Active Directory Security dot com

Complete Coverage of Delegation, Security Audit & Compliance Reporting in Active Directory

Brought to you by former Microsoft Program Manager for Active Directory Security
REFERENCE GUIDANCE REPORTING
Reference | Top-20 D | Risks | FAQ Delegate | Verify | Assess | Audit | Report | Comply Reports Tools
| Delegating Account Mgmt | Delegating Group Mgmt | Delegating OU Mgmt | Delegating SCP Mgmt |




Delegating Service Connection Point (SCP) Management in Active Directory

ADMINISTRATIVE TASK
.
HOW TO DELEGATE THE TASK
.
SECURITY IMPLICATIONS OF TASK
(when performed with malicious intent)
1. Create a service connection
    point
Grant Create Child permissions on the parent object to create Service Connection Point objectsIntroduce a misleading service connection point and use it to mislead existing services, in effect launching a denial-of-service attack against those services.
2. Delete a service connection
    point
Grant Standard Delete permissions on the SCP object or Delete Child permissions on the parent objectDelete a service connection point being used by a service, in effect launching a denial-of-service attack against the service.
3. Change a service
    connection point's keywords
Grant Write Property permissions on the SCP object to modify the Keywords attributeModify the keywords that the associated service depends on for service location, in effect launching a denial-of-service attack against the service.
4. Change a service
    connection point's service
    DNS name
Grant Write Property permissions on the SCP object to modify the Service DNS Name attributeModify the DNS name associated with the service, in effect launching a denial-of-service attack against the service.
5. Change a service
    connection point's security
    permissions
Grant Modify Permissions permissions on the SCP objectGrant or revoke any account or group of your choice the ability to perform any of the above mentioned SCP administrative tasks on this service connection point.
Gold Finger - Microsoft-endorsed, Active Directory Resultant Access/Security Auditing/Reporting Tool
About Copyright ActiveDirSec.Com 2008 – 2011. All Rights Reserved Disclaimer
Active Directory Security Active Directory Reports Active Directory Reporting Tools Cyber Security and Global Security
Active Directory Audit Tool Active Directory Reporting Tool Active Directory Reporting Tools Active Directory Effective Permissions