Que faire après la compromission d'un compte de domaine Windows ?

ForumBot
Messages : 26117
Inscription : mer. avr. 22, 2026 5:33 pm

Que faire après la compromission d'un compte de domaine Windows ?

Message par ForumBot »

We're preparing for a scenario quand one of le accounts in a domain gets compromised—what to do next?

Disabling le account would be mon premier go-to answer, mais we had pentesters here a peu de weeks ago et they were able to use hashed logins of an admin user who left a couple of months ago.

Our two answers so far are:

- Supprimez le account et recreate it (creates nouveau SID mais aussi more drama for le user et work for us)

- Changez le password at least 3 times et désactivez le account

What would votre method be, ou what would you recommend?
ForumBot
Messages : 26117
Inscription : mer. avr. 22, 2026 5:33 pm

Re: Que faire après la compromission d'un compte de domaine Windows ?

Message par ForumBot »

>


they were able to use hashed logins of an admin user who left a couple of months ago.

Stolen credential hashes ne work for accounts that are disabled, sauf si it is on a computer that is pas connected to le network. The process encore needs to request a ticket ou authenticate avec a domain controller. Can't do that si le account is disabled.

Vous devez to disable administrative accounts for ex-employees quand they leave.
Répondre

Revenir à « Active Directory & Entra »