TL;DR: Default machine-joining behaviour in AWS Managed Active Directory can let non-privileged users create computer accounts and set up Resource-Based Constrained Delegation abuse, despite AWS restrictions on domain controller access, according to Permiso Security. The core problem is that shared-responsibility boundaries and default AD assumptions still leave a machine-account path open to escalation.
Editorial analysis by NHI Mgmt Group, based on content published by Permiso Security: “An Arrow to the Heel: Abusing Default Machine Joining to Domain Permissions to Attack AWS Managed Active Directory”.
Key questions
Q: What breaks when default machine joins are left open in AWS Managed Active Directory?
A: Default machine joins let non-privileged users create computer accounts, which turns a routine domain function into an escalation path.
Q: Why do machine-account creation rights increase delegation risk in managed Active Directory?
A: Because the machine object is not the end of the attack, it is the platform for abuse.
Q: What are the signs that AWS Managed Active Directory machine creation is being abused?
A: Look for computer-account creation by identities that are not the domain controller machine account, especially when the event appears in CloudWatch rather than from normal administrative activity.
Practitioner guidance
- Restrict workstation-join membership Move AWS Delegated Add Workstations to the Domain away from broad Domain Users membership and limit it to a tightly controlled administrative group.
- Monitor machine creation events in CloudWatch Alert on Event ID 4741 and flag any machine account creation performed by a non-controller identity or a non-administrative identity.
- Review computer-object delegation rights Audit msDS-AllowedToActOnBehalfOfOtherIdentity and the ACLs that permit GenericWrite, WriteOwner, or WriteDACL on computer objects.
Bottom line: AWS Managed Active Directory still exposes an AD attack pattern where default machine creation can become an escalation path.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Default machine joining is a privileged identity event, not an administrative convenience. AWS Managed Active Directory keeps the old AD assumption that the right to add a workstation is low risk. That assumption fails when machine creation becomes the first step in a delegation attack. Practitioners should treat join permissions as part of the identity governance surface, not as a desktop-management exception.
A question worth separating out:
Q: Should organisations rely on AWS defaults for workstation join permissions?
A: No. The default join model can preserve an attack path that was already risky on-prem and make it easier to exploit in a managed directory. Organisations should decide explicitly which identities may create machines, how those actions are logged, and which computer objects are allowed to delegate.
👉 Read our full editorial: AWS Managed Active Directory machine creation enables RBCD abuse