Domain with Unsafe Backward-Compatibility Configuration

low

Description

It is possible to customize Active Directory behavior by adjusting fundamental attributes, but some of these modifications can potentially compromise security.

Solution

Remediate the security-sensitive fields of an Active Directory attribute dSHeuristics.

See Also

dSHeuristics attribute reference

Disabling the fLDAPBlockAnonOps field

Enabling the fAllowPasswordOperationsOverNonSecureConnection field (AD LDS only)

Changing the value of dwAdminSDExMask

Indicator Details

Name: Domain with Unsafe Backward-Compatibility Configuration

Codename: C-DSHEURISTICS

Severity: Low

Type: Active Directory Indicator of Exposure

MITRE ATT&CK Information: