Do you use Protected Users group?

๐——๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ โ†’ ๐—›๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐—ป๐—ฒ๐—ฑ

Real configs. Real fixes. Windows & AD security.

Do you use the ๐—ฃ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜๐—ฒ๐—ฑ ๐—จ๐˜€๐—ฒ๐—ฟ๐˜€ ๐—ด๐—ฟ๐—ผ๐˜‚๐—ฝ?

You should. Itโ€™s a tiny change with a huge payoffโ€”and I rarely see it enabled in the wild. There are following protections for you privileged accounts:

๐—ข๐—ป ๐˜๐—ต๐—ฒ ๐—ฑ๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ (๐˜„๐—ผ๐—ฟ๐—ธ๐˜€๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ป/๐˜€๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ):

๐Ÿ”น WDigest/CredSSP wonโ€™t cache plaintext passwords

๐Ÿ”น NT hash not cached in LSASS

๐Ÿ”น Kerberos uses AES only

๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—ฑ๐—ผ๐—บ๐—ฎ๐—ถ๐—ป ๐—ฐ๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐—น๐—ฒ๐—ฟ:

๐Ÿ”น No NTLM authentication for these users

๐Ÿ”น Kerberos DES/RC4 disabled (AES only)

๐Ÿ”น (Un)constrained delegation blocked

๐Ÿ”น TGT is 4-hour, non-renewable

There is one “๐—ฑ๐—ฟ๐—ฎ๐˜„๐—ฏ๐—ฎ๐—ฐ๐—ธ”, IP-based access breaks (NTLM based). Kerberos by default doesn’t support IP addresses, but it can be configured. Donโ€™t add the built-in ADAdministratorโ€”keep one ๐——๐—ฅ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜ outside.

If you want to see it for yourself, ๐—ฏ๐˜‚๐—ถ๐—น๐—ฑ ๐—ฎ ๐˜๐—ถ๐—ป๐˜† ๐—น๐—ฎ๐—ฏ, log on to a loose host with a privileged account and inspect LSASS; then add the account to Protected Users, log on again, compare.

Want to learn more? I cover this topic in ๐—บ๐˜† ๐—ณ๐—ฟ๐—ฒ๐—ฒ ๐—ฐ๐—ผ๐˜‚๐—ฟ๐˜€๐—ฒ:

https://academy.horizon-secured.com/p/active-directory-protected-users-group

๐™‡๐™š๐™–๐™ง๐™ฃ โ€ข ๐˜ฝ๐™ช๐™ž๐™ก๐™™ โ€ข ๐˜ฟ๐™š๐™›๐™š๐™ฃ๐™™