Do you restrict access?

๐——๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ โ†’ ๐—›๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐—ป๐—ฒ๐—ฑ

Real configs. Real fixes. Windows & AD security.

๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐—ฟ๐—ฒ๐˜€๐˜๐—ฟ๐—ถ๐—ฐ๐˜ ๐—ฎ๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€?

Simple test: Try to connect to a user workstation with your Domain Admin account.

โžก๏ธ Did it work?

If yes, you are not properly restricting access within your Active Directory.

โš ๏ธ And it does not end with workstations. With a Domain Admin account, you should ๐—ป๐—ผ๐˜ ๐—ฏ๐—ฒ ๐—ฎ๐—ฏ๐—น๐—ฒ ๐˜๐—ผ ๐—ฐ๐—ผ๐—ป๐—ป๐—ฒ๐—ฐ๐˜ anywhere except Tier 0 systems. This goes hand in hand with the Tiering Model.

And in my opinion, it is one of the ๐—บ๐—ผ๐˜€๐˜ ๐—ถ๐—บ๐—ฝ๐—ผ๐—ฟ๐˜๐—ฎ๐—ป๐˜ security measures you can implement in AD, because it dramatically limits where privileged accounts can be used.

๐—ช๐—ต๐˜†?

1๏ธโƒฃ It makes privileged credential theft harder

โ–ช๏ธ Lower tiers are usually ๐—บ๐—ผ๐—ฟ๐—ฒ ๐—ฒ๐˜…๐—ฝ๐—ผ๐˜€๐—ฒ๐—ฑ. User workstations, jumpy admin habits, support tools, browsers, email, documents, internet access, third-party appsโ€ฆ That is often where compromise starts.

โ–ช๏ธ If higher privileged accounts cannot log on to lower tiers, attackers have fewer places to steal them from.

2๏ธโƒฃ It prevents โ€œconvenientโ€ admin behavior

โ–ช๏ธ I implement this quite often in customer environments. And one thing I repeatedly see is that admins sometimes try to take ๐˜€๐—ต๐—ผ๐—ฟ๐˜๐—ฐ๐˜‚๐˜๐˜€. Not because they want to be insecure. But because it is faster.

โ–ช๏ธ If there is no technical restriction, ๐˜„๐—ต๐—ฎ๐˜ ๐—ฟ๐—ฒ๐—ฎ๐—น๐—น๐˜† ๐˜€๐˜๐—ผ๐—ฝ๐˜€ someone from using a powerful admin account to fix something on a workstation? Access restrictions create a clear boundary. They make the environment tell you:

โ€œ๐˜•๐˜ฐ, ๐˜ต๐˜ฉ๐˜ช๐˜ด ๐˜ข๐˜ค๐˜ค๐˜ฐ๐˜ถ๐˜ฏ๐˜ต ๐˜ด๐˜ฉ๐˜ฐ๐˜ถ๐˜ญ๐˜ฅ ๐˜ฏ๐˜ฐ๐˜ต ๐˜ฃ๐˜ฆ ๐˜ถ๐˜ด๐˜ฆ๐˜ฅ ๐˜ฉ๐˜ฆ๐˜ณ๐˜ฆ.โ€

โœ… And that is exactly what you want.

Access restrictions and Tiering Model are ๐˜๐—ผ๐—ฝ๐—ถ๐—ฐ๐˜€ ๐—œ ๐—ฐ๐—ผ๐˜ƒ๐—ฒ๐—ฟ in my hands-on course Building a Secure Active Directory, including how to build and enforce this properly on your own. There are also ๐—ณ๐—ฟ๐—ฒ๐—ฒ ๐—ฝ๐—ฟ๐—ฒ๐˜ƒ๐—ถ๐—ฒ๐˜„๐˜€ available if you want to check the style first.

๐——๐—ผ ๐˜†๐—ผ๐˜‚ restrict privileged account access in your environment? And what approach do you use?