CTD-000175

AD Delegated Managed Service Account (dMSA) object takeover by computer object

Critical
Active Directory
Credential Access Defense Evasion Persistence Privilege Escalation
v14

Signature Identity

CTD-000175
Threat ID
14
Version
IOA-IOC
Indicator Type

Threat Description

In Active Directory, computer objects, including Delegated Managed Service Accounts (dMSAs), are securable and governed by Access Control Lists (ACLs). Improper delegation of permissions at the Organizational Unit (OU) level can allow unprivileged users to gain write access to these sensitive objects.

Windows Server 2025 introduces the msDS-DelegatedManagedServiceAccount class, which enables new service account capabilities, including successor inheritance. This functionality, while powerful, can be abused to simulate a migration from a privileged identity, allowing an attacker to craft a dMSA that inherits the access of a privileged account without needing to compromise the original.

Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. If a regular user is granted permissions such as GenericWrite, WriteDacl, or WriteProperty on OUs containing dMSAs, they could exploit this to escalate privileges, evade detection, and maintain long-term persistence.

NOTE: This threat applies only in environments with at least one Windows Server 2025 Domain Controller and the corresponding schema upgrade, which introduces the msDS-DelegatedManagedServiceAccount object class.

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion Persistence Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To change permissions using Active Directory Users and Computers:
  1. Press View > Advanced features.
  2. Locate the object with abusable permissions.
  3. Right-click on it, and select Properties.
  4. Select the Security tab.
  5. Remove unwanted computers or groups from the list.
  6. Click OK to save the permission settings.

Frequently Asked Questions

What does AD Delegated Managed Service Account (dMSA) object takeover by computer object mean?

AD Delegated Managed Service Account (dMSA) object takeover by computer object occurs when an attacker exploits the ability of a computer object to impersonate a dMSA, allowing them to write to sensitive objects and simulate a migration from a privileged identity.

This vulnerability enables attackers to gain write access and escalate privileges, allowing them to modify sensitive objects and maintain persistence in Active Directory. The attacker gains the capability to simulate a migration from a privileged identity, which is a key mechanism for maintaining persistence.

Attackers exploit this vulnerability by using a computer object's impersonation capabilities to write to dMSAs, simulating a migration from a privileged identity and escalating their privileges. This allows them to maintain persistence in Active Directory and modify sensitive objects.

Cayosoft Guardian detects AD Delegated Managed Service Account (dMSA) object takeover by computer object by continuously monitoring the impersonation of dMSAs by computer objects in Active Directory, identifying potential security risks and alerting administrators to provide visibility.

Cayosoft Guardian helps reduce the risk of AD Delegated Managed Service Account (dMSA) object takeover by computer object by alerting administrators to potential impersonation risks and providing remediation guidance, enabling teams to quickly address the issue and prevent attackers from exploiting it. This supports investigation and helps administrators review the security posture.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection Privileged Access Management
Attack Tactics
Credential Access Defense Evasion Persistence Privilege Escalation
Defend Tactics
Application Configuration Hardening
Indicator Types
IOA IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical