Service accounts can become invisible administrators
Accounts created for software frequently end up with high privilege, non-expiring passwords and no owner.
Nobody logs in as them, so nobody notices them. They do not appear in leaver processes. Their passwords are old, sometimes weak, and sometimes discoverable by any authenticated user in the directory. They are among the most reliable routes to privilege in a mature environment, precisely because they are boring.
More on Windows and Active Directory
- Domain Admin is a forest-scale keyOne root under the whole forest
- Kerberos tickets are credentialsWhoever holds it, gets in
- Golden Ticket attacks target the ticket authorityThey took the press, not a ticket
- Group Policy is a fleet control planeOne dial, every desk
- LAPS reduces shared local-admin secretsOne secret, or one each
- NTLM fallback preserves older trust assumptionsThe hatch nobody bricked up
