CTD-000136

AD domain controller not changing its password

Critical
Active Directory
Credential Access
v8

Signature Identity

CTD-000136
Threat ID
8
Version
IOE
Indicator Type

Threat Description

Some domain controllers have not updated their passwords in over 45 days, suggesting that their security credentials may be outdated. Domain controllers are typically configured to change their passwords automatically every 30 days. Therefore, it is crucial to ensure that domain controller passwords are updated regularly to maintain security. Investigating why the automatic password change is not occurring is important, as it could indicate a potential security issue. Regular password updates help protect against breaches and ensure the ongoing security of your network.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Reissue Credential

Remediation

To reset the computer account password of the domain controller:

  1. At a command prompt, type the netdom help resetpwd command, and then press Enter.
  2. After you press Enter, you will be prompted to enter the password associated with the domain user. Even though you may not see any typed characters, you need to type the password and press Enter.
  3. Use the syntax that this command provides for using the Netdom command-line tool to reset the computer account password, for example: netdom resetpwd /server:<domain controller name> /userD:administrator /passwordd:*, where the domain controller name is the local DC that you're recovering.
    Note: You should run this command twice.

Frequently Asked Questions

What does AD domain controller not changing its password mean?

AD domain controller not changing its password indicates that one or more domain controllers have failed to update their Kerberos ticket-granting ticket (TGT) passwords in over 45 days, which is a critical security configuration issue.

AD domain controller not changing its password is rated critical because outdated Kerberos TGT passwords can be exploited by attackers using PtT or PtH attacks, enabling unauthorized access to sensitive information and system settings. This allows attackers to bypass traditional authentication mechanisms and gain access to resources without needing the original password.

Attackers can use PtT or PtH attacks to obtain a valid Kerberos ticket without needing the original password, allowing them to access sensitive resources and data on the network. This can lead to unauthorized access, credential theft, and other malicious activities.

Cayosoft Guardian continuously monitors the Kerberos TGT password update status of domain controllers across the Active Directory environment. When a domain controller is found to have an outdated password, Guardian flags it as a security issue so administrators can investigate and take corrective action.

Cayosoft Guardian helps reduce the risk by alerting administrators to reset the computer account password of affected domain controllers, ensuring that Kerberos TGT passwords are updated regularly and reducing exposure to unauthorized access and potential breaches.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Infrastructure
Attack Tactics
Credential Access
Defend Tactics
Reissue Credential
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical