CTD-000157

AD no fine-grained password policy found or weak settings detected

High
Active Directory
Credential Access Privilege Escalation
v39

Signature Identity

CTD-000157
Threat ID
39
Version
IOE
Indicator Type

Threat Description

The absence of a fine-grained password policy or the misconfiguration of one or more settings has been identified. Establishing fine-grained password policies for all privileged administrative and service accounts within the domain is imperative. These accounts require more stringent password protocols than those applied to standard users due to the elevated risk they pose to the organization if compromised.

MITRE ATT&CK: Attack Tactics

Credential Access Privilege Escalation

D3FEND: Defend Tactics

Strong Password Policy

Remediation

  1. Open the Active Directory Administrative Center (ADAC).
  2. Navigate to the System container and then to the Password Settings Container.
  3. Check if any fine-grained password policies (FGP) are listed. If no FGP policies are found, none exist in the domain.
  4. In ADAC, select a FGP policy to review its settings.
  5. Ensure the following settings are configured correctly:
    1. Enforce Minimum Password Length: Should be set to 24 or more.
    2. Enforce Password History: Should be set to 24 or more.
    3. Password Must Meet Complexity: Should be enabled.
    4. Store Passwords Using Reversible Encryption: Should be disabled.
    5. Enforce Minimum Password Age: Should be set to 1 day or more.
    6. Enforce Maximum Password Age: Should be set to 30 days or less.
    7. Enforce Account Lockout Policy: Should be enabled.
    8. Number of Failed Attempts Allowed: Should be set to 3 or more.
    9. Reset Failed Logon Attempts After: Should be set to 15 minutes or more.
    10. Account Lockout Duration: Should be set to 15 minutes or more.
    11. Protect from Accidental Deletion: Should be enabled.
    12. Check Applies To: Should be set to the Global group type.
  6. If any settings are incorrect or missing, you must update or create new FGP policies.
  7. To create or modify a policy, use the Active Directory Administrative Center or the AD Powershell Module with the appropriate cmdlets.
  8. After updating or creating policies, verify the changes to ensure they are correctly applied.
  9. Test the policies by enforcing password changes and lockout scenarios to confirm the settings are working as expected.

Frequently Asked Questions

What does AD no fine-grained password policy found or weak settings detected mean?

A missing fine-grained password policy in Active Directory means that privileged accounts are not protected by a strict password policy, allowing attackers to use weak passwords to authenticate and potentially gain elevated privileges. This configuration allows an attacker to exploit weak passwords, which can lead to unauthorized access to sensitive data.

This issue is rated high severity because the absence of a fine-grained password policy enables attackers to exploit weak passwords, which can lead to privilege escalation and unauthorized access to sensitive data. The attacker gains the capability to use weak passwords for authentication, allowing them to potentially gain elevated privileges.

Attackers can use weak passwords to authenticate to privileged accounts, then leverage Kerberos ticket elevation or other techniques to escalate privileges and move laterally within the domain. The attacker gains access to sensitive data and capabilities, which matters because it allows them to perform unauthorized actions.

Cayosoft Guardian continuously monitors Active Directory for missing or misconfigured fine-grained password policies, identifying potential security issues and alerting administrators to take corrective action. This provides visibility into the configuration of fine-grained password policies.

Cayosoft Guardian helps mitigate this risk by detecting missing or misconfigured policies, providing guidance on establishing a fine-grained password policy, and ensuring that privileged accounts are protected with strong passwords. This supports investigation and response efforts by providing administrators with the necessary information to address the issue.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection Privileged Access Management
Attack Tactics
Credential Access Privilege Escalation
Defend Tactics
Strong Password Policy
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical