When assessing Active Directory, which TWO of the following configurations are considered high-risk misconfigurations that commonly lead to full domain compromise?
Trap 1: The existence of a local administrator group
Every Windows machine has a local administrator group by design. The existence of this group is standard behavior and not inherently a security misconfiguration. Security risk only arises if improper credentials are used or if access controls to this group are poorly managed within the domain infrastructure.
Trap 2: Frequent password rotation for service accounts
Frequent password rotation is a security best practice, not a misconfiguration. It limits the window of opportunity for an attacker if a credential is ever leaked. It does not facilitate domain compromise, and in fact, it serves as a defensive measure against long-term credential persistence and unauthorized access.
Trap 3: Domain user account password complexity requirements
Enforcing password complexity is a standard security control to prevent brute-force attacks. It is not a misconfiguration that leads to domain compromise. Strong password policies are fundamental to protecting Active Directory against unauthorized access and should be implemented as part of a robust organization-wide security posture.
- A
Unconstrained delegation enabled on a server
Unconstrained delegation allows a computer to store the TGT of any user who authenticates to it. If a domain administrator connects to this server, their TGT is cached, enabling the attacker to impersonate them and compromise the domain, which is a classic escalation vector in Active Directory environments.
- B
The existence of a local administrator group
Why it fails: Every Windows machine has a local administrator group by design. The existence of this group is standard behavior and not inherently a security misconfiguration. Security risk only arises if improper credentials are used or if access controls to this group are poorly managed within the domain infrastructure.
- C
GenericAll rights assigned to a user over a Domain Admin object
GenericAll rights provide full control over an object, including the ability to reset passwords or change properties. If assigned to a user over a highly privileged account, the user can reset that admin's password and assume their identity, leading to a complete compromise of the Active Directory domain.
- D
Frequent password rotation for service accounts
Why it fails: Frequent password rotation is a security best practice, not a misconfiguration. It limits the window of opportunity for an attacker if a credential is ever leaked. It does not facilitate domain compromise, and in fact, it serves as a defensive measure against long-term credential persistence and unauthorized access.
- E
Domain user account password complexity requirements
Why it fails: Enforcing password complexity is a standard security control to prevent brute-force attacks. It is not a misconfiguration that leads to domain compromise. Strong password policies are fundamental to protecting Active Directory against unauthorized access and should be implemented as part of a robust organization-wide security posture.