Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Backup Operators in Active Directory: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12518
Topic starter  

TL;DR: Backup Operators can read and overwrite protected files, copy ntds.dit through shadow copies, and extract domain secrets without Domain Admin rights, according to Semperis. The governance problem is that local backup privileges become domain-wide exposure when tiering, logon restrictions, and file-level monitoring are weak.

NHIMG editorial — based on content published by Semperis: Backup Operators rights and why they create a domain problem fast

Questions worth separating out

Q: What breaks when Backup Operators is left with standing membership?

A: Standing membership turns a backup role into a persistent privilege surface.

Q: Why do Backup Operators privileges increase domain compromise risk?

A: Because on a domain controller the group can reach the files that hold directory secrets, not just perform routine backup tasks.

Q: How do security teams know whether backup rights are being abused?

A: Look for a privilege assignment event, followed by snapshot or copy tooling, followed by reads against protected files or shadow-copy paths.

Practitioner guidance

  • Keep Backup Operators empty by default Remove standing membership wherever possible and require explicit exception approval for any account that needs backup-related rights.
  • Restrict backup-capable accounts to specific servers Block interactive use on domain controllers and deny local and remote desktop logon where the role does not truly require it.
  • Audit protected-file reads and snapshot tooling Correlate 4672, 4688, 4663, and any VSS-related process telemetry around ntds.dit, the SYSTEM hive, SAM, and backup repositories.

What's in the full article

Semperis' full article covers the operational detail this post intentionally leaves for the source:

  • Step-by-step audit checks for SeBackupPrivilege abuse on domain controllers and member servers.
  • Specific Windows event combinations for detecting shadow copy activity and protected-file reads.
  • Process names and command-line patterns that help separate legitimate backup work from abuse.
  • Practical guidance for tiering, emptying the group, and constraining backup identities to approved systems.

👉 Read Semperis' analysis of Backup Operators rights and domain compromise risk →

Backup Operators in Active Directory: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12102
 

Backup privilege is a Tier 0 governance issue, not a helper role. The article makes clear that SeBackupPrivilege and SeRestorePrivilege can expose the same crown-jewel material defenders associate with Domain Admin compromise. That means the governance assumption of “local rights are local impact” fails on domain controllers and other sensitive servers. Practitioners should classify backup-capable identities by blast radius, not by group name.

A few things that frame the scale:

  • Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks, according to The 2024 ESG Report: Managing Non-Human Identities.
  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, including 46% confirmed and 26% suspected.

A question worth separating out:

Q: Who is accountable when backup privileges expose domain secrets?

A: Accountability usually sits with the identity owner, the server owner, and the team that approved the exception. Backup rights must be reviewed like Tier 0 access because they can reach the same sensitive material as more obvious admin roles. Governance fails when no one owns the expiry, review, and logon constraints for the account.

👉 Read our full editorial: Backup Operators expose a fast path to domain compromise



   
ReplyQuote
Share: