Join our Newsletter — 33% off our NHI Course

AWS Managed Active Directory: why default machine joins still matter

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Default machine-joining behaviour in AWS Managed Active Directory can let non-privileged users create computer accounts and set up Resource-Based Constrained Delegation abuse, despite AWS restrictions on domain controller access, according to Permiso Security. The core problem is that shared-responsibility boundaries and default AD assumptions still leave a machine-account path open to escalation.

Editorial analysis by NHI Mgmt Group, based on content published by Permiso Security: “An Arrow to the Heel: Abusing Default Machine Joining to Domain Permissions to Attack AWS Managed Active Directory”.

Key questions

Q: What breaks when default machine joins are left open in AWS Managed Active Directory?

A: Default machine joins let non-privileged users create computer accounts, which turns a routine domain function into an escalation path.

Q: Why do machine-account creation rights increase delegation risk in managed Active Directory?

A: Because the machine object is not the end of the attack, it is the platform for abuse.

Q: What are the signs that AWS Managed Active Directory machine creation is being abused?

A: Look for computer-account creation by identities that are not the domain controller machine account, especially when the event appears in CloudWatch rather than from normal administrative activity.

Practitioner guidance

  • Restrict workstation-join membership Move AWS Delegated Add Workstations to the Domain away from broad Domain Users membership and limit it to a tightly controlled administrative group.
  • Monitor machine creation events in CloudWatch Alert on Event ID 4741 and flag any machine account creation performed by a non-controller identity or a non-administrative identity.
  • Review computer-object delegation rights Audit msDS-AllowedToActOnBehalfOfOtherIdentity and the ACLs that permit GenericWrite, WriteOwner, or WriteDACL on computer objects.

Bottom line: AWS Managed Active Directory still exposes an AD attack pattern where default machine creation can become an escalation path.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 11 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Default machine joining is a privileged identity event, not an administrative convenience. AWS Managed Active Directory keeps the old AD assumption that the right to add a workstation is low risk. That assumption fails when machine creation becomes the first step in a delegation attack. Practitioners should treat join permissions as part of the identity governance surface, not as a desktop-management exception.

A question worth separating out:

Q: Should organisations rely on AWS defaults for workstation join permissions?

A: No. The default join model can preserve an attack path that was already risky on-prem and make it easier to exploit in a managed directory. Organisations should decide explicitly which identities may create machines, how those actions are logged, and which computer objects are allowed to delegate.

👉 Read our full editorial: AWS Managed Active Directory machine creation enables RBCD abuse


This post was modified 11 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.