skip to content

Privilege as a Graph

Membership is one edge among several: a write permission, ownership, a password-reset right, a delegation setting. Interviewers ask how you bound privilege that a group list can never surface.

on this pageshow

explore

questions

4

In Active Directory, why can any authenticated account read group memberships and permissions?

level: juniorimportance: must knowfreq 65%

answer

  1. the directory has to be readable
  2. clients resolve memberships and services
  3. Authenticated Users read by default
  4. the authorisation model is queryable data
  5. path computed, never probed

basics

~10 s

Active Directory is a shared authorisation database, and Authenticated Users can read most attributes by default: memberships, owners, permission entries, service principal names. Any valid account can map who controls whom without touching anything.

solid answer

~50 s

The directory has to be readable to function. Domain-joined machines, address books and clients locating services all resolve names, memberships and service principal names out of it, so the default security descriptors grant Authenticated Users read over most objects and attributes — including `member` and `memberOf`, the object owner, and the discretionary ACL on the security descriptor, which is readable with `READ_CONTROL`. The consequence for an attacker is not that read equals write. It is that the whole authorisation model is data. One ordinary account, including a machine account, can pull it and work out offline every chain of rights that ends at a privileged group. Nothing is probed, nothing fails, nothing is modified. The first privileged action taken is one already known to work, and it usually sits about two hops away through rights somebody granted on purpose.

go deeper

for a junior

Be ready to say plainly that any valid domain account can read memberships, owners and permission entries, and that this is a design property rather than a misconfiguration on one server.

for a middle

Explain which attributes carry the escalation-relevant facts and why the default access exists — clients resolving services, policy filtering, applications resolving groups — so you can argue about it without proposing to switch it off.

for a senior

Show the consequence in operational terms: the route is computed rather than probed, so there is no failed-attempt phase, and the cheapest credential in the estate buys the complete map of control relationships.

for a principal

Own the framing that the estate's authorisation model is public to everyone inside it, which means privilege design has to survive being fully known — tiering and edge hygiene, not obscurity of the directory.

## The directory is an authorisation database, not a phone book Active Directory stores every principal in the estate — users, computers, service accounts, groups — and, on each object, a security descriptor that says which principals may do what to that object. Group relationships are attributes (`member` on the group, `memberOf` as the computed back-link). Ownership is a field. Service accounts advertise where they run through `servicePrincipalName`. Relationships between domains and forests are `trustedDomain` objects. Taken together, that is the complete, authoritative statement of who can control whom across the estate. ## Why read access is granted to everyone It is not an oversight, and it is not a misconfiguration you can simply reverse. Windows and the applications on top of it read this data constantly: - a workstation locates domain controllers and services by querying the directory; - a client finds the instance of a service to authenticate to by resolving its service principal name; - address books and collaboration tools list people and their groups; - policy is filtered by group membership, so membership must be resolvable; - in-house applications routinely resolve a user's groups to make their own authorisation decisions. Because all of that is universal, the default security descriptors on directory objects grant read to `Authenticated Users`. Reading the discretionary ACL of an object specifically needs the `READ_CONTROL` access right, and that is included in the default read. Anything holding a valid domain credential qualifies — a first-week starter's account, a contractor, a kiosk, and every domain-joined computer account. ## The graph this creates Model the estate as a directed graph. Nodes are principals and objects. An edge from A to B means A holds some right that lets A take control of B: A is a member of B, A owns B, A can rewrite B's ACL, A can force B's password, A can add itself to B. Every one of those facts is readable. So the graph is not discovered by probing — it is downloaded and then computed. That is the point most people miss when they first meet this. On a filesystem you find out you can write a file by trying to write it, and the attempt either works or fails. In a directory the answer is published in advance. An attacker with one working credential computes the transitive closure — following nesting, inherited permission entries and trusts — and gets a ranked list of routes to the highest-value groups before touching a single object. ## What this changes about escalation Three things follow, and interviewers want all three: 1. **There is no noisy trial-and-error phase.** The reconnaissance is a read that is authorised by design. It changes no privilege, fails nowhere, and is the same query a joiners-movers-leavers script, a licence reconciliation job and an auditor run every week. 2. **The route is usually short and legitimate.** The shortest path is typically two hops through rights an administrator granted deliberately years ago — a help-desk delegation, an application owner given control of a group, a group nested into another group for convenience. 3. **It is available to the weakest account in the estate.** Any credential compromise, however unprivileged, buys the complete map. ## What the read does not give Be precise, because the counter-question is coming. Reading the directory hands you no password, no hash and no right you did not already hold. Credential secrets are not attributes; they never leave the domain controller's protected store. Attributes explicitly flagged confidential require a specific extended right, not the default read. So the read is a map, not a key. Its value is that the map tells you exactly which key you are already carrying and which door it opens. ## The wrong answers to avoid - *You would need administrative rights to enumerate all that.* No — Authenticated Users membership is enough, and machine accounts have it too. - *Read access is harmless because nothing changes.* Nothing changing is precisely why it is cheap; the harm is the path it reveals. - *Just remove the read.* Removing it broadly breaks sign-in, policy filtering, service location and a long tail of in-house applications. The durable fix is removing the edges the read exposes, not the read.

  • Does an attacker need any special privilege or group to run that enumeration?
    No. Membership in Authenticated Users is enough, and that is granted to every valid domain credential — a brand-new user account, a contractor, a service account with no rights anywhere. Domain-joined computer accounts are Authenticated Users too, so a compromised workstation can do the same reading without any user logging on.
  • Can you fix this by denying Authenticated Users read on the directory?
    Not broadly. Sign-in, policy filtering, service location by service principal name, address books and many in-house applications all depend on that read, and removing it estate-wide breaks them. Targeted hardening exists — marking specific attributes confidential, cleaning up legacy compatibility groups — but the real remediation is deleting the control edges the read exposes.
  • What can an ordinary authenticated account not read from the directory?
    Credential secrets, because password material is not exposed as a readable attribute at all. Attributes flagged confidential need an explicit extended right rather than the default read. Everything else that matters for escalation — memberships, owners, permission entries, service principal names, trust objects — is readable, which is why the map is complete enough to compute paths from.

Every door in the building still needs its own key, but the master key-cutting register is pinned up in the lobby where any badge holder can study it.

saying these in an interview costs you the question

  • Claims you need admin rights to enumerate the directory
  • Says read access cannot matter because nothing is modified
  • Thinks group membership is the only thing worth reading
  • Proposes removing Authenticated Users read as a simple fix
  • Believes reading permissions also reveals passwords or hashes

context

open as a page

A reviewer calls Active Directory enumeration 'read-only, not a vulnerability' — what is your rebuttal?

level: seniorimportance: must knowfreq 46%

basics

~20 s

The finding is not the read; it is the graph the read reveals. Because authorisation data is readable by design, an attacker computes a working two-hop route at zero cost, with no failed attempts and nothing modified, and then acts once.

open as a page

In Active Directory, a user in no privileged group still reaches Domain Admins — which rights explain it?

level: middleimportance: should knowfreq 52%

basics

~20 s

Membership is only one kind of edge. Ownership, WriteDacl, WriteOwner, GenericAll, write access to a group's member attribute and the force-password-reset extended right each let one principal take control of another, and inherited delegation spreads them across whole organisational units.

open as a page

After a merger adds a forest trust, why does the privilege graph change with no membership edits?

level: seniorimportance: nice to knowfreq 34%

basics

~20 s

A trust is an edge. Principals from the acquired forest become authenticated principals in yours when they authenticate across it, and any group or permission entry that references them joins the two graphs, so their weakest delegation now leads into your estate.

open as a page