Language:
Active Directory offers protection for critical objects, such as Domain Administrators, by periodically applying default access control rules to these objects. It's essential to check these default rules for consistency since they affect the security of the most important objects in Active Directory.
Permissions set on the adminSDHolder object should only allow privileged access to administrative accounts.
Reducing the Active Directory Attack Surface
Securing Active Directory Administrative Groups and Accounts
Name: Ensure SDProp Consistency
Codename: C-SDPROP-CONSISTENCY
Severity: Critical