Home
Contents
CLOSE
AuthLite Interactive Documentation
Quick Start: Install and protect Domain Admins AuthLite Features Supported Tokens Installation and Upgrading Configuration Token Management How to Log In Troubleshooting
CLOSE
Fig. 1) Require 2-factor Authentication for Domain Admins
Fig. 2) Create an emergency recovery Administrator

Properly securing Domain Admin credentials is an extra challenge: any attacker who gains a foothold as a domain admin might be able to alter any restrictions that have been placed onto their account.

Securing Domain Admin accounts

Note: You should keep one Administrator account outside the control of AuthLite for emergency recovery purposes (see Fig. 2). Create and store a long random password for it and don't use that account (even for services).

Other administrative accounts

You can create additional group pairs and use the same strategy to control effective membership in other groups to which you've delegated power in the domain.

Service accounts

Services scheduled tasks are automated, and they must be able to log on without human interaction.  Therefore by necessity they store the credentials used to log themselves on.  If you have any service accounts that run as Domain Admin or other powerful group, that means any compromise of a system running that service can take over your whole domain! Run services and tasks as a lower privilege user if possible. Restrict allowed logon types and locations using group policy User Rights Assignment.

Auditing your power group membership

Through nested group membership, many organizations don't fully know which accounts have power over the domain.  In the AuthLite Admin Powershell, you can run the command Print-Users-In-Power-Groups to enumerate each powerful account in the domain, where it derives power, and some advice about mitigating risks.

Convert a user's power groups to be "AuthLite controlled"

In the AuthLite Admin Powershell, you can run the command Convert-Admin-Groups  to pull a user out of their natural power groups and add them to whatever AuthLite equivalent groups you've defined in the AuthLite User Group Pairs dialog (i.e. AuthLite-Protected Domain Admins).  You can reverse the conversion by adding "-toAuthLite $false"