CTD-000094

AD domain with unsecure configuration of Cloud Kerberos Trust

High
Active Directory Entra ID Hybrid
Credential Access
v24

Signature Identity

CTD-000094
Threat ID
24
Version
IOE
Indicator Type

Threat Description

In a hybrid scenario, identities are synchronized from the on-premises AD to Microsoft Entra ID, with the on-premises AD being the authoritative source. Normally, lateral movement from the compromised on-premises AD to Microsoft Entra ID is more common, as information flows from on-premises to the cloud.

However, the Cloud Kerberos Trust model creates trust from the on-premises AD to Microsoft Entra ID, allowing authentication based on information from Microsoft Entra ID. A threat actor who obtains Global Admin privileges in Microsoft Entra ID can abuse this trust to escalate their privileges to Domain Admin. This means that the attacker, starting with control over Microsoft Entra ID, can gain control over the on-premises AD and potentially compromise the entire environment.

NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.

According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To prevent privileged accounts in Active Directory from using passwordless authentication methods through the Cloud Kerberos Trust:

  1. Identify the highly privileged accounts and groups that you want to prevent from using passwordless authentication methods, such as the MSOL sync account or built-in privileged accounts and groups. These accounts should be able to authenticate using passwords or other methods.
  2. Find the RODC object in Active Directory Users and Computers (ADUC).
  3. Go to Password Replication Policy tab.
  4. Add the privileged accounts and groups that do not require passwordless authentication with Deny setting. This list restricts the accounts from using passwordless authentication methods through the Cloud Kerberos Trust.

Frequently Asked Questions

What does AD domain with unsecure configuration of Cloud Kerberos Trust mean?

An Active Directory (AD) domain with an unsecured Cloud Kerberos Trust configuration is a hybrid environment where the trust model between Microsoft Entra ID and on-premises AD is misconfigured, allowing authentication based on information from Microsoft Entra ID. This creates a risk because an attacker with Global Admin privileges in Microsoft Entra ID can use this trust to access sensitive resources.

This misconfiguration enables unauthorized access to highly privileged accounts and groups, allowing attackers to move laterally within the on-premises AD environment. The attacker can bypass traditional authentication mechanisms, gaining control over sensitive resources.

An attacker who has Global Admin privileges in Microsoft Entra ID can use the misconfigured trust to access highly privileged accounts and groups. This allows them to move laterally within the on-premises AD environment, potentially gaining control over sensitive resources.

Cayosoft Guardian continuously monitors the state of the Cloud Kerberos Trust model across your hybrid Active Directory environment, detecting misconfigured trusts and flagging them as security issues. This ensures administrators are aware of unnecessary risks and can take corrective action.

Cayosoft Guardian helps reduce the risk by providing visibility into misconfigured trusts, allowing administrators to identify and address unnecessary risks. This supports investigation and response efforts, helping teams respond quickly to potential security incidents.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory Entra ID Hybrid
Themes
Domain-wide Tenant-wide
Attack Tactics
Credential Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical