CTD-000033

Privileged AD account password set to never expire

High
Active Directory
Credential Access
v5

Signature Identity

CTD-000033
Threat ID
5
Version
IOE
Indicator Type

Threat Description

The privileged user account whose password never expires poses a threat to your environment. A password obtained by a malicious actor will be valid until the password is changed. In the meantime, the malicious actor will be able to log in to Active Directory, access resources, and inflict damage. Regular password rotation reduces the risk and effectiveness of password-based attacks and exploits by shortening the timeframe during which a compromised password may be valid.

NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.

According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.

MITRE ATT&CK: Attack Tactics

Credential Access

D3FEND: Defend Tactics

Credential Rotation

Remediation

  1. Set the password to expire and force the user to change their password on the next login:
    1. Click Start.
    2. Open Windows Administrative Tools.
    3. Click Active Directory Users and Computers.
    4. Find the user account.
    5. Open it.
    6. On the Account tab uncheck Password never expires.
    7. Enable User must change password at next logon.
    8. Press OK.
  2. Implement regular password rotation for all users.

Frequently Asked Questions

What does Privileged AD account password set to never expire mean?

Privileged AD account password set to never expire means that an administrative user's password in the Active Directory environment domain will not expire, allowing an attacker to maintain access until it is changed.

This setting allows attackers to authenticate to Active Directory without needing to re-obtain credentials, enabling persistent unauthorized access and increasing the risk of operational impact.

An attacker who obtains a privileged user's non-expiring password can use it indefinitely to authenticate to Active Directory and access resources, causing persistent operational impact until the password is changed. This allows attackers to maintain a foothold in the environment, enabling further lateral movement and potential data exfiltration.

Cayosoft Guardian continuously monitors the password expiration settings of administrative users in the Active Directory environment domain, flagging any accounts with non-expiring passwords as a security issue.

Cayosoft Guardian alerts administrators when it detects non-expiring passwords for administrative users, enabling them to change the password expiration settings and regularly rotate passwords, reducing the effectiveness of password-based attacks and providing visibility into potential security issues.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access
Defend Tactics
Credential Rotation
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical