logo

Protected Users: you thought you were safe uh?

ID: 34c3cf4e-58ee-5725-a32f-ec5c3d00ad8d

STIX ID: report--34c3cf4e-58ee-5725-a32f-ec5c3d00ad8d

Feed Name: SensePost Blog

Threat Score
70/100

Date Published: 2023-03-31

Date Updated: 2026-04-30

...
...

This report demonstrates that the Active Directory built-in RID 500 (Administrator) account remains exempt from key protections of the "Protected Users" group: RC4-based Kerberos authentication and delegation can still be leveraged, enabling OverPass-the-Hash and RBCD delegation abuse when an NT hash or active session is available. The authors provide proof-of-concept tests, exploitation scenarios, and mitigations (restrict protocol encryption via ms-DSSupportedProtocolEncryption, set the account as sensitive and non-delegable, or disable the account), and note Microsoft considers the behavior intended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.