Fine-Grained Password Policies
Fine-Grained Password Policies let AD apply different password requirements to different accounts — stricter for admins, relaxed for service accounts. Finding accounts with weaker PSOs gives you better odds at password spraying. Misconfigured PSOs that apply to large groups can weaken entire populations of accounts. This covers PSO enumeration and the full abuse chain.
Members Only Content
This article is exclusively available to registered members of LazyHackers. Login or subscribe to read.