Map Network Drive Using Different Credentials

๐Ÿ”’ Secure Bits ๐Ÿ’ก
๐—ฆ๐˜๐—ถ๐—น๐—น ๐—ฎ๐—น๐—น๐—ผ๐˜„๐—ถ๐—ป๐—ด ๐—บ๐—ฎ๐—ฝ๐—ฝ๐—ฒ๐—ฑ ๐—ป๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ ๐—ฑ๐—ฟ๐—ถ๐˜ƒ๐—ฒ๐˜€ ๐˜„๐—ถ๐˜๐—ต ๐—ฎ๐—น๐˜๐—ฒ๐—ฟ๐—ป๐—ฎ๐˜๐—ฒ ๐—ฐ๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น๐˜€?
You might be exposing passwords โ€” especially for privileged accounts.

When users map network drives using โ€œ๐—–๐—ผ๐—ป๐—ป๐—ฒ๐—ฐ๐˜ ๐˜‚๐˜€๐—ถ๐—ป๐—ด ๐—ฑ๐—ถ๐—ณ๐—ณ๐—ฒ๐—ฟ๐—ฒ๐—ป๐˜ ๐—ฐ๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น๐˜€โ€, those credentials are cached on the machine โ€” and they end up in LSASS memory.
๐Ÿ”“ If itโ€™s an admin account, thatโ€™s a serious security problem.

This behavior is default and often forgotten โ€” even though it opens the door to credential theft.

๐Ÿ› ย ๐—š๐—ฃ๐—ข ๐—ณ๐—ถ๐˜…:
Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options
๐˜•๐˜ฆ๐˜ต๐˜ธ๐˜ฐ๐˜ณ๐˜ฌ ๐˜ข๐˜ค๐˜ค๐˜ฆ๐˜ด๐˜ด: ๐˜‹๐˜ฐ ๐˜ฏ๐˜ฐ๐˜ต ๐˜ข๐˜ญ๐˜ญ๐˜ฐ๐˜ธ ๐˜ด๐˜ต๐˜ฐ๐˜ณ๐˜ข๐˜จ๐˜ฆ ๐˜ฐ๐˜ง ๐˜ฑ๐˜ข๐˜ด๐˜ด๐˜ธ๐˜ฐ๐˜ณ๐˜ฅ๐˜ด ๐˜ข๐˜ฏ๐˜ฅ ๐˜ค๐˜ณ๐˜ฆ๐˜ฅ๐˜ฆ๐˜ฏ๐˜ต๐˜ช๐˜ข๐˜ญ๐˜ด ๐˜ง๐˜ฐ๐˜ณ ๐˜ฏ๐˜ฆ๐˜ต๐˜ธ๐˜ฐ๐˜ณ๐˜ฌ ๐˜ข๐˜ถ๐˜ต๐˜ฉ๐˜ฆ๐˜ฏ๐˜ต๐˜ช๐˜ค๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ

โš ๏ธ ๐—ก๐—ผ๐˜๐—ฒ:ย This is related to Windows Credential Manager – mapping stops working, task scheduler with credentials, …, so test before deploying widely.

I provide more details about this topic in my ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—œ๐—ป๐—ณ๐—ฟ๐—ฎ๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† course:
โ†’ https://horizon-secured.com/courses/windows-infrastructure-security

When these credentials are cached in LSASS, they ๐˜€๐—ต๐—ผ๐˜‚๐—น๐—ฑ ๐—ฏ๐—ฒ ๐—ฝ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜๐—ฒ๐—ฑ ๐—ฏ๐˜† ๐—–๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—š๐˜‚๐—ฎ๐—ฟ๐—ฑ, but it is always good to have this ๐—บ๐˜‚๐—น๐˜๐—ถ-๐—น๐—ฎ๐˜†๐—ฒ๐—ฟ ๐—ฎ๐—ฝ๐—ฝ๐—ฟ๐—ผ๐—ฎ๐—ฐ๐—ต.

Do you allow mapped drives for admins in your environment?