CTD-000055

AD domain account with password stored using reversible encryption

Medium
Active Directory
Credential Access
v21

Signature Identity

CTD-000055
Threat ID
21
Version
IOE
Indicator Type

Threat Description

Storing encrypted passwords in a way that is reversible means that the encrypted passwords can be decrypted. A threat actor who is able to break this encryption can then sign in to network resources by using the compromised account. For this reason, never enable Store password using reversible encryption for users in the domain unless application requirements outweigh the need to protect password information

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

To disable reversible encryption for a password of a user account:

  1. Click Start.
  2. Point to Control Panel.
  3. Point to Administrative Tools.
  4. Click Active Directory Users and Computers.
  5. Find a user account. 
  6. On the Account tab, uncheck Store password using reversible encryption in the Account options.

Frequently Asked Questions

What does AD domain account with password stored using reversible encryption mean?

When a user's password is stored using reversible encryption, it means the password is encrypted with a key that allows it to be decrypted. This makes it possible for an attacker who gains access to the encrypted password to use it to sign in to network resources without knowing the valid username and password.

The risk of credential exposure and subsequent unauthorized access is meaningful due to the potential for attackers to decrypt passwords and gain anonymous access. This vulnerability can be exploited through administrative scope, allowing attackers to bypass traditional security controls.

An attacker who gains access to an encrypted password can use it to sign in to network resources without valid credentials, allowing for anonymous access. The attacker must still have the necessary permissions or credentials to decrypt the password.

Cayosoft Guardian continuously monitors Active Directory settings and detects when a user's password is stored using reversible encryption. When this setting is found, Guardian flags it as a security issue, providing administrators with clear visibility into potential credential exposure.

Cayosoft Guardian alerts administrators to disable reversible encryption for user passwords in Active Directory Users and Computers, limiting the exposure of encrypted passwords and reducing the potential for attackers to access network resources anonymously. This helps provide visibility into potential security issues and supports investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access
Defend Tactics
Domain Account Monitoring
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical