CTD-000135

Privileged AD user not protected against delegation

High
Active Directory
Initial Access Privilege Escalation
v9

Signature Identity

CTD-000135
Threat ID
9
Version
IOE
Indicator Type

Threat Description

A threat actor controlling a delegated account can perform actions on other services or systems, potentially escalating their privileges. Privileged accounts, such as those belonging to any of the administrator groups, must not be trusted for delegation. Allowing privileged accounts to be trusted for delegation provides a means for privilege escalation from a compromised system.

MITRE ATT&CK: Attack Tactics

Initial Access Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening Domain Account Monitoring

Remediation

  1. Open Active Directory Users and Computers.
  2. View the properties of each privileged account.
  3. Under the Account tab, locate the Account Options section.
  4. Enable the Account is sensitive and cannot be delegated checkbox.
  5. Click Apply to save the changes.

Frequently Asked Questions

What does Privileged AD user not protected against delegation mean?

Privileged AD user not protected against delegation means that a user with elevated permissions in Active Directory has been configured to allow unconstrained delegation of their Kerberos tickets. This allows an attacker controlling the privileged account to assume the identity of other users or services, potentially escalating their privileges.

This vulnerability enables attackers to exploit the Kerberos protocol and gain elevated permissions, allowing them to perform malicious actions. The risk of privilege escalation through unconstrained delegation justifies a high-severity rating.

When a privileged AD user is not protected against delegation, an attacker controlling the account can use the Kerberos protocol to obtain a ticket-granting ticket (TGT) and assume the identity of other users or services. This allows them to access sensitive resources and perform actions that would otherwise be restricted.

Cayosoft Guardian detects Privileged AD user not protected against delegation by continuously monitoring Active Directory for privileged accounts that have been configured to allow unconstrained delegation. When such a configuration is found, Guardian flags it as a security issue so administrators are aware of the potential risk.

Cayosoft Guardian helps reduce the risk by alerting administrators to disable unconstrained delegation for privileged accounts in Active Directory Users and Computers, preventing attackers from using delegated Kerberos tickets to assume other identities.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Initial Access Privilege Escalation
Defend Tactics
Application Configuration Hardening Domain Account Monitoring
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical