Credentials Delegation – Default Credentials

๐Ÿ”’ Secure Bits ๐Ÿ’ก
๐—ฃ๐—น๐—ฎ๐—ถ๐—ป๐˜๐—ฒ๐˜…๐˜ ๐—ฃ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ๐˜€ ๐—ถ๐—ป ๐—Ÿ๐—ฆ๐—”๐—ฆ๐—ฆ โ€” ๐——๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ ๐—–๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น๐˜€

๐—ช๐—ต๐˜†ย would you enable something like this?
This has been disabled by default for years, yet I still encounter it during assessments.

๐—ช๐—ต๐˜†โ“
Wellโ€ฆ thereโ€™s a reason. (Not a good one, though.)
๐Ÿ‘‰ IT admins often want ๐—ฐ๐—ผ๐—ป๐˜ƒ๐—ฒ๐—ป๐—ถ๐—ฒ๐—ป๐—ฐ๐—ฒย โ€” making it easy for users to log into ๐˜๐—ฒ๐—ฟ๐—บ๐—ถ๐—ป๐—ฎ๐—น ๐˜€๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ๐˜€ or launch RemoteApps without entering passwords again.

๐Ÿ› ย ๐—ฆ๐—ผ ๐˜๐—ต๐—ฒ๐˜† ๐—ฒ๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ:
Computer Configuration\Administrative Templates\System\Credentials Delegation\Allow delegating default credentials

And sure, it works. You get SSO for RDP.

๐—•๐˜‚๐˜ ๐—ถ๐˜ ๐—ฐ๐—ผ๐—บ๐—ฒ๐˜€ ๐˜„๐—ถ๐˜๐—ต ๐—ฎ ๐—ฐ๐—ผ๐˜€๐˜:
๐Ÿ’ฅ The password gets cached during login โ€” and it can be extracted from LSASS in plaintext.

You might think: โ€œBut I have Credential Guard, right?โ€
Well… not always. ๐—–๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—š๐˜‚๐—ฎ๐—ฟ๐—ฑ ๐—ฐ๐—ฎ๐—ป ๐—ต๐—ฒ๐—น๐—ฝ โ€” but itโ€™s not guaranteed to be active across your environment.

๐—ช๐—ต๐˜† ๐—ป๐—ผ๐˜?
โ˜ ๏ธ Older operating systems
โ˜ ๏ธ Virtual machines without Secure Boot
โ˜ ๏ธ And the big trap I see far too often: Windows Professional edition

Did you knowย ๐—–๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—š๐˜‚๐—ฎ๐—ฟ๐—ฑ ๐—ถ๐˜€๐—ปโ€™๐˜ ๐—ฎ๐˜ƒ๐—ฎ๐—ถ๐—น๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ผ๐—ป ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฃ๐—ฟ๐—ผ?
So even if you think youโ€™re covered, you might not be.

๐Ÿ”ย ๐—ง๐—ต๐—ฒ ๐—•๐—ฒ๐˜๐˜๐—ฒ๐—ฟ ๐—ข๐—ฝ๐˜๐—ถ๐—ผ๐—ป?
If your goal is secure SSO for RDP โ€” this isnโ€™t it. Use ๐—ฅ๐—ฒ๐—บ๐—ผ๐˜๐—ฒ ๐—–๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—š๐˜‚๐—ฎ๐—ฟ๐—ฑ ๐—ถ๐—ป๐˜€๐˜๐—ฒ๐—ฎ๐—ฑ. It gives you the same SSO experience โ€” but without caching the password in memory.

๐Ÿ›  ๐—˜๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ ๐˜๐—ต๐—ฒ๐˜€๐—ฒ ๐—ฝ๐—ผ๐—น๐—ถ๐—ฐ๐—ถ๐—ฒ๐˜€:
1๏ธโƒฃ Computer Configuration\Administrative Templates\System\Credentials Delegation\Remote host allows delegation of nonexportable credentials
2๏ธโƒฃ Computer Configuration\Administrative Templates\System\Credentials Delegation\Restrict delegation of credentials to remote servers

๐Ÿ’ฌ Still using Default Credential Delegation?