Stop AD Threats As They Happen
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Why organizations replace legacy tools with Cayosoft for stronger security, faster recovery, and unified hybrid identity control.
A user right assignment in Windows controls powerful local privileges such as “Log on as a service”, “Act as part of the operating system”, or “Debug programs”, etc. If these privileges are granted to non-administrative users or groups on domain controllers, a threat actor can use them to escalate privileges, establish persistence, or bypass authentication mechanisms.
Domain controllers should only grant sensitive rights to trusted security principals (typically Administrators, SYSTEM, or domain-specific service accounts). Assigning dangerous rights to non-standard accounts can allow lateral movement, impersonation, or even complete domain compromise.
D3FEND: Defend Tactics
Win + R, type gpmc.msc, and press Enter.| Policy name | Setting |
| ‘Manage auditing and security log’ with Exchange | BUILTINAdministrators, Exchange Servers |
| ‘Manage auditing and security log’ without Exchange | BUILTINAdministrators |
| Access Credential Manager as a trusted caller | |
| Access this computer from the network | BUILTINAdministrators, NT AUTHORITYAuthenticated Users, NT AUTHORITYENTERPRISE DOMAIN CONTROLLERS |
| Act as part of the operating system | |
| Add workstations to domain | BUILTINAdministrators |
| Allow log on locally | BUILTINAdministrators |
| Allow log on through Remote Desktop Services | BUILTINAdministrators |
| Back up files and directories | BUILTINAdministrators |
| Create a pagefile | BUILTINAdministrators |
| Create a token object | |
| Create global objects | BUILTINAdministrators, NT AUTHORITYLOCAL SERVICE, NT AUTHORITYNETWORK SERVICE, NT AUTHORITYSERVICE |
| Create permanent shared objects | |
| Create symbolic links | BUILTINAdministrators |
| Debug programs | BUILTINAdministrators |
| Deny access to this computer from the network | BUILTINGuests |
| Deny log on as a batch job | BUILTINGuests |
| Deny log on as a service | |
| Deny log on locally | BUILTINGuests |
| Deny log on through Remote Desktop Services | BUILTINGuests |
| Enable computer and user accounts to be trusted for delegation | BUILTINAdministrators |
| Force shutdown from a remote system | BUILTINAdministrators |
| Generate security audits | NT AUTHORITYNETWORK SERVICE, NT AUTHORITYLOCAL SERVICE |
| Impersonate a client after authentication | NT AUTHORITYSERVICE, NT AUTHORITYNETWORK SERVICE, NT AUTHORITYLOCAL SERVICE, BUILTINAdministrators |
| Increase scheduling priority | BUILTINAdministrators |
| Load and unload device drivers | BUILTINAdministrators |
| Lock pages in memory | |
| Modify firmware environment values | BUILTINAdministrators |
| Perform volume maintenance tasks | BUILTINAdministrators |
| Profile single process | BUILTINAdministrators |
| Restore files and directories | BUILTINAdministrators |
| Take ownership of files or other objects | BUILTINAdministrators |
Active Directory assigns powerful local privileges such as 'Log on as a service', 'Act as part of the operating system', or 'Debug programs' to non-administrative users or groups on domain controllers. This can allow unauthorized access and privilege escalation.
High-severity ratings are assigned due to the direct enablement of serious compromise and privileged access. Sensitive rights granted to non-standard accounts facilitate lateral movement, impersonation, or complete domain compromise.
Attackers exploit assigned privileges for privilege escalation, persistence, or authentication bypass. This enables lateral movement, impersonation, or even complete domain compromise through unauthorized access and manipulation of sensitive resources.
Cayosoft Guardian continuously monitors the assignment of sensitive privileges to non-admin users or groups across the Active Directory environment. When such an assignment is found, Guardian flags it as a security issue for administrator awareness and action.
Cayosoft Guardian provides visibility into sensitive privilege assignments, enabling administrators to identify and correct issues. This ensures trusted security principals have access to these powerful rights.
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack