From the Field: Over-privileged Service Accounts

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments

๐Ÿ’ฅ ๐Ÿฐ๐Ÿณ.๐Ÿฒ%ย of infrastructures Iโ€™ve assessed ๐—ฑ๐—ผ ๐—ป๐—ผ๐˜ ๐˜‚๐˜€๐—ฒ ๐˜๐—ต๐—ฒ ๐—น๐—ฒ๐—ฎ๐˜€๐˜ ๐—ฝ๐—ฟ๐—ถ๐˜ƒ๐—ถ๐—น๐—ฒ๐—ด๐—ฒ ๐—บ๐—ผ๐—ฑ๐—ฒ๐—น ๐—ณ๐—ผ๐—ฟ ๐˜€๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€

Most environments still rely onย basic domain user accountsย as service accounts โ€” and theyโ€™re usually highly privileged.ย ๐—ง๐—ต๐—ถ๐˜€ ๐—ฐ๐—ฟ๐—ฒ๐—ฎ๐˜๐—ฒ๐˜€ ๐˜€๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐—ฎ๐—น ๐—ฝ๐—ฟ๐—ผ๐—ฏ๐—น๐—ฒ๐—บ๐˜€:

1๏ธโƒฃย ๐—ฃ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ๐˜€ ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—ฏ๐—ฎ๐—ฐ๐—ธ๐—ด๐—ฟ๐—ผ๐˜‚๐—ป๐—ฑย โ€“ These accounts have regular passwords, which are often weak and almost never rotated (without a 3rd-party solution). ๐—œ ๐—ณ๐—ฟ๐—ฒ๐—พ๐˜‚๐—ฒ๐—ป๐˜๐—น๐˜† ๐˜€๐—ฒ๐—ฒ ๐—ฝ๐—ฟ๐—ฒ๐—ต๐—ถ๐˜€๐˜๐—ผ๐—ฟ๐—ถ๐—ฐ ๐˜€๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€ from 2003 that nobody dares to touch โ€” because when disabled, something breaks. Many of them have 5โ€“8 character passwords.

2๏ธโƒฃย ๐—ž๐—ฒ๐—ฟ๐—ฏ๐—ฒ๐—ฟ๐—ผ๐—ฎ๐˜€๐˜๐—ถ๐—ป๐—ด ๐—ฟ๐—ถ๐˜€๐—ธย โ€“ If a Service Principal Name (SPN) is registered, anyone can request a Ticket Granting Service (TGS) ticket. These are ๐—ฒ๐—ป๐—ฐ๐—ฟ๐˜†๐—ฝ๐˜๐—ฒ๐—ฑ ๐˜„๐—ถ๐˜๐—ต ๐—ฎ ๐—ธ๐—ฒ๐˜† ๐—ฑ๐—ฒ๐—ฟ๐—ถ๐˜ƒ๐—ฒ๐—ฑ ๐—ณ๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜โ€™๐˜€ ๐—ฝ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ. If that password is weak, attackers can crack it offline and gain access.

๐—›๐—ผ๐˜„ ๐˜๐—ผ ๐—ต๐—ฎ๐—ป๐—ฑ๐—น๐—ฒ ๐˜€๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€ ๐—ฝ๐—ฟ๐—ผ๐—ฝ๐—ฒ๐—ฟ๐—น๐˜†:

๐Ÿ”น ๐——๐—ผ๐—ปโ€™๐˜ ๐˜‚๐˜€๐—ฒ basic domain user accountsย for services.

๐Ÿ”น If access is needed only to local resources โ†’ useย ๐—ฉ๐—ถ๐—ฟ๐˜๐˜‚๐—ฎ๐—น ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—”๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€ย (VSA).

๐Ÿ”น If access to domain resources is needed โ†’ useย ๐— ๐—ฎ๐—ป๐—ฎ๐—ด๐—ฒ๐—ฑ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—”๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€ (MSA / gMSA / dMSA).

๐Ÿ‘‰ Withย Windows Server 2025, you can more easily replace your service accounts withย dMSAs.

๐—œ๐—ณ ๐˜†๐—ผ๐˜‚ ๐—บ๐˜‚๐˜€๐˜ ๐˜‚๐˜€๐—ฒ ๐—ฏ๐—ฎ๐˜€๐—ถ๐—ฐ ๐˜‚๐˜€๐—ฒ๐—ฟ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€:

๐Ÿ”ธ Use long, random passwords (20+ characters).

๐Ÿ”ธ Restrict Kerberos encryption toย AES only.

โœ… And the main thing, always ๐—ฝ๐—ฟ๐—ผ๐˜ƒ๐—ถ๐—ฑ๐—ฒ ๐—ท๐˜‚๐˜€๐˜ ๐—ฒ๐—ป๐—ผ๐˜‚๐—ด๐—ต ๐—ฝ๐—ฟ๐—ถ๐˜ƒ๐—ถ๐—น๐—ฒ๐—ด๐—ฒ๐˜€ ๐˜๐—ผ ๐—ณ๐—ถ๐—ป๐—ถ๐˜€๐—ต ๐˜๐—ต๐—ฒ ๐˜๐—ฎ๐˜€๐—ธ. Do not use highly privileged groups, just because somebody asks you to, there is usually a better way.