CTD-000159

Insufficient forest and domain functional levels

High
Active Directory
Defense Evasion Persistence Privilege Escalation
v9

Signature Identity

CTD-000159
Threat ID
9
Version
IOE
Indicator Type

Threat Description

Active Directory environments operating at Windows Server 2012 R2 or lower functional levels lack foundational security features, such as robust encryption, advanced authentication methods, and recovery mechanisms. These limitations expose the environment to critical vulnerabilities, including outdated cryptographic standards, unprotected credentials, and the difficulty to recover from accidental deletions. Forests and domains at these levels are highly susceptible to exploitation by attackers leveraging deprecated protocols and privilege escalation techniques.

MITRE ATT&CK: Attack Tactics

Defense Evasion Persistence Privilege Escalation

D3FEND: Defend Tactics

D3-OSM (Operating System Monitoring)

Remediation

Raise the Active Directory domain and forest functional levels to 2016 by following the steps outlined in Raise Active Directory Domain and Forest Functional Levels.

Frequently Asked Questions

What does Insufficient forest and domain functional levels mean?

Insufficient forest and domain functional levels means that the Active Directory environment is operating at a level lower than Windows Server 2016, which lacks support for modern security protocols such as Kerberos authentication and AES encryption.

Environments operating at lower functional levels are vulnerable to exploitation by attackers using techniques such as NTLM relay attacks and privilege escalation through Group Policy Object (GPO) manipulation, which can lead to unauthorized access and data breaches.

Attackers can exploit deprecated protocols, such as NTLM, to gain access to sensitive areas of the Active Directory environment. They may also use privilege escalation techniques, like GPO manipulation, to elevate their privileges and move laterally within the network.

Cayosoft Guardian continuously monitors the Active Directory environment for low functional levels, checking for compliance with Windows Server 2016 or higher. When a non-compliant level is detected, Guardian flags it as a security issue so administrators can take corrective action.

Cayosoft Guardian helps reduce the risk by alerting administrators to raise the Active Directory domain and forest functional levels to 2016 or higher, ensuring that modern security protocols are enabled and secure password policies can be enforced.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Forest-wide Infrastructure
Attack Tactics
Defense Evasion Persistence Privilege Escalation
Defend Tactics
D3-OSM (Operating System Monitoring)
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical