Do your services still run under regular domain user accounts?

๐——๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ โ†’ ๐—›๐—ฎ๐—ฟ๐—ฑ๐—ฒ๐—ป๐—ฒ๐—ฑ

Real configs. Real fixes. Windows & AD security.

Do your services still run under ๐—ฟ๐—ฒ๐—ด๐˜‚๐—น๐—ฎ๐—ฟ ๐—ฑ๐—ผ๐—บ๐—ฎ๐—ถ๐—ป ๐˜‚๐˜€๐—ฒ๐—ฟ ๐—ฎ๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€?

Thatโ€™s the classic ๐˜๐—ฟ๐—ฎ๐—ฝ ๐Ÿงจ.ย Over-privileged accounts, passwords that never change, SPNs that make them ๐—ธ๐—ฒ๐—ฟ๐—ฏ๐—ฒ๐—ฟ๐—ผ๐—ฎ๐˜€๐˜๐—ฎ๐—ฏ๐—น๐—ฒโ€”and on Windows services, the credential ends up in the registry and can be retrieved in plain text. All of this is avoidable (if supported by the service).

๐—จ๐˜€๐—ฒ ๐— ๐—ฎ๐—ป๐—ฎ๐—ด๐—ฒ๐—ฑ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ ๐—”๐—ฐ๐—ฐ๐—ผ๐˜‚๐—ป๐˜๐˜€ (MSA / gMSA / dMSA). Theyโ€™re built for services and fix the core risks:

๐Ÿ”น Strong, automatically rotated passwords managed by AD

๐Ÿ”น No interactive logon (service use only)

๐Ÿ”น Kerberos-only authentication

๐Ÿ”น No password stored on the hostโ€™s registry

๐Ÿ”น Kerberoasting risk minimized by strong, rotating keys

Want a quick walkthrough with examples? Iโ€™ve got a ๐—ณ๐—ฟ๐—ฒ๐—ฒ ๐—บ๐—ถ๐—ป๐—ถ-๐—ฐ๐—ผ๐˜‚๐—ฟ๐˜€๐—ฒ on service accounts.

๐™‡๐™š๐™–๐™ง๐™ฃ โ€ข ๐˜ฝ๐™ช๐™ž๐™ก๐™™ โ€ข ๐˜ฟ๐™š๐™›๐™š๐™ฃ๐™™