Garrett
unsignedsh0rt.bsky.social
Garrett
@unsignedsh0rt.bsky.social
AdSim @ SpecterOps
November 15, 2024 at 5:42 AM
November 15, 2024 at 5:42 AM
It's not limited to just ADCLI either...ManageEngine is probably the most familiar or recognizable tool that does this. It's true microsoft fixed creating them in ADUC but hardly fixed things where third party tools are involved.
November 15, 2024 at 5:33 AM
So what's happening? The tool before would create the computer object without a password and then set it to a default after the fact. Now, that password setting is blocked and the object persists...with no password.
November 15, 2024 at 5:31 AM
But now, you get a failure as you cannot change the accounts password. However, it STILL creates the object.
November 15, 2024 at 5:29 AM
I had a hunch though that behavior might not be true for third party tools and third-party tools were arguably the biggest cause of their existence across all the enviroments I've tested over the years. An example of this is the adcli command line tool. Before it would set with a default password.
November 15, 2024 at 5:28 AM