๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ
Real configs. Real fixes. Windows & AD security.
Do you use the ๐ฃ๐ฟ๐ผ๐๐ฒ๐ฐ๐๐ฒ๐ฑ ๐จ๐๐ฒ๐ฟ๐ ๐ด๐ฟ๐ผ๐๐ฝ?
You should. Itโs a tiny change with a huge payoffโand I rarely see it enabled in the wild. There are following protections for you privileged accounts:
๐ข๐ป ๐๐ต๐ฒ ๐ฑ๐ฒ๐๐ถ๐ฐ๐ฒ (๐๐ผ๐ฟ๐ธ๐๐๐ฎ๐๐ถ๐ผ๐ป/๐๐ฒ๐ฟ๐๐ฒ๐ฟ):
๐น WDigest/CredSSP wonโt cache plaintext passwords
๐น NT hash not cached in LSASS
๐น Kerberos uses AES only
๐๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐ฑ๐ผ๐บ๐ฎ๐ถ๐ป ๐ฐ๐ผ๐ป๐๐ฟ๐ผ๐น๐น๐ฒ๐ฟ:
๐น No NTLM authentication for these users
๐น Kerberos DES/RC4 disabled (AES only)
๐น (Un)constrained delegation blocked
๐น TGT is 4-hour, non-renewable
There is one “๐ฑ๐ฟ๐ฎ๐๐ฏ๐ฎ๐ฐ๐ธ”, IP-based access breaks (NTLM based). Kerberos by default doesn’t support IP addresses, but it can be configured. Donโt add the built-in ADAdministratorโkeep one ๐๐ฅ ๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐ outside.
If you want to see it for yourself, ๐ฏ๐๐ถ๐น๐ฑ ๐ฎ ๐๐ถ๐ป๐ ๐น๐ฎ๐ฏ, log on to a loose host with a privileged account and inspect LSASS; then add the account to Protected Users, log on again, compare.
Want to learn more? I cover this topic in ๐บ๐ ๐ณ๐ฟ๐ฒ๐ฒ ๐ฐ๐ผ๐๐ฟ๐๐ฒ:
https://academy.horizon-secured.com/p/active-directory-protected-users-group
๐๐๐๐ง๐ฃ โข ๐ฝ๐ช๐๐ก๐ โข ๐ฟ๐๐๐๐ฃ๐
