๐๐ฒ๐ณ๐ฎ๐๐น๐ โ ๐๐ฎ๐ฟ๐ฑ๐ฒ๐ป๐ฒ๐ฑ
Real configs. Real fixes. Windows & AD security.
๐ช๐ต๐ฎ๐ ๐ฑ๐ผ๐ฒ๐ ๐๐ผ๐๐ฟ ๐น๐ผ๐ฐ๐ฎ๐น ๐ด๐ฟ๐ผ๐๐ฝ ๐บ๐ฒ๐บ๐ฏ๐ฒ๐ฟ๐๐ต๐ถ๐ฝ ๐น๐ผ๐ผ๐ธ ๐น๐ถ๐ธ๐ฒ?
During my security assessments, I unfortunately often see the โleft sideโ.
๐ธ Messy local group membership.
๐ธ No clear ownership.
๐ธ No defined state.
๐ธ No real control over who can access the device interactively or who is local admin on it.
And this is very typical.
Over time, ๐ฐ๐ผ๐ป๐ณ๐ถ๐ด๐๐ฟ๐ฎ๐๐ถ๐ผ๐ป ๐ฑ๐ฟ๐ถ๐ณ๐๐. Administrators, external providers, developers, project teams, support teamsโฆ people keep adding members when they need access. Projects come and go. ๐๐ฐ๐ฐ๐ฒ๐๐ ๐๐๐ฎ๐๐.
โ ๏ธ Unmanaged local group membership can easily create ๐๐ป๐ป๐ฒ๐ฐ๐ฒ๐๐๐ฎ๐ฟ๐ ๐ฎ๐๐๐ฎ๐ฐ๐ธ ๐ฝ๐ฎ๐๐ต๐ across your environment.
๐ฌ๐ผ๐ ๐๐ต๐ผ๐๐น๐ฑ ๐ฐ๐ผ๐ป๐๐ฟ๐ผ๐น ๐๐ต๐ถ๐ ๐๐ต๐ฟ๐ผ๐๐ด๐ต ๐๐๐ผ ๐๐ต๐ถ๐ป๐ด๐:
1๏ธโฃ User Rights Assignment – who can log on locally, over RDP, as a service, etc.
2๏ธโฃ Local group membership – who is actually a local administrator or member of other sensitive local groups.
Both should be ๐๐๐ฟ๐ถ๐ฐ๐๐น๐ ๐ฑ๐ฒ๐ณ๐ถ๐ป๐ฒ๐ฑ ๐ฎ๐ป๐ฑ ๐ฐ๐ผ๐ป๐๐ฟ๐ผ๐น๐น๐ฒ๐ฑ. This is usually part of a proper Tiering Model implementation, where you define tiers, memberships, privileges, and access restrictions.
But letโs focus only on local group membership here. The best way I usually implement this is through ๐๐ฟ๐ผ๐๐ฝ ๐ฃ๐ผ๐น๐ถ๐ฐ๐ ๐ฃ๐ฟ๐ฒ๐ณ๐ฒ๐ฟ๐ฒ๐ป๐ฐ๐ฒ๐.
๐๐ถ๐ด๐ต ๐น๐ฒ๐๐ฒ๐น ๐ถ๐ฑ๐ฒ๐ฎ:
1๏ธโฃ Higher OU / tier structure
โช๏ธ Define the expected local Administrators group for that group of devices.
โช๏ธ Here you remove all current members and groups, and then add only what should be there.
โช๏ธ The built-in local Administrator account with RID 500 stays automatically.
2๏ธโฃ Lower OU / more specific structure
โช๏ธ You can then add additional members where needed, but without clearing the whole group again.
โ This way, when GPO applies, it ๐ฟ๐ฒ๐บ๐ผ๐๐ฒ๐ ๐๐ป๐๐ฎ๐ป๐๐ฒ๐ฑ members and rebuilds the group into the expected state.
โก๏ธ But be careful. Just because you can keep adding members lower in the structure does not mean you should. You still need to think about the ๐ง๐ถ๐ฒ๐ฟ๐ถ๐ป๐ด ๐ ๐ผ๐ฑ๐ฒ๐น and avoid creating cross-tier attack paths.
This exact implementation is something I teach in my Building a Secure Active Directory ๐ฐ๐ผ๐๐ฟ๐๐ฒ, where you ๐ฏ๐๐ถ๐น๐ฑ ๐ฎ ๐ง๐ถ๐ฒ๐ฟ๐ถ๐ป๐ด ๐ ๐ผ๐ฑ๐ฒ๐น ๐ผ๐ป ๐๐ผ๐๐ฟ ๐ผ๐๐ป and enforce control over local group membership.
Another option is ๐ฅ๐ฒ๐๐๐ฟ๐ถ๐ฐ๐๐ฒ๐ฑ ๐๐ฟ๐ผ๐๐ฝ๐, but in most real environments I find it too rigid and not flexible enough for this use case.
What do you use to keep local group memberships clean and controlled?
