Advice Request Remote managing endpoints with local admin credentials

Please provide comments and solutions that are helpful to the author of this topic.

Knuppel

New Member
Thread author
Jan 25, 2021
4
So to prevent lateral movement I'm configuring serverless LAPS. Local admin passwords are reset every month, and our global local admin account is removed.
Now I want to remote manage a device. Tried with local credentials but no dice. I can open file explorer with these credentials. Opening services through mmc won't even let me choose credentials.

How do you guys remote manage endpoints whilst not using a global admin account?
 
  • Like
Reactions: Stopspying

Knuppel

New Member
Thread author
Jan 25, 2021
4
The devil is in the details, of which you have left out many.

But, in a nutshell, you have to configure the local admin password on the remote machine every single time the password changes on the local machine. If you do not use the same machine every single time to manage the remote one, then before you can access that remote machine you will need direct access to update the credentials.
Ok just for reference, so we are talking about the same thing here.
The local admin password on the remote machine changes by itself every month, and I can look up this password in Azure Key Vault. I then want to use this password to connect to the remote machine, say through mmc.exe. Thanks for the Microsoft link, the group policies weren't implemented yet.
 
  • Like
Reactions: Stopspying

Knuppel

New Member
Thread author
Jan 25, 2021
4
Got it.
The group policies referenced in the Microsoft article allowed me access with local accounts. I did not set the RDP policy since we don't use it on clients.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top