CTD-000176

Exchange-related AD group with excessive permissions

Critical
Active Directory Exchange
Credential Access Defense Evasion Initial Access Persistence Privilege Escalation
v12

Signature Identity

CTD-000176
Threat ID
12
Version
IOA-IOC
Indicator Type

Threat Description

Cayosoft Guardian detects a threat when the Exchange Windows Permissions and Exchange Trusted Subsystem Exchange-related security groups in Active Directory have any of the following excessive permissions assigned on critical AD objects (such as the domain root):
  • FullControl
  • WriteDACL
  • ForceChangePassword
  • AddMember
These permissions, when inherited via ACLs, grant broad and dangerous control over user and group objects.

If an Exchange server or administrative account is compromised, a threat actor can exploit these permissions to:

  • Reset passwords of privileged accounts (e.g., MSOL_*)
  • Add accounts to sensitive groups, including those with elevated privileges
  • Modify ACLs to gain full domain control
While AdminSDHolder protects some Tier 0 accounts, many others – including Microsoft Entra Connect service accounts – are unprotected. This allows for privilege escalation paths such as:
  • DCSync attacks
  • ESC9 / ESC10 (Exchange permission abuse)
  • ESC14 (X.509 certificate mapping abuse)

MITRE ATT&CK: Attack Tactics

Credential Access Defense Evasion Initial Access Persistence Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

Review and remove excessive permissions from the Exchange Windows Permissions and Exchange Trusted Subsystem groups. Follow Microsoft’s guidance on split permissions to isolate Exchange and AD privilege boundaries.

Frequently Asked Questions

What does Exchange-related AD group with excessive permissions mean?

Exchange-related AD group with excessive permissions refers to the assignment of broad and dangerous control over user and group objects in Active Directory, including FullControl, WriteDACL, ForceChangePassword, or AddMember permissions on critical AD objects. This enables an attacker to exploit these permissions for privilege escalation.

This configuration grants broad and dangerous control over user and group objects, allowing an attacker to reset passwords of privileged accounts or modify ACLs for domain control. This can lead to immediate compromise of identity infrastructure.

An attacker exploiting the excessive permissions in the Exchange Windows Permissions and Exchange Trusted Subsystem groups can reset passwords of privileged accounts, add accounts to sensitive groups, or modify ACLs for domain control. This allows them to gain full domain control.

Cayosoft Guardian continuously monitors the permissions assigned to the Exchange Windows Permissions and Exchange Trusted Subsystem groups in Active Directory, flagging any excessive permissions, such as FullControl or WriteDACL, on critical AD objects.

Cayosoft Guardian alerts administrators to review and remove the excessive permissions from the Exchange Windows Permissions and Exchange Trusted Subsystem groups, limiting an attacker's ability to exploit these permissions for privilege escalation.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory Exchange
Themes
Infrastructure Privileged Access Management
Attack Tactics
Credential Access Defense Evasion Initial Access Persistence Privilege Escalation
Defend Tactics
Application Configuration Hardening
Indicator Types
IOA IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical