AD privileges & permissions

intermediateInternal & Active Directory

TL;DR

Active Directory decides who can do what across a Windows network. A handful of groups and rights are effectively game over if the wrong account holds them, so most of the value is in knowing which ones matter and keeping them to as few people as possible.

What it is

Active Directory (AD) is the directory most Windows networks run on: it holds the users, computers and groups, and domain controllers enforce who can do what. Permissions are what an account can do to a specific object (a file, a group, another user). Privileges (user rights) are broader powers, like logging on as a service or acting as part of the operating system.

The ones that matter

You do not need to memorise everything. A short list of memberships and rights carries most of the risk:

Group / rightWhy it matters
Domain AdminsFull control of the domain. The classic target.
Enterprise AdminsControl across every domain in the forest. Bigger still.
Account / Server OperatorsOften overlooked, but powerful enough to be a stepping stone.
DCSync (Replicating Directory Changes)Lets an account pull password data as if it were a domain controller.
Unconstrained delegationA machine that can impersonate anyone who connects to it.

How to review it

Defending AD is mostly knowing who holds these and shrinking the list:

Reference: Microsoft’s Best Practices for Securing Active Directory.

← Back to Internal & Active Directory