Shared Local Administrator Password
Typical used in Deployment Solutions
Easy for admins to login to various servers/machines when problem arises
Attackers can get hash on one machine and use it on all other machines
Shared Administrator Password
Map the Local Network
Spray Username and Password across the Network
Dump the SAM database for one specific host
Access the Client using the hash found in previous step
Countermeasures
One easy way of changing this is to use Local Administrator Password Solution (LAPS) from Microsoft.
Change who is allowed to login over the network.
LAPS and Preventing over the network login with local accounts
In The Domain Controller Machine
Visit: https://aka.ms/laps
Download: LAPS.x64.msi
Installation Steps
Select AdmPwd GPO Extension as Entire feature will be unavailable
Select Management Tools as Entire feature will be installed on local hard drive
Select Fat client UI as Entire feature will be unavailable
After Installation of LAPS
Open Powershell
Import the Module we have just installed
Last updated