{"id":7729,"date":"2023-07-17T08:00:48","date_gmt":"2023-07-17T06:00:48","guid":{"rendered":"https:\/\/www.teal-consulting.de\/?p=7729"},"modified":"2023-08-29T10:57:57","modified_gmt":"2023-08-29T08:57:57","slug":"troopers-conference-recap","status":"publish","type":"post","link":"https:\/\/www.teal-consulting.de\/en\/2023\/07\/17\/troopers-conference-recap\/","title":{"rendered":"Troopers Conference Recap: ACL-based Active Directory Attacks and Defenses"},"content":{"rendered":"<div class=\"wpb-content-wrapper\" id=\"wpb-content-root\">[vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;30&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text][\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_empty_space height=&#8221;30&#8243;][vc_column_text]Last month was the first time Teal was a speaker at the <a href=\"https:\/\/troopers.de\/\" target=\"_blank\" rel=\"noopener\">Troopers 23<\/a> Security Conference in Heidelberg, Germany. In this blog post, we would like to share the topic we presented with a wider audience. We strongly believe that a layered security structure can improve IT security in the long run. However, there are a few issues to consider and these are exactly what we would like to share here.<\/p>\n<p>But first, what are the troops? Hardcore security enthusiasts will probably be familiar with it, but probably not everyone. Troopers is an annual security conference in Heidelberg, Germany, where IT security topics are discussed in depth in training sessions, lectures, and roundtables. Active Directory security topics are always on the agenda. The speakers are also internationally recognized. For example, Sean Metcalf (Mr. AD Security \ud83d\ude0a <a href=\"https:\/\/adsecurity.org\/?author=2\" target=\"_blank\" rel=\"noopener\">Sean Metcalf &#8211; Active Directory Security (adsecurity.org)<\/a>), but also our partner company SpecterOps has already held presentations there.<\/p>\n<p>Reason enough for us to want to be there as well. That&#8217;s why we submitted a presentation together with our friends from <a href=\"https:\/\/specterops.io\/\" target=\"_blank\" rel=\"noopener\">SpecterOps<\/a> in early 2023 &#8211; and to our delight, it was quickly accepted.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text]\n<h2>Our topic \u2013 Hidden Pathways: Exploring the Anatomy of ACL-Based Active Directory Attacks and Building Strong Defenses<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]While brainstorming with SpecterOps, we quickly realized the potential to combine our respective strengths and provide valuable value to our audience. SpecterOps, through BloodHound and <a href=\"https:\/\/aktionen.teal-consulting.de\/bloodhound-enterprise\/?utm_source=blog\" target=\"_blank\" rel=\"noopener\">BloodHound Enterprise<\/a>, specializes in discovering attack vectors, visualizing them, and presenting technical information as a defense. Teal helps clients evaluate and improve management processes and architectures to reduce the attack surface and minimize the impact of a successful attack.<\/p>\n<p>From a purely technical perspective, it is &#8220;easy&#8221; to close an attack vector by removing a privilege, for example. However, in a complex IT infrastructure that has grown over time, it is often very difficult to make changes &#8220;on the fly&#8221; without good preparation. This is where we come in and help our customers. The goal is to adapt processes and behaviors so that the operations team can be involved and security measures can be implemented appropriately.[\/vc_column_text][vc_empty_space height=&#8221;50&#8243;][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; z_index=&#8221;&#8221; background_color=&#8221;#ededed&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text]\n<h2 style=\"text-align: center;\">The complete recorded presentation<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_video link=&#8221;https:\/\/www.youtube.com\/watch?v=4aQZUdpmQno&#8221; el_width=&#8221;80&#8243; align=&#8221;center&#8221; css_animation=&#8221;fadeInDown&#8221;][vc_empty_space height=&#8221;50&#8243;][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_column_text]\n<h2>Let&#8217;s start with the theme of the previous day &#8211; really \ud83d\ude0a<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]After an admittedly somewhat lengthy introduction, let&#8217;s get down to business.<\/p>\n<p>In Active Directory, there are both standard permissions and historically grown misconfigurations that an attacker can exploit. First, we will briefly explain how permissions work in AD, then we will describe why this well-known topic is still relevant today, and finally we will present our solution approach.[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_column_text]\n<h2>What are AD ACLs \/ ACEs?<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]Every object in Active Directory has an Access Control List (ACL). Just like in the NTFS file system, the ACL describes &#8220;who can do what&#8221;. The ACL is composed of individual Access Control Entries (ACEs) that define an atomic permission. This then looks like this:<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-7696 lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_1.png\" alt=\"\" width=\"943\" height=\"447\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_1.png 943w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_1-300x142.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_1-768x364.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_1-700x332.png 700w\" data-sizes=\"(max-width: 943px) 100vw, 943px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 943px; --smush-placeholder-aspect-ratio: 943\/447;\" \/><\/p>\n<p>The user object &#8220;Andy&#8221; has an ACL that is composed of 32 ACEs. To give some examples:<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>The group &#8220;Account Operators&#8221; has the right &#8220;Full Control&#8221;<\/li>\n<li>The group &#8220;Cert Publishers&#8221; has the right to read and write the &#8220;UserCertificate&#8221; property<\/li>\n<li>The group Service Desk has the right &#8220;Reset Password<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_column_text]\n<h2>How ACLs can be exploited (examples)<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]Bloodhound visualizes the (known) exploitable ACLs in so-called <a href=\"https:\/\/bloodhound.readthedocs.io\/en\/latest\/data-analysis\/edges.html\" target=\"_blank\" rel=\"noopener\">Edges<\/a>:<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-7698 lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_2.png\" alt=\"\" width=\"630\" height=\"310\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_2.png 630w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_2-300x148.png 300w\" data-sizes=\"(max-width: 630px) 100vw, 630px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 630px; --smush-placeholder-aspect-ratio: 630\/310;\" \/><\/p>\n<p>In this example, the Helpdeskadmins group can add members to the Serveradmins group. Since Andy is a member of this group, he also has this right. The Serveradmins group in turn has the &#8220;Generic All&#8221; right = full access to a server named &#8220;Adminserver01&#8221;.<\/p>\n<p>The &#8220;Full Access&#8221; right can be exploited in several ways:<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li>If the client uses LAPS, the attacker can read the password of the local administrator<\/li>\n<li>A s<a href=\"https:\/\/eladshamir.com\/2021\/06\/21\/Shadow-Credentials.html\" target=\"_blank\" rel=\"noopener\">shadow credential<\/a> attack that steals the TGT or NTLM hash of the object<\/li>\n<li>A <a href=\"https:\/\/eladshamir.com\/2019\/01\/28\/Wagging-the-Dog.html\" target=\"_blank\" rel=\"noopener\">Resource Based Constrained Delegation<\/a> attack that authenticates an arbitrary user against the object<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_column_text]\n<h2>Why are ACLs still a security issue today?<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]ACL based attacks are not new, but misconfigurations are something we encounter in virtually every environment.<\/p>\n<p>We have identified 4 reasons why we think this is the case:<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li><strong>ACLs are complicated.<\/strong><br \/>\nThe default security descriptor defines the permissions that each newly created object has. For example, if a pentest report showed that an attacker had exploited the &#8220;full control&#8221; permission described above, one might think that removing the permission would solve the problem. In reality, however, any newly created object will contain this ACE again and thus be exploitable again.<br \/>\nBesides the Default Security Descriptor there is also the <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/ad-ds\/plan\/security-best-practices\/appendix-c--protected-accounts-and-groups-in-active-directory\" target=\"_blank\" rel=\"noopener\">AdminSD Holder process<\/a>. This protects the objects that are worth protecting from Microsoft&#8217;s point of view and overwrites changes to the permissions. To stay with the example of the pentest report, if one were to adjust the permission of a protected object after the pentest, the change would be reversed after one hour. Unfortunately, not all relevant objects are protected by the AdminSD Holder process.<\/li>\n<li>New attack paths are still being found that are all based on ACLs. Here is an example of what has been added to Bloodhound alone since 2017:<img decoding=\"async\" class=\"aligncenter wp-image-7705 size-full lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal-3.png\" alt=\"\" width=\"896\" height=\"334\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal-3.png 896w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal-3-300x112.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal-3-768x286.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal-3-700x261.png 700w\" data-sizes=\"(max-width: 896px) 100vw, 896px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 896px; --smush-placeholder-aspect-ratio: 896\/334;\" \/><\/li>\n<li>The number of ACLs and relationships to other objects is mind-boggling. In the following Bloodhound Enterprise screenshot from a relatively small environment with ~4500 users, it can be seen that there are 360,000 ACLs or ~480,000 relationships.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-7702 lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_4.png\" alt=\"\" width=\"478\" height=\"506\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_4.png 478w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_4-283x300.png 283w\" data-sizes=\"(max-width: 478px) 100vw, 478px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 478px; --smush-placeholder-aspect-ratio: 478\/506;\" \/><\/p>\n<p>These are orders of magnitude far beyond what can be manually tested.[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_column_text]\n<h2>What can we do now?<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]One solution, and the one we favor, is to introduce a tiering structure and protect assets based on their need for protection. One aspect and core topic of the Troopers talk \/ this article is to build a protected OU structure as a basic framework for tiering. We have already blogged about some of the other measures (<a href=\"https:\/\/www.teal-consulting.de\/en\/2021\/02\/15\/esae-deep-dive-serie-part-7-tiering-model\/\" target=\"_blank\" rel=\"noopener\">LINK1<\/a>, <a href=\"https:\/\/www.teal-consulting.de\/en\/2019\/11\/13\/assume-breach\/\" target=\"_blank\" rel=\"noopener\">LINK2<\/a>), with more articles to follow.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-7731 size-full lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_12.png\" alt=\"\" width=\"1200\" height=\"310\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_12.png 1200w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_12-300x78.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_12-1024x265.png 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_12-768x198.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_12-700x181.png 700w\" data-sizes=\"(max-width: 1200px) 100vw, 1200px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1200px; --smush-placeholder-aspect-ratio: 1200\/310;\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>We strongly recommend NOT adjusting permissions in existing OUs (except for isolated quick wins). Instead, a new OU structure should be created, provided with the appropriate permissions and filled.<\/p>\n<p>The recommendations for permissions are based on a <a href=\"https:\/\/learn.microsoft.com\/en-us\/previous-versions\/windows\/it-pro\/windows-server-2003\/cc773365(v=ws.10)\" target=\"_blank\" rel=\"noopener\">Best Practice Guide<\/a> from 2011 \ud83d\ude0a. This 12 year old source is still valid and, we are not currently aware of a newer valid reference. If anyone has a newer source, they are very welcome to contact us. We would also donate an ice cream \ud83d\ude0a.[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_column_text]\n<h2>Define roles and responsibilities<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]First, the question of who should do what must be answered. What sounds simple is often very difficult to answer. Companies often don&#8217;t know who should do what. Or there are statements like &#8211; everyone in team XY has to be the local administrator on all servers. But it doesn&#8217;t work that way. It&#8217;s tedious and painful, but it&#8217;s imperative to get rid of this legacy. Here is a snippet of what a definition might look like:<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-7713 lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_6.png\" alt=\"\" width=\"1604\" height=\"331\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_6.png 1604w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_6-300x62.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_6-1024x211.png 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_6-768x158.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_6-1536x317.png 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_6-700x144.png 700w\" data-sizes=\"(max-width: 1604px) 100vw, 1604px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1604px; --smush-placeholder-aspect-ratio: 1604\/331;\" \/>[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_column_text]\n<h2>Building a new OU structure<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]Microsoft recommends a division into Tier0, Tier1 and Tier2 in the ESAE model. This can look like this, for example:<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-7716 lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_7.png\" alt=\"\" width=\"250\" height=\"482\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_7.png 250w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_7-156x300.png 156w\" data-sizes=\"(max-width: 250px) 100vw, 250px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 250px; --smush-placeholder-aspect-ratio: 250\/482;\" \/><\/p>\n<p>Of course, the structure can be adapted to the needs of each organization.<\/p>\n<p>To make it easier for our readers, we have published a script for creating the OUs:<\/p>\n<p><a href=\"https:\/\/github.com\/teal-technology-consulting\/New-TealTierOUs\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/teal-technology-consulting\/New-TealTierOUs<\/a><\/p>\n<p>The OUs are defined via an XML and created via script. Simply take our suggestion, or adapt the XML.[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_column_text]\n<h2>Set permissions<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]Next, the permissions from the Best Practice Guide must be set on the newly created OUs. We have published a script for this as well: <a href=\"https:\/\/github.com\/teal-technology-consulting\/Set-TealTierOUAcl\" target=\"_blank\" rel=\"noopener\">teal-technology-consulting\/Set-TealTierOUAcl: Sets secure permissions on a tiering OU structure (github.com)<\/a><\/p>\n<p>It stops inheritance at the top level (Administration OU in the example above), sets the desired permissions, and removes all direct permissions on child OUs.<\/p>\n<p>It leaves inheritance on the child OUs, so delegations are inherited as usual.[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_column_text]\n<h2>Move highly privileged groups<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]The Best Practice Guide states that the default groups &#8220;Domain Admins&#8221;, &#8220;Schema Admins&#8221; and Enterprise Admins should be moved to the secured OU structure.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-7718 lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_8.png\" alt=\"\" width=\"634\" height=\"340\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_8.png 634w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_8-300x161.png 300w\" data-sizes=\"(max-width: 634px) 100vw, 634px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 634px; --smush-placeholder-aspect-ratio: 634\/340;\" \/><\/p>\n<p>From our point of view, this is not enough. In addition to the groups mentioned above and the groups protected by the Admin SD Holder process, it is now known that other built-in groups can be exploited.<\/p>\n<p>Microsoft has <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/ad-ds\/manage\/understand-security-groups\" target=\"_blank\" rel=\"noopener\">documentation<\/a> on which groups can be moved, but in our opinion the documentation is flawed and not always helpful:<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-7720 lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_9.png\" alt=\"\" width=\"798\" height=\"80\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_9.png 798w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_9-300x30.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_9-768x77.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_9-700x70.png 700w\" data-sizes=\"(max-width: 798px) 100vw, 798px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 798px; --smush-placeholder-aspect-ratio: 798\/80;\" \/><\/p>\n<p>Therefore, we recommend moving all groups from the &#8220;Users&#8221; OU AFTER you have tested the effect in your own environment.[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_column_text]\n<h2>Set permissions regularly<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]Now we are actually ready to move the remaining assets to the correct OUS. We mentioned above that new objects get the ACLs from the default security descriptor. This gives Account Operators full access to users and group objects that are newly created within the protected OU structure:<\/p>\n<p><em>&#8220;The Account Operators group grants a user limited account creation privileges. Members of this group can create and modify most types of accounts, including accounts for users, local groups, and global groups. Group members can log on to domain controllers locally.&#8221;<\/em><\/p>\n<p>In general, we recommend that you do not use account operators, but this does not prevent an attacker from exploiting the permissions. Therefore, we have written a script that runs periodically, e.g. every 15 minutes by a scheduled task, which removes the account and print operators from the ACLs of all objects in the protected OU structure.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-7722 lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_10.png\" alt=\"\" width=\"376\" height=\"402\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_10.png 376w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_10-281x300.png 281w\" data-sizes=\"(max-width: 376px) 100vw, 376px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 376px; --smush-placeholder-aspect-ratio: 376\/402;\" \/><\/p>\n<p>The script can be found here:<\/p>\n<p><a href=\"https:\/\/github.com\/teal-technology-consulting\/Remove-AccAndPrintOpsFromOU\" target=\"_blank\" rel=\"noopener\">teal-technology-consulting\/Remove-AccAndPrintOpsFromOU: A script to remove the Print- and Account Operator groups from all objects in an OU structure. It is meant to run in a scheduled task. (github.com)<\/a><\/p>\n<p>An alternative is to change the default security descriptor. Since we cannot exclude the possibility that this may cause unintended page effects, we prefer the scripting variant.[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_column_text]\n<h2>New objects, delegate and move<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]The OU structure is now ready for use and assets can be moved into the structure. Depending on the size of the organization, this can be a lengthy process.<\/p>\n<p>It is recommended to start with the new objects to be created first and train the administrators on how to use the new structure.<\/p>\n<p>If existing objects are moved, the permissions must be checked, since directly set ACEs are also moved. By the way, this also applies to group policy objects that are linked to the new OU structure.<\/p>\n<p>To enforce tier separation of accounts, Kerberos Authentication Policy Silos should be set up. But that is a topic for another post \ud83d\ude09.[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_column_text]\n<h2>Conclusion<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]These changes can go a long way toward improving IT security. Some of the activities shown are complex and tedious, but they are definitely worth it. For one thing, after implementation, you will have defined who has what responsibilities and cleaned up outdated permission structures. The whole thing can be done without expensive detection and response solutions &#8211; so it doesn&#8217;t cost any licenses, but &#8220;only&#8221; the effort of existing IT resources. Don&#8217;t get me wrong, detection and response tools do add value, but often you have multiple tools in use, some of which do the same thing. This is where you could save money and instead spend the time and budget on eliminating the legacy. If you have any questions, please contact us.[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_column_text]\n<h2>Off Topic<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;][vc_column_text]At this point a big thank you to our Alex for preparing this talk and presenting it at Troopers. As soon as the talk is online, we will link it. Until then, here are some impressions from Troopers, including a fire alarm in the middle of the night \ud83d\ude0a.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-7724 lazyload\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_11.png\" alt=\"\" width=\"1200\" height=\"780\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_11.png 1200w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_11-300x195.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_11-1024x666.png 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_11-768x499.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_11-400x260.png 400w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/07\/troopers_blogartikel_teal_11-700x455.png 700w\" data-sizes=\"(max-width: 1200px) 100vw, 1200px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1200px; --smush-placeholder-aspect-ratio: 1200\/780;\" \/>[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;100&#8243;][vc_raw_html]JTNDYSUyMGhyZWYlM0QlMjJqYXZhc2NyaXB0JTNBaGlzdG9yeS5iYWNrJTI4JTI5JTIyJTNFJTNDc3BhbiUyMHN0eWxlJTNEJTIyY29sb3IlM0ElMjAlMjNmZjIwNzAlM0IlMjIlM0UlM0MlM0MlMjBCYWNrJTNDJTJGc3BhbiUzRSUzQyUyRmElM0U=[\/vc_raw_html][vc_empty_space height=&#8221;50&#8243;][vc_separator type=&#8221;small&#8221; position=&#8221;center&#8221; color=&#8221;#eeeeee&#8221; thickness=&#8221;2&#8243; width=&#8221;1100&#8243;][vc_empty_space height=&#8221;50&#8243;][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;center&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; z_index=&#8221;&#8221;][vc_column width=&#8221;1\/2&#8243; offset=&#8221;vc_hidden-sm vc_hidden-xs&#8221;][vc_column_text] <\/p>\n<div class=\"brlbs-cmpnt-container brlbs-cmpnt-content-blocker brlbs-cmpnt-with-individual-styles\" data-borlabs-cookie-content-blocker-id=\"default\" data-borlabs-cookie-content=\"PGlmcmFtZSB0aXRsZT0iRWluZ2ViZXR0ZXRlciBCZWl0cmFnIiBzcmM9Imh0dHBzOi8vd3d3LmxpbmtlZGluLmNvbS9lbWJlZC9mZWVkL3VwZGF0ZS91cm46bGk6dWdjUG9zdDo2ODU5NzU0MjE1OTM0MzI0NzM2P2NvbXBhY3Q9MSIgd2lkdGg9IjUwNCIgaGVpZ2h0PSIyODQiIGZyYW1lYm9yZGVyPSIwIiBhbGxvd2Z1bGxzY3JlZW49ImFsbG93ZnVsbHNjcmVlbiIgZGF0YS1tY2UtZnJhZ21lbnQ9IjEiPjwvaWZyYW1lPg==\">\n<div class=\"brlbs-cmpnt-cb-preset-a\">\n<p class=\"brlbs-cmpnt-cb-description\">You are currently viewing a placeholder content from <strong>Default<\/strong>. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.<\/p>\n<div class=\"brlbs-cmpnt-cb-buttons\"> <a class=\"brlbs-cmpnt-cb-btn\" href=\"#\" data-borlabs-cookie-unblock role=\"button\">Unblock content<\/a> <a class=\"brlbs-cmpnt-cb-btn\" href=\"#\" data-borlabs-cookie-accept-service role=\"button\" style=\"display: none\">Accept required service and unblock content<\/a> <\/div>\n<p> <a class=\"brlbs-cmpnt-cb-provider-toggle\" href=\"#\" data-borlabs-cookie-show-provider-information role=\"button\">More Information<\/a> <\/div>\n<\/div>\n[\/vc_column_text][\/vc_column][vc_column width=&#8221;1\/2&#8243; offset=&#8221;vc_hidden-sm vc_hidden-xs&#8221;][vc_column_text] <\/p>\n<div class=\"brlbs-cmpnt-container brlbs-cmpnt-content-blocker brlbs-cmpnt-with-individual-styles\" data-borlabs-cookie-content-blocker-id=\"default\" data-borlabs-cookie-content=\"PGlmcmFtZSB0aXRsZT0iRWluZ2ViZXR0ZXRlciBCZWl0cmFnIiBzcmM9Imh0dHBzOi8vd3d3LmxpbmtlZGluLmNvbS9lbWJlZC9mZWVkL3VwZGF0ZS91cm46bGk6dWdjUG9zdDo2NTg5ODY5NzI5MTY1Mzg5ODI0P2NvbXBhY3Q9MSIgd2lkdGg9IjUwNCIgaGVpZ2h0PSIyODQiIGZyYW1lYm9yZGVyPSIwIiBhbGxvd2Z1bGxzY3JlZW49ImFsbG93ZnVsbHNjcmVlbiIgZGF0YS1tY2UtZnJhZ21lbnQ9IjEiPjwvaWZyYW1lPg==\">\n<div class=\"brlbs-cmpnt-cb-preset-a\">\n<p class=\"brlbs-cmpnt-cb-description\">You are currently viewing a placeholder content from <strong>Default<\/strong>. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.<\/p>\n<div class=\"brlbs-cmpnt-cb-buttons\"> <a class=\"brlbs-cmpnt-cb-btn\" href=\"#\" data-borlabs-cookie-unblock role=\"button\">Unblock content<\/a> <a class=\"brlbs-cmpnt-cb-btn\" href=\"#\" data-borlabs-cookie-accept-service role=\"button\" style=\"display: none\">Accept required service and unblock content<\/a> <\/div>\n<p> <a class=\"brlbs-cmpnt-cb-provider-toggle\" href=\"#\" data-borlabs-cookie-show-provider-information role=\"button\">More Information<\/a> <\/div>\n<\/div>\n[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;grid&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;center&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; z_index=&#8221;&#8221;][vc_column width=&#8221;1\/2&#8243; offset=&#8221;vc_hidden-lg vc_hidden-md&#8221;][vc_column_text] <\/p>\n<div class=\"brlbs-cmpnt-container brlbs-cmpnt-content-blocker brlbs-cmpnt-with-individual-styles\" data-borlabs-cookie-content-blocker-id=\"default\" data-borlabs-cookie-content=\"PGlmcmFtZSB0aXRsZT0iRWluZ2ViZXR0ZXRlciBCZWl0cmFnIiBzcmM9Imh0dHBzOi8vd3d3LmxpbmtlZGluLmNvbS9lbWJlZC9mZWVkL3VwZGF0ZS91cm46bGk6dWdjUG9zdDo2ODU5NzU0MjE1OTM0MzI0NzM2P2NvbXBhY3Q9MSIgd2lkdGg9IjMwNCIgaGVpZ2h0PSIyODQiIGZyYW1lYm9yZGVyPSIwIiBhbGxvd2Z1bGxzY3JlZW49ImFsbG93ZnVsbHNjcmVlbiIgZGF0YS1tY2UtZnJhZ21lbnQ9IjEiPjwvaWZyYW1lPg==\">\n<div class=\"brlbs-cmpnt-cb-preset-a\">\n<p class=\"brlbs-cmpnt-cb-description\">You are currently viewing a placeholder content from <strong>Default<\/strong>. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.<\/p>\n<div class=\"brlbs-cmpnt-cb-buttons\"> <a class=\"brlbs-cmpnt-cb-btn\" href=\"#\" data-borlabs-cookie-unblock role=\"button\">Unblock content<\/a> <a class=\"brlbs-cmpnt-cb-btn\" href=\"#\" data-borlabs-cookie-accept-service role=\"button\" style=\"display: none\">Accept required service and unblock content<\/a> <\/div>\n<p> <a class=\"brlbs-cmpnt-cb-provider-toggle\" href=\"#\" data-borlabs-cookie-show-provider-information role=\"button\">More Information<\/a> <\/div>\n<\/div>\n[\/vc_column_text][\/vc_column][vc_column width=&#8221;1\/2&#8243; offset=&#8221;vc_hidden-lg vc_hidden-md&#8221;][vc_column_text] <\/p>\n<div class=\"brlbs-cmpnt-container brlbs-cmpnt-content-blocker brlbs-cmpnt-with-individual-styles\" data-borlabs-cookie-content-blocker-id=\"default\" data-borlabs-cookie-content=\"PGlmcmFtZSB0aXRsZT0iRWluZ2ViZXR0ZXRlciBCZWl0cmFnIiBzcmM9Imh0dHBzOi8vd3d3LmxpbmtlZGluLmNvbS9lbWJlZC9mZWVkL3VwZGF0ZS91cm46bGk6dWdjUG9zdDo2NTg5ODY5NzI5MTY1Mzg5ODI0P2NvbXBhY3Q9MSIgd2lkdGg9IjMwNCIgaGVpZ2h0PSIyODQiIGZyYW1lYm9yZGVyPSIwIiBhbGxvd2Z1bGxzY3JlZW49ImFsbG93ZnVsbHNjcmVlbiIgZGF0YS1tY2UtZnJhZ21lbnQ9IjEiPjwvaWZyYW1lPg==\">\n<div class=\"brlbs-cmpnt-cb-preset-a\">\n<p class=\"brlbs-cmpnt-cb-description\">You are currently viewing a placeholder content from <strong>Default<\/strong>. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.<\/p>\n<div class=\"brlbs-cmpnt-cb-buttons\"> <a class=\"brlbs-cmpnt-cb-btn\" href=\"#\" data-borlabs-cookie-unblock role=\"button\">Unblock content<\/a> <a class=\"brlbs-cmpnt-cb-btn\" href=\"#\" data-borlabs-cookie-accept-service role=\"button\" style=\"display: none\">Accept required service and unblock content<\/a> <\/div>\n<p> <a class=\"brlbs-cmpnt-cb-provider-toggle\" href=\"#\" data-borlabs-cookie-show-provider-information role=\"button\">More Information<\/a> <\/div>\n<\/div>\n[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;center&#8221; background_image_as_pattern=&#8221;without_pattern&#8221; z_index=&#8221;&#8221;][vc_column width=&#8221;1\/2&#8243;][vc_empty_space height=&#8221;30&#8243;][vc_column_text]\n<blockquote class=\"instagram-media\" style=\"background: #FFF; border: 0; border-radius: 3px; box-shadow: 0 0 1px 0 rgba(0,0,0,0.5),0 1px 10px 0 rgba(0,0,0,0.15); margin: 1px; max-width: 540px; min-width: 326px; padding: 0; width: calc(100% - 2px);\" data-instgrm-permalink=\"https:\/\/www.instagram.com\/p\/CnUD5tdD4-f\/?utm_source=ig_embed&amp;utm_campaign=loading\" data-instgrm-version=\"14\">\n<div style=\"padding: 16px;\">\n<p>&nbsp;<\/p>\n<div style=\"display: flex; flex-direction: row; align-items: center;\">\n<div style=\"background-color: #f4f4f4; border-radius: 50%; flex-grow: 0; height: 40px; margin-right: 14px; width: 40px;\"><\/div>\n<div style=\"display: flex; flex-direction: column; flex-grow: 1; justify-content: center;\">\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; margin-bottom: 6px; width: 100px;\"><\/div>\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; width: 60px;\"><\/div>\n<\/div>\n<\/div>\n<div style=\"padding: 19% 0;\"><\/div>\n<div style=\"display: block; height: 50px; margin: 0 auto 12px; width: 50px;\"><\/div>\n<div style=\"padding-top: 8px;\">\n<div style=\"color: #3897f0; font-family: Arial,sans-serif; font-size: 14px; font-style: normal; font-weight: 550; line-height: 18px;\">Sieh dir diesen Beitrag auf Instagram an<\/div>\n<\/div>\n<div style=\"padding: 12.5% 0;\"><\/div>\n<div style=\"display: flex; flex-direction: row; margin-bottom: 14px; align-items: center;\">\n<div>\n<div style=\"background-color: #f4f4f4; border-radius: 50%; height: 12.5px; width: 12.5px; transform: translateX(0px) translateY(7px);\"><\/div>\n<div style=\"background-color: #f4f4f4; height: 12.5px; transform: rotate(-45deg) translateX(3px) translateY(1px); width: 12.5px; flex-grow: 0; margin-right: 14px; margin-left: 2px;\"><\/div>\n<div style=\"background-color: #f4f4f4; border-radius: 50%; height: 12.5px; width: 12.5px; transform: translateX(9px) translateY(-18px);\"><\/div>\n<\/div>\n<div style=\"margin-left: 8px;\">\n<div style=\"background-color: #f4f4f4; border-radius: 50%; flex-grow: 0; height: 20px; width: 20px;\"><\/div>\n<div style=\"width: 0; height: 0; border-top: 2px solid transparent; border-left: 6px solid #f4f4f4; border-bottom: 2px solid transparent; transform: translateX(16px) translateY(-4px) rotate(30deg);\"><\/div>\n<\/div>\n<div style=\"margin-left: auto;\">\n<div style=\"width: 0px; border-top: 8px solid #F4F4F4; border-right: 8px solid transparent; transform: translateY(16px);\"><\/div>\n<div style=\"background-color: #f4f4f4; flex-grow: 0; height: 12px; width: 16px; transform: translateY(-4px);\"><\/div>\n<div style=\"width: 0; height: 0; border-top: 8px solid #F4F4F4; border-left: 8px solid transparent; transform: translateY(-4px) translateX(8px);\"><\/div>\n<\/div>\n<\/div>\n<div style=\"display: flex; flex-direction: column; flex-grow: 1; justify-content: center; margin-bottom: 24px;\">\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; margin-bottom: 6px; width: 224px;\"><\/div>\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; width: 144px;\"><\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p style=\"color: #c9c8cd; font-family: Arial,sans-serif; font-size: 14px; line-height: 17px; margin-bottom: 0; margin-top: 8px; overflow: hidden; padding: 8px 0 7px; text-align: center; text-overflow: ellipsis; white-space: nowrap;\"><a style=\"color: #c9c8cd; font-family: Arial,sans-serif; font-size: 14px; font-style: normal; font-weight: normal; line-height: 17px; text-decoration: none;\" href=\"https:\/\/www.instagram.com\/p\/CnUD5tdD4-f\/?utm_source=ig_embed&amp;utm_campaign=loading\" target=\"_blank\" rel=\"noopener\">Ein Beitrag geteilt von TEAL Technology Consulting (@tealconsulting)<\/a><\/p>\n<\/div>\n<\/blockquote>\n<p><script async src=\"\/\/www.instagram.com\/embed.js\"><\/script>[\/vc_column_text][\/vc_column][vc_column width=&#8221;1\/2&#8243;][vc_empty_space height=&#8221;30&#8243;][vc_column_text]\n<blockquote class=\"instagram-media\" style=\"background: #FFF; border: 0; border-radius: 3px; box-shadow: 0 0 1px 0 rgba(0,0,0,0.5),0 1px 10px 0 rgba(0,0,0,0.15); margin: 1px; max-width: 540px; min-width: 326px; padding: 0; width: calc(100% - 2px);\" data-instgrm-permalink=\"https:\/\/www.instagram.com\/p\/CnO1NpTjDXO\/?utm_source=ig_embed&amp;utm_campaign=loading\" data-instgrm-version=\"14\">\n<div style=\"padding: 16px;\">\n<p>&nbsp;<\/p>\n<div style=\"display: flex; flex-direction: row; align-items: center;\">\n<div style=\"background-color: #f4f4f4; border-radius: 50%; flex-grow: 0; height: 40px; margin-right: 14px; width: 40px;\"><\/div>\n<div style=\"display: flex; flex-direction: column; flex-grow: 1; justify-content: center;\">\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; margin-bottom: 6px; width: 100px;\"><\/div>\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; width: 60px;\"><\/div>\n<\/div>\n<\/div>\n<div style=\"padding: 19% 0;\"><\/div>\n<div style=\"display: block; height: 50px; margin: 0 auto 12px; width: 50px;\"><\/div>\n<div style=\"padding-top: 8px;\">\n<div style=\"color: #3897f0; font-family: Arial,sans-serif; font-size: 14px; font-style: normal; font-weight: 550; line-height: 18px;\">Sieh dir diesen Beitrag auf Instagram an<\/div>\n<\/div>\n<div style=\"padding: 12.5% 0;\"><\/div>\n<div style=\"display: flex; flex-direction: row; margin-bottom: 14px; align-items: center;\">\n<div>\n<div style=\"background-color: #f4f4f4; border-radius: 50%; height: 12.5px; width: 12.5px; transform: translateX(0px) translateY(7px);\"><\/div>\n<div style=\"background-color: #f4f4f4; height: 12.5px; transform: rotate(-45deg) translateX(3px) translateY(1px); width: 12.5px; flex-grow: 0; margin-right: 14px; margin-left: 2px;\"><\/div>\n<div style=\"background-color: #f4f4f4; border-radius: 50%; height: 12.5px; width: 12.5px; transform: translateX(9px) translateY(-18px);\"><\/div>\n<\/div>\n<div style=\"margin-left: 8px;\">\n<div style=\"background-color: #f4f4f4; border-radius: 50%; flex-grow: 0; height: 20px; width: 20px;\"><\/div>\n<div style=\"width: 0; height: 0; border-top: 2px solid transparent; border-left: 6px solid #f4f4f4; border-bottom: 2px solid transparent; transform: translateX(16px) translateY(-4px) rotate(30deg);\"><\/div>\n<\/div>\n<div style=\"margin-left: auto;\">\n<div style=\"width: 0px; border-top: 8px solid #F4F4F4; border-right: 8px solid transparent; transform: translateY(16px);\"><\/div>\n<div style=\"background-color: #f4f4f4; flex-grow: 0; height: 12px; width: 16px; transform: translateY(-4px);\"><\/div>\n<div style=\"width: 0; height: 0; border-top: 8px solid #F4F4F4; border-left: 8px solid transparent; transform: translateY(-4px) translateX(8px);\"><\/div>\n<\/div>\n<\/div>\n<div style=\"display: flex; flex-direction: column; flex-grow: 1; justify-content: center; margin-bottom: 24px;\">\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; margin-bottom: 6px; width: 224px;\"><\/div>\n<div style=\"background-color: #f4f4f4; border-radius: 4px; flex-grow: 0; height: 14px; width: 144px;\"><\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p style=\"color: #c9c8cd; font-family: Arial,sans-serif; font-size: 14px; line-height: 17px; margin-bottom: 0; margin-top: 8px; overflow: hidden; padding: 8px 0 7px; text-align: center; text-overflow: ellipsis; white-space: nowrap;\"><a style=\"color: #c9c8cd; font-family: Arial,sans-serif; font-size: 14px; font-style: normal; font-weight: normal; line-height: 17px; text-decoration: none;\" href=\"https:\/\/www.instagram.com\/p\/CnO1NpTjDXO\/?utm_source=ig_embed&amp;utm_campaign=loading\" target=\"_blank\" rel=\"noopener\">Ein Beitrag geteilt von TEAL Technology Consulting (@tealconsulting)<\/a><\/p>\n<\/div>\n<\/blockquote>\n<p><script async src=\"\/\/www.instagram.com\/embed.js\"><\/script>[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;30&#8243;][vc_column_text]\n<h4>LATEST POSTS<\/h4>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;]\n<div class='latest_post_holder boxes three_columns one_row' >\n    <ul>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/09\/02\/tiering-isnt-dead\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h4 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/09\/02\/tiering-isnt-dead\/\">Microsoft is backtracking: Tiering isn&#8217;t dead\u2014it&#8217;s essential for survival<\/a><\/h4>\n                            <p class=\"excerpt\">Microsoft releases an Active Directory Tier Model on GitHub. To many, this sounds like just another tool. For us, it\u2019s official proof of something we\u2019ve been saying for years: if you don\u2019t strictly isolate ...<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">02 September, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/08\/06\/microsoft-sms-mfa-obsolete\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2025\/10\/blog_header_microsoft-windows.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h4 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/08\/06\/microsoft-sms-mfa-obsolete\/\">Microsoft pulls the plug: why SMS MFA is now finally obsolete<\/a><\/h4>\n                            <p class=\"excerpt\">Starting September 1, 2026, passkeys will gradually become the default authentication method in Microsoft Entra ID. At the same time, Microsoft has announced that it will discontinue native support for SMS and voice MFA....<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">06 August, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/07\/01\/one-click-desaster-in-microsoft-365-copilot\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-539x303.png\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-539x303.png 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-300x169.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-1024x575.png 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-768x432.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-1536x863.png 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot-700x393.png 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/06\/header_blog_teal_copilot.png 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h4 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/07\/01\/one-click-desaster-in-microsoft-365-copilot\/\">One-Click Disaster in Microsoft 365 Copilot: When AI becomes a hacker&#8217;s best friend<\/a><\/h4>\n                            <p class=\"excerpt\">AI agents like Microsoft 365 Copilot are revolutionizing our daily work and promise unprecedented productivity. But what happens if this very smart assistant system quietly turns into the ultimate spy? ...<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">01 July, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n        <\/ul>\n<\/div>[\/vc_column][\/vc_row]\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Last month was the first time Teal was a speaker at the Troopers 23 Security Conference in Heidelberg, Germany. In this blog post, we would like to share the topic we presented with a wider audience<\/p>\n","protected":false},"author":14,"featured_media":7728,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[14],"tags":[],"class_list":["post-7729","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-further-topics-en"],"_links":{"self":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/7729","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/comments?post=7729"}],"version-history":[{"count":5,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/7729\/revisions"}],"predecessor-version":[{"id":7771,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/7729\/revisions\/7771"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media\/7728"}],"wp:attachment":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media?parent=7729"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/categories?post=7729"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/tags?post=7729"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}