Improve Active Directory posture with AD-SPM ↗
Prerequisites
- ITDR add-on
- View or View/Edit RBAC permissions for Identity Runtime Security
Active Directory Security Posture Management (AD-SPM) scans your infrastructure against known misconfiguration patterns, and weak and compromised passwords, to detect security vulnerabilities and provide specific remediation guidance.
To enable AD-SPM, toggle the AD-SPM setting in the Identity profile of the agent. To see how to configure the Identity profile, see Set up Identity Profiles.
Explore AD identities
AD-SPM discovers the following on-premises identity types:
- Human identities
- Non-human identities
- Groups
- Policies
Review and manage AD posture detection rules
Monitor your organization’s detected AD misconfigurations and weak passwords in Modules → Identity Security → Detection Rules → Posture.
AD-SPM provides a comprehensive list of about 150 detection rules. Filter the Provider field for Active Directory to see the detection rules that apply to identities. Following are a few examples of these rules:
- Dangerous ACLs on AD certificate container
- Privileged user with a password that never expires
- Non-privileged users can set Server Trust Account
On this page you can do the following:
- Use the widgets to view your identity rules, identify top issues, and view impact by asset type.
- Click each rule in the table to open a side panel where you can see the rule details, remediation suggestions, and compliance controls. This panel also displays the XQL query used to generate the issue. You can customize it or copy it to use it in the XQL Query editor.
- Create a new rule. Cortex provides default rules for managing your cloud posture. To add more customized rules, click Create Rule, select Identity. For more information, see Create a custom detection rule in Cortex Cloud Identity Security.
Investigate AD misconfigurations
To review the AD misconfigurations in your organization and investigate the issues related to them, navigate to Modules → Identity Security → Identity Asset Inventory → All Identity Assets. In the On-premises Identities tab, filter the table using the following types to see the details about risky identities:
- AD Generic Principle
- AD Group
- AD Machine Account
- AD Service Account
- AD User
Filter according to the Weak/Compromised Password to see the accounts at risk for unauthorized access and credential exploitation.\
Each identity displays the number and severity of the issues triggered by the module.\
To investigate the issues do one of the following:
- Click the identity to see its side panel. From this panel, click the number of issues to open up the issues table.
- In Modules → Identity Security → Issues → Posture, select an issue.