Local administrator accounts on domain systems must not share the same password.

From Active Directory Domain Security Technical Implementation Guide (STIG)

Part of Unique Passwords for all Local Administrator Accounts

Associated with: CCI-001941

SV-47844r4_rule Local administrator accounts on domain systems must not share the same password.

Vulnerability discussion

Local administrator accounts on domain systems must use unique passwords. In the event a domain system is compromised, sharing the same password for local administrator accounts on domain systems will allow an attacker to move laterally and compromise multiple domain systems.

Check content

Verify local administrator accounts on domain systems are using unique passwords. If local administrator accounts on domain systems are sharing a password, this is a finding. Microsoft's Local Administrator Password Solution (LAPS) provides an automated solution for maintaining and regularly changing a local administrator password for domain-joined systems. LAPS can manage a single local administrator account. The default is the built-in administrator account however it can be configured to manage an administrator account of a different name. If additional local administrator accounts exist across systems, the organization must have a process to require unique passwords on each system for the additional accounts. Other automated solutions that provide this capability may also be used. If LAPS has been installed and enabled in the domain, the following PowerShell query will return a list of systems that do not have a local administrator password managed by LAPS. (The LAPS PowerShell module requires PowerShell 2.0 or higher and .NET Framework 4.0.) Open "Windows PowerShell". If the LAPS PowerShell module has not been previously imported, execute the following first: "Import-Module AdmPwd.ps". Execute "Get-AdmPwdPassword -ComputerName * | Where-object {$_.password -eq $null}" If any systems are listed, this is a finding. Ignore computers with "OU=Domain Controllers" in the DistinguishedName field.

Fix text

Set unique passwords for all local administrator accounts on domain systems. Microsoft's Local Administrator Password Solution (LAPS) provides an automated solution for maintaining and regularly changing a local administrator password for domain-joined systems. If additional local administrator accounts exist across systems, the organization must have a process to require unique passwords on each system for the additional accounts. Other automated solutions that provide this capability may also be used. See Microsoft Security Advisory 3062591 for additional information and download of LAPS. https://technet.microsoft.com/en-us/library/security/3062591.aspx

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer