Smart Cards in Active Directory

๐Ÿ”’Secure Bits๐Ÿ’ก
Do you use ๐—ฆ๐—บ๐—ฎ๐—ฟ๐˜ ๐—–๐—ฎ๐—ฟ๐—ฑ๐˜€ ๐—ถ๐—ป ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ?

Greatโ€”but did you know NT Hashes are still cached by default? Thatโ€™s all an attacker needs. Without proper configuration, an NT Hash can remain unchanged indefinitely!

โœ… 1. Smart Card Authentication (Image 1) โ€“ Replaces the userโ€™s password with a random NT hash, but this hash remains static unless rotated.

โœ… 2. NT Hash Rotation (Image 2) โ€“ Enables automatic NT hash changes based on password policy, preventing long-term hash reuse.

โœ… 3. Protected Users Group (Image 3) โ€“ Prevents NT hash caching in memory (LSASS) and forces Kerberos-only authentication (and much more).

๐Ÿ’ก Are you using Smart Cards? Have you secured NT Hash caching properly?