Do you RDP to your Domain Controllers from your workstation?

โฑ๏ธ 60-Second Bits ๐Ÿ”’

๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐—ฅ๐——๐—ฃ ๐˜๐—ผ ๐˜†๐—ผ๐˜‚๐—ฟ ๐——๐—ผ๐—บ๐—ฎ๐—ถ๐—ป ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐—น๐—ฒ๐—ฟ๐˜€ ๐—ณ๐—ฟ๐—ผ๐—บ ๐˜†๐—ผ๐˜‚๐—ฟ ๐˜„๐—ผ๐—ฟ๐—ธ๐˜€๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ป?

Even with ๐—–๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—š๐˜‚๐—ฎ๐—ฟ๐—ฑ enabled, your ๐——๐—ผ๐—บ๐—ฎ๐—ถ๐—ป ๐—”๐—ฑ๐—บ๐—ถ๐—ป ๐—ฐ๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น๐˜€ can still end up in the ๐— ๐—ฆ๐—ง๐—ฆ๐—– process memory on your workstation.

Credential Guard protects ๐—Ÿ๐—ฆ๐—”๐—ฆ๐—ฆ.

It does ๐—ป๐—ผ๐˜ protect credentials handled by the ๐—ฅ๐——๐—ฃ client.

If your workstation is compromised, an attacker may be able to recover those credentials from ๐—บ๐˜€๐˜๐˜€๐—ฐ.๐—ฒ๐˜…๐—ฒ.

The solution isnโ€™t another Windows security feature.

Itโ€™s proper privileged administration:

โœ… ๐—ฃ๐—ฟ๐—ถ๐˜ƒ๐—ถ๐—น๐—ฒ๐—ด๐—ฒ๐—ฑ ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—ช๐—ผ๐—ฟ๐—ธ๐˜€๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ป (๐—ฃ๐—”๐—ช)

โœ… A properly implemented ๐—ง๐—ถ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด ๐— ๐—ผ๐—ฑ๐—ฒ๐—น

Credential Guard is important.

It just doesnโ€™t solve this problem.