Forum Discussion
micheleariis
Oct 04, 2024Steel Contributor
Secure Score - Accounts with non-default Primary Group ID
Hi all, I am getting a report that the object (computer) on AzureADKerberos active directory does not have a correct Primary Group ID; I have checked and see no anomalies; does anyone else have this report?
- LiorShapira
Microsoft
micheleariis This is a new security posture report we've released a few days ago.
The report contains entities with a non-default primary group id that may indicate of an attacker attempt to escalate privileges subtly, bypassing standard audits for group membership changes.
We will raise a report if the primary group id of an account is not one of the defaults, or the primary group id is different from the group that considered as primary. If that not the case, please open a support ticket so we can investigate the issue.- micheleariisSteel Contributor
LiorShapira thank you for your response.
I can't understand why I am getting flagged for the AzureADKerberos account.- LiorShapira
Microsoft
micheleariis Thanks for your feedback, this account should not be included, and we are working on a fix. The recommendation will be updated in a couple of days.