CTD-000082

AD forest with high numbers of privileged group accounts

Critical
Active Directory
Privilege Escalation
v36

Signature Identity

CTD-000082
Threat ID
36
Version
IOE
Indicator Type

Threat Description

A large number of accounts in privileged groups makes it difficult to keep track of them, which can lead to poor accountability among privileged users. An environment with an excessive number of privileged users presents a bigger attack surface.

NOTE: Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. Privileged users are defined in Active Directory as users with AdminCount=1. By design, Active Directory uses this attribute to protect members of administrative groups.

According to the security best practices, it is not recommended to reuse admin accounts; instead, these accounts must be de-provisioned. If an account has administrative permissions, it may also gain access to other resources using these permissions and retain this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.

MITRE ATT&CK: Attack Tactics

Privilege Escalation

D3FEND: Defend Tactics

Domain Account Monitoring

Remediation

Review membership of the privileged groups, delete unnecessary accounts with administrative privileges.

Frequently Asked Questions

What does AD forest with high numbers of privileged group accounts mean?

An AD forest with a large number of user accounts in groups that have administrative permissions makes it challenging to maintain accountability and track access. This excessive number of privileged users increases the attack surface for potential threats.

The large number of privileged users in an AD forest makes it difficult to track access, increasing the risk of privilege escalation. This can lead to a significant attack surface, making it easier for attackers to gain unauthorized access or escalate privileges.

Attackers can exploit an environment with many privileged users by gaining access to one account and using its permissions to move laterally within the domain. This allows them to leverage the existing permissions to escalate privileges, potentially gaining control over critical systems or data.

Cayosoft Guardian continuously monitors the membership and permissions of groups across the Active Directory environment domain. When it identifies a large number of privileged users, Guardian flags this as a security issue to alert administrators.

Cayosoft Guardian provides visibility into the number of privileged users and their permissions. This allows administrators to review membership, delete unnecessary accounts with administrative privileges, and implement better Privileged Access Management (PAM) practices to limit the attack surface.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Forest-wide Privileged Access Management
Attack Tactics
Privilege Escalation
Defend Tactics
Domain Account Monitoring
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical