CTD-000122

AD object with schema update permissions

Critical
Active Directory
Impact Persistence
v13

Signature Identity

CTD-000122
Threat ID
13
Version
IOC
Indicator Type

Threat Description

In Active Directory, a schema is a blueprint that defines the rules for the type of objects that can be stored in the Active Directory database and the attributes related to these objects. The schema contains formal definitions of every object class that can be created in an Active Directory forest, as well as every attribute that can exist in an Active Directory object. The schema is managed as an object itself, so it can be administered and manipulated.
A threat actor with permissions to modify schema might compromise your Active Directory forest or make it inoperable.

MITRE ATT&CK: Attack Tactics

Impact Persistence

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To review permissions on the schema object in Active Directory using ADSI Edit:

  1. Press Win + R to open the Run dialog.
  2. Type adsiedit.msc and press Enter.
  3. Right-click on ADSI Edit and select Connect to.
  4. Choose Select or type a domain or server.
  5. Enter the server/domain name where the schema is located.
  6. Select Select a well-known Naming Context and choose Schema.
  7. Click OK.
  8. Expand the Schema node.
  9. Find and click on CN=Schema,CN=Configuration.
  10. Right-click on CN=Schema,CN=Configuration and select Properties.
  11. Go to the Security tab to view permissions.
  12. Click the Advanced button to access advanced security settings.
  13. Click Edit to make changes.
  14. Add, remove, or adjust permissions for users/groups.
  15. Ensure changes align with your organization’s policies.
  16. Verify modifications before applying them.
  17. Click OK or Apply to save changes.
  18. Close ADSI Edit to complete the process.

Frequently Asked Questions

What does AD object with schema update permissions mean?

AD object with schema update permissions means a user or group has been granted the ability to modify the schema definition in the Active Directory environment database. The schema is a blueprint that defines the rules for the type of objects that can be stored and their attributes, making it a critical component of forest integrity.

Modifying the schema definition can compromise the Active Directory environment forest's integrity. A threat actor with these permissions could create malicious objects, attributes, or relationships that violate security policies, leading to data corruption, unauthorized access, or even domain takeover.

An attacker can modify the schema definition to create unauthorized attributes, objects, or relationships. This could lead to data corruption, unauthorized access, or even domain takeover due to the creation of malicious entities that bypass security controls.

Cayosoft Guardian detects AD object with schema update permissions by continuously monitoring Active Directory for changes to the schema definition and permissions. When an unauthorized modification is detected, Guardian flags it as a security issue so administrators can review and correct the configuration.

Cayosoft Guardian helps reduce the risk of AD object with schema update permissions by alerting administrators to review and adjust permissions on the schema object. This ensures that only authorized users have access to modify the schema definition, reducing the likelihood of unauthorized changes.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Forest-wide
Attack Tactics
Impact Persistence
Defend Tactics
Application Configuration Hardening
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical