Directory replication is a privileged capability
The permission that lets a domain controller synchronise with another can be used to extract every credential in the directory.
It is a legitimate function held by legitimate systems, and if it is granted to an ordinary account it is equivalent to compromising the entire domain. Auditing who holds it is a short exercise that occasionally produces alarming answers.
More on Windows and Active Directory
- Domain Admin is a forest-scale keyOne root under the whole forest
- Kerberos tickets are credentialsWhoever holds it, gets in
- Golden Ticket attacks target the ticket authorityThey took the press, not a ticket
- Group Policy is a fleet control planeOne dial, every desk
- LAPS reduces shared local-admin secretsOne secret, or one each
- NTLM fallback preserves older trust assumptionsThe hatch nobody bricked up
