Forum Discussion

micheleariis's avatar
micheleariis
Steel Contributor
Oct 04, 2024

Secure Score - Accounts with non-default Primary Group ID

Hi all, I am getting a report that the object (computer) on AzureADKerberos active directory does not have a correct Primary Group ID; I have checked and see no anomalies; does anyone else have this report?

 

 

 

 

  • micheleariis This is a new security posture report we've released a few days ago.
    The report contains entities with a non-default primary group id that may indicate of an attacker attempt to escalate privileges subtly, bypassing standard audits for group membership changes.
    We will raise a report if the primary group id of an account is not one of the defaults, or the primary group id is different from the group that considered as primary. If that not the case, please open a support ticket so we can investigate the issue. 

    • micheleariis's avatar
      micheleariis
      Steel Contributor

      LiorShapira thank you for your response.
      I can't understand why I am getting flagged for the AzureADKerberos account.

      • LiorShapira's avatar
        LiorShapira
        Icon for Microsoft rankMicrosoft

        micheleariis Thanks for your feedback, this account should not be included, and we are working on a fix. The recommendation will be updated in a couple of days. 

Resources