{"id":4054,"date":"2025-05-19T10:03:27","date_gmt":"2025-05-19T10:03:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/19\/abusing-dmsa-with-advanced-active-directory-persistence-techniques\/"},"modified":"2025-05-19T10:03:27","modified_gmt":"2025-05-19T10:03:27","slug":"abusing-dmsa-with-advanced-active-directory-persistence-techniques","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/19\/abusing-dmsa-with-advanced-active-directory-persistence-techniques\/","title":{"rendered":"Abusing dMSA with Advanced Active Directory Persistence Techniques\u00a0"},"content":{"rendered":"<p>    Abusing dMSA with Advanced Active Directory Persistence Techniques\u00a0<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Delegated Managed Service Accounts (dMSAs), introduced in Windows Server 2025, represent Microsoft\u2019s latest innovation in secure service account management.\u00a0<\/p>\n<p>While designed to enhance security by preventing traditional credential theft attacks like Kerberoasting, security researchers have uncovered potential abuse vectors that could allow attackers to establish persistent access in <a href=\"https:\/\/cybersecuritynews.com\/windows-remote-management-leveraged\/\" target=\"_blank\" rel=\"noreferrer noopener\">Active Directory<\/a> environments.\u00a0<\/p>\n<p>dMSAs were created to solve long-standing problems with traditional service accounts. Unlike standard accounts that require manual password management, dMSAs provide automatic credential management and link authentication directly to machine identities.<\/p>\n<p>According to Microsoft documentation, \u201cdMSA is a more secure and manageable approach to service account management compared to traditional service accounts\u201d.<\/p>\n<p>The technology allows administrators to migrate from conventional <a href=\"https:\/\/cybersecuritynews.com\/cloud-attacks-raises-by-five-times\/\" target=\"_blank\" rel=\"noreferrer noopener\">service accounts<\/a> while disabling the original account\u2019s password authentication, redirecting all requests through the Local Security Authority (LSA) using the new dMSA mechanism.\u00a0<\/p>\n<p>This feature was specifically designed to eliminate credential theft risks.<\/p>\n<h2 class=\"wp-block-heading\"><strong>The Persistence Vector<\/strong><\/h2>\n<p>According to Matan Bahar, despite enhanced security controls, dMSAs can potentially be abused by attackers who have temporarily gained elevated privileges. The attack targets the Access Control Lists (ACLs) of the dMSA objects themselves.<\/p>\n<p>The key vulnerability lies in the \u201cManaged Service Accounts\u201d container and its permission inheritance structure.\u00a0<\/p>\n<p>An attacker with domain administrator access, even temporarily, can modify ACLs to maintain access to dMSA accounts after their privileged access is revoked.<\/p>\n<p>The attack begins by gaining \u201cGenericAll\u201d permissions on the Managed Service Accounts container:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcUPTl8UGnUGiR9ZqU_-TVINGANJ--09qBGXkZ6Bqzh7NdT0KJGMe9bEa3U0ZZJESSbtv6S8Z6kEq-8oAgQevMaekPsXHP5_3ey_GkYvv56A3KSQcKqQEDQGQgFo_NDKKg6ljMaNg?key=pt90noQEvP8R8ZbT2mLR7Q\" alt=\"\"><\/figure>\n<\/div>\n<p>While having \u201cGenericAll\u201d permissions on the container doesn\u2019t automatically grant access to child objects, attackers can force inheritance down to all dMSA objects:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXeQC7g1KXDZhJAp-tx5SHuVqtigtT1oqXU9TqEULskZrOwgVtC-cF9-6MEmLp9dnm8_r1GXCPpehDsW12VWCxbQMhqgTuZztqnQ__gXMqNwB-iFQyY6gBc-pf5QU0X8_-HLw-dpTw?key=pt90noQEvP8R8ZbT2mLR7Q\" alt=\"\"><\/figure>\n<\/div>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdHZGPfJbFoQIB_ubD6fsTdnYm5q0naNQwGShYeRGW1cJCXWfVMfxP8DA86YWoHCgYPQ1CQynteLKz-PJX_VnIC_mynHbEfEeUWCu-_lQsKZ7X1uWRNqR5x8bOR6889a5m9NyWDUw?key=pt90noQEvP8R8ZbT2mLR7Q\" alt=\"\"><\/figure>\n<\/div>\n<p>These commands establish persistent control over all existing and future dMSA objects. The attacker can then:<\/p>\n<ul class=\"wp-block-list\">\n<li>Change ownership of dMSA objects.<\/li>\n<li>Create new dMSA accounts under their control.<\/li>\n<li>Modify the PrincipalsAllowedToRetrieveManagedPassword property to include their compromised accounts.<\/li>\n<\/ul>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdxhYp6UFIZyV6DbIUl6mKDl5d8-rMKSdjrYmAjEIvndZ2APC_30uNqkPntktK5xV8zR5WajW6XFvwzg4Ksois5BtqgJqTTdKv1FTPN6VLodZxvfu22Y_ax1GKYv_Oix29zzTLbnA?key=pt90noQEvP8R8ZbT2mLR7Q\" alt=\"\"><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Mitigation<\/strong><\/h2>\n<p>Organizations deploying <a href=\"https:\/\/cybersecuritynews.com\/windows-server-2025-hotpatching\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Server 2025<\/a> should implement these protections:<\/p>\n<ul class=\"wp-block-list\">\n<li>Closely monitor modifications to the \u201cManaged Service Accounts\u201d container ACLs<\/li>\n<li>Enable the Group Policy setting: \u201cComputer ConfigurationAdministrative TemplatesSystemKerberosEnable Delegated Managed Service Account logons\u201d only on authorized systems<\/li>\n<\/ul>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXdW-LJbZouUdCo9xZcFKyuwMuZnf2nrW4OMkzoc48qNtZnTywss_iqPvjdpw0Mvq9kGriydYL-tpKGxGpnPxSHpOAFcfmf21qEos-H0OPT9CW5JbXs8x6AYCfrwI8ldp-7fVJ0Iqg?key=pt90noQEvP8R8ZbT2mLR7Q\" alt=\"\"><\/figure>\n<\/div>\n<ul class=\"wp-block-list\">\n<li>Monitor for Event ID 4662, which indicates \u201cWrite\u201d access to dMSA objects.<\/li>\n<li>Implement least privilege access to Active Directory administrative groups.<\/li>\n<li>Regularly audit ACL changes on critical containers using tools like PingCastle or BloodHound.<\/li>\n<\/ul>\n<p>While dMSAs significantly improve service account security over traditional accounts, organizations must remain vigilant about potential abuse vectors.\u00a0<\/p>\n<p>According to the <a href=\"https:\/\/medium.com\/@matanb707\/advanced-active-directory-persistence-techniques-can-dmsa-be-abused-32d690d09e5d\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Report<\/a>, the security improvements offered by dMSAs still outweigh the risks, particularly when proper monitoring and access controls are implemented.<\/p>\n<p>As Microsoft continues to develop Windows Server 2025, additional security controls around dMSA management will likely emerge to address these newly discovered persistence techniques.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Vulnerability Attack Simulation on How Hackers Rapidly Probe Websites for Entry Points \u2013 <a href=\"https:\/\/webinars.indusface.com\/15-minute-vulnerability-attack-simulation-insights-to-fortify-edge\/register?utm_source=gbhackers-blog-cta&amp;utm_campaign=2025-may-webinar-vulnerability&amp;utm_medium=referral\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Free Webinar<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/abusing-dmsa-active-directory\/\">Abusing dMSA with Advanced Active Directory Persistence Techniques\u00a0<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/abusing-dmsa-active-directory\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Abusing dMSA with Advanced Active Directory Persistence Techniques\u00a0 Delegated Managed Service Accounts (dMSAs), introduced in Windows Server 2025, represent Microsoft\u2019s latest innovation in secure service account management.\u00a0 While designed to enhance security by preventing traditional credential theft attacks like Kerberoasting, security researchers have uncovered potential abuse vectors that could allow attackers to establish persistent access [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,158,395],"tags":[130],"class_list":["post-4054","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-microsoft","category-windows","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4054"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4054"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4054\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}