๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ
Real configs. Real fixes. Windows & AD security.
๐๐ผ ๐๐ผ๐ ๐ฟ๐ฒ๐๐๐ฟ๐ถ๐ฐ๐ ๐ฎ๐ฐ๐ฐ๐ฒ๐๐?
Simple test: Try to connect to a user workstation with your Domain Admin account.
โก๏ธ Did it work?
If yes, you are not properly restricting access within your Active Directory.
โ ๏ธ And it does not end with workstations. With a Domain Admin account, you should ๐ป๐ผ๐ ๐ฏ๐ฒ ๐ฎ๐ฏ๐น๐ฒ ๐๐ผ ๐ฐ๐ผ๐ป๐ป๐ฒ๐ฐ๐ anywhere except Tier 0 systems. This goes hand in hand with the Tiering Model.
And in my opinion, it is one of the ๐บ๐ผ๐๐ ๐ถ๐บ๐ฝ๐ผ๐ฟ๐๐ฎ๐ป๐ security measures you can implement in AD, because it dramatically limits where privileged accounts can be used.
๐ช๐ต๐?
1๏ธโฃ It makes privileged credential theft harder
โช๏ธ Lower tiers are usually ๐บ๐ผ๐ฟ๐ฒ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ๐ฑ. User workstations, jumpy admin habits, support tools, browsers, email, documents, internet access, third-party appsโฆ That is often where compromise starts.
โช๏ธ If higher privileged accounts cannot log on to lower tiers, attackers have fewer places to steal them from.
2๏ธโฃ It prevents โconvenientโ admin behavior
โช๏ธ I implement this quite often in customer environments. And one thing I repeatedly see is that admins sometimes try to take ๐๐ต๐ผ๐ฟ๐๐ฐ๐๐๐. Not because they want to be insecure. But because it is faster.
โช๏ธ If there is no technical restriction, ๐๐ต๐ฎ๐ ๐ฟ๐ฒ๐ฎ๐น๐น๐ ๐๐๐ผ๐ฝ๐ someone from using a powerful admin account to fix something on a workstation? Access restrictions create a clear boundary. They make the environment tell you:
โ๐๐ฐ, ๐ต๐ฉ๐ช๐ด ๐ข๐ค๐ค๐ฐ๐ถ๐ฏ๐ต ๐ด๐ฉ๐ฐ๐ถ๐ญ๐ฅ ๐ฏ๐ฐ๐ต ๐ฃ๐ฆ ๐ถ๐ด๐ฆ๐ฅ ๐ฉ๐ฆ๐ณ๐ฆ.โ
โ And that is exactly what you want.
Access restrictions and Tiering Model are ๐๐ผ๐ฝ๐ถ๐ฐ๐ ๐ ๐ฐ๐ผ๐๐ฒ๐ฟ in my hands-on course Building a Secure Active Directory, including how to build and enforce this properly on your own. There are also ๐ณ๐ฟ๐ฒ๐ฒ ๐ฝ๐ฟ๐ฒ๐๐ถ๐ฒ๐๐ available if you want to check the style first.
๐๐ผ ๐๐ผ๐ restrict privileged account access in your environment? And what approach do you use?
