILTINAdministrators, Exchange Servers
    ‘Manage auditing and security log’ without ExchangeBUILTINAdministrators
    Access Credential Manager as a trusted caller
    Access this computer from the networkBUILTINAdministrators, NT AUTHORITYAuthenticated Users, NT AUTHORITYENTERPRISE DOMAIN CONTROLLERS
    Act as part of the operating system
    Add workstations to domainBUILTINAdministrators
    Allow log on locallyBUILTINAdministrators
    Allow log on through Remote Desktop ServicesBUILTINAdministrators
    Back up files and directoriesBUILTINAdministrators
    Create a pagefileBUILTINAdministrators
    Create a token object 
    Create global objects BUILTINAdministrators, NT AUTHORITYLOCAL SERVICE, NT AUTHORITYNETWORK SERVICE, NT AUTHORITYSERVICE
    Create permanent shared objects 
    Create symbolic linksBUILTINAdministrators
    Debug programsBUILTINAdministrators
    Deny access to this computer from the networkBUILTINGuests
    Deny log on as a batch jobBUILTINGuests
    Deny log on as a service
    Deny log on locallyBUILTINGuests
    Deny log on through Remote Desktop ServicesBUILTINGuests
    Enable computer and user accounts to be trusted for delegationBUILTINAdministrators
    Force shutdown from a remote systemBUILTINAdministrators
    Generate security auditsNT AUTHORITYNETWORK SERVICE, NT AUTHORITYLOCAL SERVICE
    Impersonate a client after authenticationNT AUTHORITYSERVICE, NT AUTHORITYNETWORK SERVICE, NT AUTHORITYLOCAL SERVICE, BUILTINAdministrators
    Increase scheduling priorityBUILTINAdministrators
    Load and unload device driversBUILTINAdministrators
    Lock pages in memory
    Modify firmware environment valuesBUILTINAdministrators
    Perform volume maintenance tasksBUILTINAdministrators
    Profile single processBUILTINAdministrators
    Restore files and directoriesBUILTINAdministrators
    Take ownership of files or other objectsBUILTINAdministrators

Frequently Asked Questions

What does Active directory dangerous user rights assignments on domain controllers mean?

Active Directory assigns powerful local privileges such as 'Log on as a service', 'Act as part of the operating system', or 'Debug programs' to non-administrative users or groups on domain controllers. This can allow unauthorized access and privilege escalation.

High-severity ratings are assigned due to the direct enablement of serious compromise and privileged access. Sensitive rights granted to non-standard accounts facilitate lateral movement, impersonation, or complete domain compromise.

Attackers exploit assigned privileges for privilege escalation, persistence, or authentication bypass. This enables lateral movement, impersonation, or even complete domain compromise through unauthorized access and manipulation of sensitive resources.

Cayosoft Guardian continuously monitors the assignment of sensitive privileges to non-admin users or groups across the Active Directory environment. When such an assignment is found, Guardian flags it as a security issue for administrator awareness and action.

Cayosoft Guardian provides visibility into sensitive privilege assignments, enabling administrators to identify and correct issues. This ensures trusted security principals have access to these powerful rights.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Infrastructure Privileged Access Management
Attack Tactics
Defense Evasion Persistence Privilege Escalation
Defend Tactics
D3-APA (Access Policy Administration)
Indicator Types
IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical