Briefing

Why Changing Passwords Doesn’t End an Active Directory Breach

security
by Sponsored by Specops Software ·

Patch password reset gaps by clearing cached credentials on endpoints and invalidating active Kerberos tickets.

What to do now

Patch password reset gaps by clearing cached credentials on endpoints, invalidating active Kerberos tickets, rotating service account passwords, and forcing frequent AD–Entra sync.

Summary

Password resets are often the first response to a suspected compromise, but they do not immediately invalidate cached hashes on Windows endpoints or synchronize with Entra ID in hybrid environments. In both Active Directory (AD) and hybrid Entra ID setups, a short window remains where attackers can use cached credentials or forged Kerberos tickets to maintain access. Specops uReset can update the local cached credential store immediately on the device where the reset is performed, closing the window where the old hash remains usable. However, active Kerberos tickets remain valid after a password change, allowing attackers to continue accessing resources without re‑entering credentials. Service accounts with long‑lived passwords also present a persistent backdoor, as they are rarely reset quickly. The Entra ID sync delay can leave the old password usable for a few minutes, and resetting the KRBTGT account twice is often necessary to invalidate forged tickets. Defenders must terminate active sessions, clear Kerberos tickets, rotate service account passwords, and enforce frequent AD–Entra synchronization. Specops provides a secure self‑service password reset process that enforces end‑user ID verification to reduce reset abuse.

Key changes

  • Password resets do not immediately invalidate cached hashes on Windows endpoints.
  • Cached credentials can be used for pass‑the‑hash attacks.
  • Specops uReset updates the local cached credential store immediately on the device where the reset is performed.
  • Active Kerberos tickets remain valid after a password change, allowing continued access.
  • Service accounts with long‑lived passwords present a persistent backdoor.
  • Entra ID sync delay can leave the old password usable for a few minutes; resetting KRBTGT twice invalidates forged tickets.

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting