AD AdminSDHolder

๐Ÿ”’Secure Bits๐Ÿ’ก
Do you know ๐˜„๐—ต๐—ฎ๐˜ ๐—”๐—ฑ๐—บ๐—ถ๐—ป๐—ฆ๐——๐—›๐—ผ๐—น๐—ฑ๐—ฒ๐—ฟ ๐—ถ๐˜€ย ?

If you are responsible for Active Directory, you should know this crucial component.

The purpose of this component is to provide a permission template for privileged accounts and groups. As you can also see in the picture, privileged users and groups have the same ACL as AdminSDHolder container.

๐—›๐—ผ๐˜„ ๐—ฑ๐—ผ๐—ฒ๐˜€ ๐—ถ๐˜ ๐˜„๐—ผ๐—ฟ๐—ธ ?

There is a process of AdminSDHolder, that runs every 60 minutes (can be changed) and it compares the permissions on the protected accounts and groups with the container. If they do not match, process resets them.

It is important to monitor AdminSDHolder container, as it can be abused to gain permissions over your privileged accounts and groups, without actually being member of any privileged group. As you can see in the example, Badguy can basically become a highly privileged account at any time.

There are other important things about AdminSDHolder, but I will separate it into more posts. 1/2

๐—™๐—ผ๐—น๐—น๐—ผ๐˜„ ๐˜‚๐˜€ for more insights and free courses.