Using Smart Cards in Active Directory? Don’t forget the NT hash.

โฑ๏ธย 60-Second Bitsย ๐Ÿ”’

๐—จ๐˜€๐—ถ๐—ป๐—ด ๐—ฆ๐—บ๐—ฎ๐—ฟ๐˜ ๐—–๐—ฎ๐—ฟ๐—ฑ๐˜€ ๐—ถ๐—ป ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜†? ๐——๐—ผ๐—ปโ€™๐˜ ๐—ณ๐—ผ๐—ฟ๐—ด๐—ฒ๐˜ ๐˜๐—ต๐—ฒ ๐—ก๐—ง ๐—›๐—ฎ๐˜€๐—ต.

Many administrators assume Smart Cards eliminate password-related risks. They donโ€™t.

By default,ย ๐—ฆ๐—บ๐—ฎ๐—ฟ๐˜ ๐—–๐—ฎ๐—ฟ๐—ฑ ๐—น๐—ผ๐—ด๐—ผ๐—ปย replaces the password with a randomย ๐—ก๐—ง ๐—›๐—ฎ๐˜€๐—ต, but that hash can remain unchanged indefinitely.

To reduce the risk:

โœ… Enableย ๐—ก๐—ง ๐—›๐—ฎ๐˜€๐—ต ๐—ฅ๐—ผ๐˜๐—ฎ๐˜๐—ถ๐—ผ๐—ปย so the hash changes automatically based on your password policy.

โœ… Add privileged accounts to theย ๐—ฃ๐—ฟ๐—ผ๐˜๐—ฒ๐—ฐ๐˜๐—ฒ๐—ฑ ๐—จ๐˜€๐—ฒ๐—ฟ๐˜€ย group to prevent NT hash caching inย ๐—Ÿ๐—ฆ๐—”๐—ฆ๐—ฆย and enforce Kerberos-only authentication.

Smart Cards are an excellent security control-but theyโ€™re only part of the solution.