Native Administrative Group Members

critical

Description

With regard to privileged groups in Active Directory, there are very few cases where it's necessary to add an account to default administrative groups. Membership to these groups should be scrutinized and carefully justified.

Solution

Restrict privileged administrative group membership to a minimum.

See Also

Securing Privileged Access

Indicator Details

Name: Native Administrative Group Members

Codename: C-NATIVE-ADM-GROUP-MEMBERS

Severity: Critical

MITRE ATT&CK Information:

Tactics: TA0004

Techniques: T1078