Loading...

Microsoft Defender for Identity expands its coverage with new AD CS sensor!

Microsoft Defender for Identity expands its coverage with new AD CS sensor!

Active Directory (AD) continues to be a major component of most organizations’ IT footprint, and as such, attackers are constantly hunting for vulnerabilities or misconfigurations they can exploit. To stay ahead of these new tactics, and ensure we continue to deliver powerful security solutions to our customers, our research and engineering teams are always evolving and updating our offerings.

One such enhancement is a new Microsoft Defender for Identity sensor that can be deployed on Active Directory Certificate Services (AD CS) servers. This new sensor builds on the existing detections for suspicious certificate usage available today and extends Defender for Identities capabilities and coverage more comprehensively across identity environments.


What is Active Directory Certificate Services?

In Active Directory environments, Active Directory Certificate Services (AD CS) is a role in Windows Server that allows you to create and manage public key infrastructure (PKI) certificates. These certificates are used to establish trusted and secure communication between users, devices, and applications on a network or, more importantly for this discussion, as password- equivalents for user authentication.


While AD CS is not a default element of every AD instance, the adoption of new authentication methods has led to rather widespread deployment. Despite this popularity the security capabilities around this infrastructure has not been a focus. Pairing the lack of protection with the fact that the certificates managed via these servers replace passwords and other authentication mechanisms, they are a ripe target for would be attackers. Further fueling the issue is that AD CS can be extremely easy to misconfigure.


To put the gravity of these vulnerabilities into perspective lets take a hypothetical example. In this case a malicious actor has successfully exploited a misconfiguration in your AD CS server and has minted or stolen a certificate. Because that certificate acts as a password-equivalent the identity and access management controls you have in place will be bypassed and the attacker will have gained a foothold in your organization, all without having to compromise a single password.

What are the benefits of this new sensor?

The new sensor will provide Defender for Identity customers with new detections and security recommendations in Secure Score including:  

New detections:

  • Domain-controller certificate issuance for a non-DC – also known as ESC8, an attacker can relay NTLM authentication to ADCS, issuing a certificate for the impersonated entity. When the victim of such an attack is a Domain Controller, this can result in full domain compromise. ESC8.png
  • Suspicious disable of audit logs of AD CS – Attackers will often disable the logs so that they can perform malicious actions without leaving any trace of their activities. Defender for Identity will now track the audit configurations and alert you when that change has been made. Suspicious audit log.png
  •  Suspicious deletion of the certificate database – Attackers will often delete certificate requests in an effort to cover their tracks. This new detection will monitor that activity by tracking when and by whom those requests are deleted. Suspicious deletion.png

  • Suspicious modifications to the AD CS settings (coming soon)- This event suggests that a change was made to the access control list (ACL) of the certification authority itself. This allows attackers to perform certificate authority level operations that potentially can lead to domain takeover. 

     

Upcoming security recommendations in Secure Score:

  • Prevent users from requesting a certificate valid for arbitrary users based on a vulnerable certificate template (ESC1) 
  • Edit overly permissive Certificate Template with privileged EKU (Any purpose EKU or No EKU) (ESC2)
  • Edit misconfigured enrollment agent certificate template (ESC3)
  • Edit misconfigured certificate templates ACL (ESC4)
  • Edit misconfigured certificate templates owner (ESC4)

 

Learn more about the new sensor in our documentation here and check back for updates on new detections and security recommendations around AD CS coming over the next few weeks.

 

Published on:

Learn more
Microsoft 365 Defender Blog articles
Microsoft 365 Defender Blog articles

Microsoft 365 Defender Blog articles

Share post:

Related posts

Monthly news - November 2024

Microsoft Defender XDRMonthly newsNovember 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and v...

1 year ago

Monthly news - August 2024

Microsoft Defender XDRMonthly newsAugust 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and var...

1 year ago

Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

New Security Copilot skill: Identity Summary

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Demystify potential data leaks with Insider Risk Management insights in Defender XDR

In today's complex security landscape, understanding and mitigating data exfiltration risks is more critical than ever. Earlier this year, we ...

1 year ago

Monthly news - October 2024

Microsoft Defender XDRMonthly newsOctober 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and va...

1 year ago

AI-Driven Guided Response for SOCs with Microsoft Copilot for Security

In today's evolving cybersecurity landscape, security operation centers (SOCs) are constantly bombarded with incidents ranging from minor aler...

1 year ago

Identity Summary: New Security Copilot skill within Defender XDR

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Detecting browser anomalies to disrupt attacks early

Detecting browser anomalies is crucial for early identification and prevention of cyber threats, preventing data breaches and attacks by monit...

1 year ago

Microsoft Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.