CTD-000194

AD domain with misconfigured LDAP signing policy on the domain controllers

High
Active Directory
Credential Access Defense Evasion Lateral Movement Privilege Escalation
v8

Signature Identity

CTD-000194
Threat ID
8
Version
IOE
Indicator Type

Threat Description

The Lightweight Directory Access Protocol (LDAP) is used by clients and services to query and interact with Active Directory. When LDAP signing is not enforced, authentication traffic between clients and domain controllers is transmitted in clear text and can be intercepted or modified by attackers. This exposes the environment to man-in-the-middle (MitM) and LDAP relay attacks, which can result in credential theft, privilege escalation, or user impersonation.

To mitigate these risks, Microsoft strongly recommends configuring domain controllers to require LDAP signing. Enforcing signed LDAP communication ensures data integrity and authenticity, preventing unauthorized entities on the network from tampering with or relaying LDAP requests.

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion Lateral Movement Privilege Escalation

D3FEND: Defend Tactics

D3-ACH (Application Configuration Hardening)

Remediation

  1. Right-click Start > Run, type mmc.exe, and click OK.
  2. In the Microsoft Management Console (MMC), select File > Add/Remove Snap-in….
  3. Select Group Policy Management Editor, and click Add >.
  4. In the Select Group Policy Object window, click Browse.
  5. In the Browse for a Group Policy Object dialog box, select Default Domain Controllers Policy under All tab, then click OK.
  6. Click Finish, then OK to load the policy.
  7. Double-click Default Domain Controllers Policy.
  8. Navigate to: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > double click Security Options.
  9. In the right pane, locate and right-click Domain controller: LDAP server signing requirements, then select Properties.
  10. In the properties dialog box:
    • Check Define this policy setting.
    • Select Require signing from the list.
    • Click Apply.
    • In the Confirm Setting Change dialog box, click Yes.
    • Click OK.
  11. Update Group Policy on all domain controllers by running: gpupdate /force

Frequently Asked Questions

What does AD domain with misconfigured LDAP signing policy on the domain controllers mean?

The LDAP signing policy is not enabled or is incorrectly configured on the domain controllers. This allows clients to send unencrypted LDAP requests, enabling an attacker to intercept and modify authentication traffic.

The lack of signed LDAP communication enables attackers to exploit man-in-the-middle attacks, which can lead to credential theft or privilege escalation through unauthorized access to sensitive data. Specifically, an attacker can intercept authentication traffic and modify it to gain unauthorized access.

Attackers can exploit the lack of encryption to intercept or modify authentication traffic between clients and domain controllers. This allows them to steal credentials, escalate privileges, or impersonate users, enabling lateral movement within the environment.

Cayosoft Guardian continuously monitors the Active Directory environment for misconfigured LDAP signing policies. When a non-compliant configuration is detected, Guardian flags it as a security issue to alert administrators of the exposure.

Cayosoft Guardian helps mitigate the risk by providing visibility into non-compliant configurations and alerting administrators to enable signed LDAP communication. This ensures data integrity and authenticity, preventing unauthorized entities from tampering with or relaying LDAP requests.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Forest-wide Infrastructure Privileged Access Management
Attack Tactics
Credential Access Defense Evasion Lateral Movement Privilege Escalation
Defend Tactics
D3-ACH (Application Configuration Hardening)
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical