CTD-000070

Privileged group members with weak password policy

Critical
Active Directory
Credential Access Privilege Escalation
v27

Signature Identity

CTD-000070
Threat ID
27
Version
IOE
Indicator Type

Threat Description

A threat actor might use various techniques to obtain a password of a privileged account. To reduce risks of compromising a password, a policy to rotate and to set lengthier passwords must be implemented. The password should consist of a minimum of 12 characters, though a length of 14 characters or more is even more preferable. Periodic password expiration is a defense against the probability that a password will be compromised during its validity interval and will be used by a threat actor.

NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.

According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp – Microsoft Community Hub.

MITRE ATT&CK: Attack Tactics

Credential Access Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

To configure the AD account password policy, open the Group Policy Management console:

  1. Expand your domain.
  2. Find the GPO named Default Domain Policy.
  3. Right-click it.
  4. Select Edit.
  5. Go to Computer configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy.
  6. Double-click a policy setting to edit it.
  7. Enable a specific policy setting:
    1. Check the Define this policy settings.
    2. Specify the necessary value.
  8. Save the changes.
The new password policy settings will be applied to all domain computers in the background in some time.

Frequently Asked Questions

What does Privileged group members with weak password policy mean?

A privileged group member has a password that doesn't meet the recommended length or rotation requirements, making it vulnerable to brute-force attacks. An attacker can use this weakness to obtain the password and gain unauthorized access to sensitive resources.

This vulnerability allows attackers to bypass authentication mechanisms and gain administrative control, which can lead to serious compromise of identity infrastructure or business-critical systems. An attacker can use the weak password to authenticate as a privileged user and access sensitive resources.

Attackers can exploit this vulnerability by attempting to guess or crack the weak password of a privileged account. Once obtained, the password can be used for authentication bypass and unauthorized access to sensitive resources.

Cayosoft Guardian continuously monitors the password policies of privileged groups across Active Directory and detects any weak passwords as security issues. This allows administrators to take prompt action to resolve the issue.

Cayosoft Guardian helps reduce this risk by alerting administrators to disable or change weak passwords and providing ongoing monitoring to ensure that the issue is resolved. This limits the exposure of privileged accounts to authentication bypass and unauthorized access.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access Privilege Escalation
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical