๐ Secure Bits ๐ก
๐๐ผ ๐ฌ๐ผ๐ ๐จ๐๐ฒ ๐ฅ๐ฒ๐๐๐ฟ๐ถ๐ฐ๐๐ฒ๐ฑ ๐๐ฑ๐บ๐ถ๐ป ๐ ๐ผ๐ฑ๐ฒ ๐ณ๐ผ๐ฟ ๐ฅ๐๐ฃ?
If not, you shouldโit ๐ฝ๐ฟ๐ฒ๐๐ฒ๐ป๐๐ ๐ฐ๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น ๐ฒ๐ ๐ฝ๐ผ๐๐๐ฟ๐ฒ.
๐ช๐ต๐ ๐๐ ๐๐
๐ถ๐๐๐:
Restricted Admin Mode was designed to let administrators connect to a potentially compromised device without passing their credentials to it.
You must already be an administrator on the target machine, but your credentials never leave the source system, preventing theft and lateral movement attacks.
๐ช๐ต๐ ๐๐ ๐ ๐ฎ๐๐๐ฒ๐ฟ๐:
โ
๐ฆ๐๐ผ๐ฝ๐ ๐๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น ๐ง๐ต๐ฒ๐ณ๐ โ Protects privileged accounts during RDP sessions.
โ
๐๐ฑ๐ฒ๐ฎ๐น ๐ณ๐ผ๐ฟ ๐๐๐บ๐ฝ ๐๐ผ๐๐๐ & ๐ฃ๐๐ช๐ โ Securely connect to your devices without risk.
โ
๐๐ฒ๐ฒ๐น๐ ๐๐ถ๐ธ๐ฒ ๐ฆ๐ฆ๐ข โ No password entry neededโyour local admin credentials are used, but never sent to the target.
๐๐ผ๐ ๐๐ผ ๐๐ป๐ฎ๐ฏ๐น๐ฒ ๐๐:
๐น๐ข๐ป ๐๐ต๐ฒ ๐ง๐ฎ๐ฟ๐ด๐ฒ๐ ๐๐ฒ๐๐ถ๐ฐ๐ฒ:
Add this registry key:
HKLM\SYSTEM\CurrentControlSet\Control\LSA
REG_DWORD – DisableRestrictedAdmin – 0
๐น๐ข๐ป ๐๐ต๐ฒ ๐ฆ๐ผ๐๐ฟ๐ฐ๐ฒ (๐๐๐บ๐ฝ๐๐ผ๐๐/๐ฃ๐๐ช):
Administrative Templates\System\Credentials Delegation\Restrict delegation of credentials to remote servers – Require Restricted Admin
โ ๏ธ ๐๐ถ๐บ๐ถ๐๐ฎ๐๐ถ๐ผ๐ป: Since no credentials are stored on the target, SSO wonโt work from that machine.
I explain more about this feature in my Cybersecurity Courses ๐
https://academy.horizon-secured.com/p/courses
๐ Do you use this feature in your environment?
