持续开启的特权访问在大多数环境中仍然是常态,根据调查,67%的组织至少授予某些角色此权限,出自 Netwrix 2026 Data and Identity Security Report。这些权限在执行相关任务之间保持激活状态,这正是特权用户监控旨在弥补的空白。
拥有 Domain Admins 成员资格的管理员在适用的 Active Directory 控制范围内拥有完全授权,无论凭据背后的人是基础设施负责人还是通过网络钓鱼获取凭据的攻击者。
成功的授权决定仅证明许可。良好意图和操作合法性需要单独的证据。监控提供这些证据,并在不减缓业务依赖的管理的情况下加强访问治理。
什么是特权用户监控?
特权用户监控是对被信任执行安全相关功能的账户所执行活动的持续收集和分析,以确保每次使用提升权限都会留下可审查的记录。NIST 将privileged user 定义为拥有授权,因此被信任执行普通用户无法执行的安全相关功能的人。
该定义中不要求凭据背后必须有人,因此拥有提升权限的服务账户、managed identities 和 automation principals 也属于相同范围。
范围超出了大多数团队起步的本地目录。无论身份在 Active Directory、云身份提供商、SaaS 管理控制台还是数据库中拥有管理权限,该身份都属于受监控的群体。
为什么特权用户账户最难追踪
授权系统回答主体是否可以执行某个操作,对于特权账户,其控制边界内的答案通常是“是”。四种机制使得这个“是”隐藏了比应有的更多内容。
有效的凭据使管理和攻击看起来相同
一旦目录授予权限,登录事件、组成员资格检查和资源访问都会成功,因为凭证有效,无论背后的人是管理员还是通过钓鱼获得凭证的攻击者。
MITRE技术T1078.002正是涵盖了对有效域账户凭据的滥用,用于初始访问、持久性、权限提升和防御规避。在Netwrix 2026 Data and Identity Security Report背后的调查中,73.78%的组织表示他们不完全相信其Active Directory没有允许权限提升的错误配置。每一个都是进入同一受信任位置的另一条路径。
正式组查询会遗漏嵌套成员
Active Directory 的 memberOf 属性会忽略嵌套的组成员身份,因此直接读取 Domain Admins 或任何其他特权组时,会遗漏通过嵌套访问的所有用户。针对该直接成员身份范围的访问审查从一开始就会认证错误的用户群体。
ACL在每个privileged group之外创建影子管理员
访问控制列表授予shadow admins敏感权限,这些账户完全位于所有privileged directory组之外。最严重的情况是拥有修改组成员权限的账户,可以将自己添加到该组。此行为是设计使然,无法通过设置禁用。
GPO 和本地管理员权限不会留下可捕获的成员资格事件
Group Policy Object (GPO) 的编辑权限,如 GenericWrite 或 WriteDacl,以及 local administrator rights 存储在计算机的本地 Security Accounts Manager (SAM) 中,赋予相同的有效权限,无需组成员资格。
服务和计划任务登录还会将账户密码作为可重用的秘密保存在本地安全机构(LSA)的磁盘上,这会导致该主机的任何被攻破都变成凭据泄露。这些操作均不会生成权限报告所依赖的4728、4732或4756成员变更事件。
特权用户监控应涵盖的内容
监控通过捕捉推动风险变化的因素来证明其成本合理性。理想的警报事件具有高未授权活动可能性和低误报率,且audit records 有时是成功攻击留下的唯一证据(CIS Control 8)。诱惑是收集所有内容,这只会产生没人阅读的队列。
Signal | Examples | Why it matters |
|---|---|---|
|
Entitlement changes |
Admin group additions, Microsoft Entra ID role assignments, organizational unit (OU) delegation, ACL changes, GPO edits |
Each one grants effective authorization or establishes persistence, covered by MITRE T1484 |
|
Authentication behavior |
Logon type shifts, unfamiliar source hosts, elevated-token logons, failed elevation attempts, off-hours access |
Valid-credential abuse carries no malicious signature and surfaces as deviation from an account's baseline |
|
Access to sensitive data |
Non-owner mailbox access, reads of regulated stores, bulk export |
Content access with no matching task maps to collection techniques such as T1114 and T1213 |
|
Security control changes |
Audit policy edits, log clearing, agent disablement, Conditional Access changes |
Tampering with controls usually signals a larger operation already in progress |
|
Account lifecycle events |
Creation, re-enablement of disabled accounts, dormancy |
Adversaries use account creation to hold access across remediation |
非所有者访问敏感数据,包括邮箱读取,映射到如MITRE T1114和T1213的收集技术,并通过Microsoft 365中的MailItemsAccessed审计操作显示。防篡改功能会显示禁用端点代理的尝试。
休眠需要一个明确的阈值,且 CISA 的过期账户对策 将该数字留给每个组织(其示例标记密码年龄为180天)。供应商账户应与离职员工同样严格管理。
CISA的Cross-Sector Cybersecurity Performance Goals 2.0于2025年12月发布,将管理服务提供商风险目标与要求在员工离职当天禁用所有账户和访问路径相结合。
Netwrix Threat Manager根据每个身份的基线评估特权和服务账户活动,当行为偏离基线时发出威胁警报。请求演示。
特权用户监控 vs. 特权会话管理 vs. 用户活动监控
三个控制项容易混淆,因为它们都涉及管理员行为,但每个控制项针对不同的单位,回答不同的问题。
Dimension | Privileged user monitoring | Privileged session management | User activity monitoring |
|---|---|---|---|
|
Scope |
The privileged identity and its entitlements |
The individual privileged session |
Every workforce user |
|
Time horizon |
Continuous, with baselines built over weeks to months |
Duration of a single connection |
|
|
Question answered |
Is this identity's behavior and entitlement set appropriate |
What happened during this session |
Could this person's activity indicate an insider threat |
|
Primary artifact |
Behavioral baseline, risk score, anomaly alerts, entitlement reports |
Session recording, keystroke log, forensic index |
Screen and keystroke content across every employee |
|
Content capture |
Optional |
Standard |
Standard |
特权会话管理 直接代理连接,隔离终端用户的凭据,因此其最深层的产物是会话录制和击键日志。这些日志捕获所有输入内容,包括密码和个人数据,因此保留期限和访问控制必须严格,调查人员仍然需要与录制内容一起的解析命令日志,因为单独为某个操作剪辑视频不可扩展。
用户活动监控将相同的内容捕获扩展到整个员工队伍,以检测内部威胁,依据NIST的UAM定义。英国ICO的员工监控指南将该级别的屏幕和按键捕获视为足够广泛的处理,需要进行数据保护影响评估。
Privileged user monitoring 默认跳过内容捕获,保持以授权为中心,清点管理员群体并审计每个身份使用的提升权限。正是这种更狭窄的关注点,使得能够在每个 privileged account 上持续运行,而不是对会话进行抽样,大多数程序最终至少运行三者中的两个。
如何构建特权用户监控程序
首先是发现,然后是减少,再是基线和检测,最后是证据保护。每个阶段都会缩小下一阶段需要覆盖的范围,这就是为什么从检测工具开始最终仍需重新构建清单的原因。
1. 发现所有特权用户
映射每个账户和授予管理权限的每项权利,而不仅仅是组成员身份:
- 域和本地管理员,通过传递性组成员身份解析,因此包括嵌套成员。
- 目录对象上的ACL授予权限和GPO编辑权限。
- 每个 endpoint 上的本地管理员组。
- 服务帐户类型,包括 group Managed Service Accounts (gMSAs)、standalone Managed Service Accounts (sMSAs)、计算机帐户和运行服务的用户帐户。
- Break-glass emergency accounts and vendor and contractor access.
- Cloud and SaaS privileged roles, from Entra ID Global Administrator and Privileged Role Administrator to the equivalent tenant-admin roles in other identity providers and business applications.
Give every entry a named owner and a stated purpose, or the inventory becomes a list nobody acts on.
2. Reduce it before monitoring it
Remove every standing account monitoring doesn't need to cover before building the next stage. Most environments carry more elevated rights than the work requires, and the same Netwrix survey found 68% of organizations don't enforce strict least privilege.
Move accounts to just-in-time elevation at minimum, temporary permissions that lapse on expiry, or further to zero standing privilege, where no account holds elevated rights between approved sessions and ephemeral accounts exist only for the duration of the work.
3. Baseline normal administration by role
Feed authentication attempts, access requests, privilege changes, and directory modifications into an identity threat detection and response platform, and let it build a profile for each identity and its peer group instead of judging one connection at a time.
Behavioral analytics and signal correlation catch what single-event rules miss, the same principle behind Microsoft Defender for Identity's own detections. Expect weaker signal for the first few weeks on a new administrator or freshly provisioned service account, since baseline quality improves as activity accumulates.
4. Track entitlement drift between reviews
Compare current entitlements against the last certified state between review cycles, not just during them. Periodic certifications only capture a moment, so a grant added the week after reviewers close a campaign can go unchecked until the next one. Flag any grant that appeared since the last certification, so the annual review confirms what monitoring already caught instead of being the only check that ever runs.
5. Alert on change, correlate on pattern
Alert immediately on the small set of events that are almost never legitimate on their own. Correlate everything else. Most attack activity only becomes visible across a sequence of weaker signals, such as an unusual logon followed by a privilege change followed by access to a system the account has never touched. Build single-event rules and behavioral correlation into the same design, rather than choosing one.
6. Protect the evidence from the administrators it describes
Assume the administrators being monitored can edit the record until the architecture proves otherwise. Domain Admins membership includes membership in the local Administrators group on every domain-joined computer by default, which grants the right to read the Security log and the ability to clear it outright.
NIST SP 800-53 AU-9(4) covers exactly this recursion, since individuals with privileged access who are also audit subjects can affect audit information reliability by inhibiting logging or modifying records.
A determined domain administrator can still bypass ACL restrictions on log access by using SeTakeOwnershipPrivilege to take object ownership and rewrite the object's discretionary access control list (DACL). Build architectural separation instead; that control survives the move. AU-9(2) requires separate audit storage so a compromise of the monitored system doesn't compromise its record.
- Forward security events in near real time to a collector under separate administration. Windows Event Forwarding supports this, but it sends no notification and leaves no gap indicator when a disconnected client's log overwrites events.
- Send the 4728, 4732, and 4756 group-membership-addition events and 5136 changes on AdminSDHolder to that same collector, so nobody can edit a re-grant out of the record between reviews.
- Restrict audit log management to a defined subset of privileged users separate from the administrators the audit covers, per AU-9(4), and grant reviewers read-only access, per AU-9(6).
- Alert on tampering itself. Event 4719 records an audit policy change, and Windows logs it regardless of the audit policy setting; rate it as high criticality. Correlate it with a preceding 4688 process-creation event showing wevtutil or auditpol, which requires command-line logging.
Compliance requirements for privileged user monitoring
Auditors ask organizations to prove who held which rights, when they held them, and what they did with them. Frameworks express that demand as recertification intervals and logging obligations, and the intervals are the easy half. What sinks programs is reconstruction, because a review that nobody can rebuild six months later fails the audit, whether or not it ran on schedule.
以下参考资料使用截至2026年9月生效的版本,涵盖 PCI DSS v4.0.1、NIST SP 800-53 Rev 5、HIPAA Security Rule,45 CFR 第164部分子部分C,以及 ISO/IEC 27001:2022。
还有两项欧洲法规同时适用:Network and Information Systems Directive 2(NIS2)的实施条例和Digital Operational Resilience Act(DORA)的授权条例。
Framework | Requirement for privileged accountability |
|---|---|
|
PCI DSS v4.0.1 |
Requirement 10.2.1.2 requires logging of all administrative actions. Requirement 7.2.4 requires six-month reviews of user accounts and privileges, including third-party and vendor accounts. |
|
NIST SP 800-53 Rev 5 |
AC-6(9) requires logging the execution of privileged functions. |
|
HIPAA Security Rule |
45 CFR 164.312(b) requires records of system activity for systems holding electronic protected health information (ePHI). The rule prescribes no audit log retention period. |
|
SOX and the Public Company Accounting Oversight Board (PCAOB) |
No numbered control ID covers privileged access review. AS 1105 requires auditors to test the accuracy and completeness of company-produced information. |
|
ISO/IEC 27001:2022 |
Annex A 5.18 and 8.2 require restricting privileged access rights and reviewing them at planned intervals and after changes. Intervals follow the organization's risk assessment. |
|
NIS2 (Implementing Regulation 2024/2690) |
Annex point 11.3 requires reviews of privileged access rights at planned intervals, with the results documented. |
|
DORA (Delegated Regulation 2024/1774) |
Article 21 requires access reviews at least every six months for systems supporting critical or important functions and at least annually for all others. |
HHS于2025年1月提出了Security Rule的全面修订,但这仍然是一个提案,监管日程目标为2027年7月进行最终行动。根据提案,审计控制标准将从164.312(b)移至164.312(d)(1),并扩展到所有相关系统,而不仅仅是持有ePHI的系统。在HHS最终确定规则之前,适用的引用仍为164.312(b)。
当有人要求组织重建数月前的特权操作时,审计准备显示出其局限性,而答案取决于证据保存的时间长短。
Microsoft Entra ID 在免费版中保留审核和登录日志7天,在P1和P2中保留30天,均遵循其本地保留期限。
PCI DSS要求10.5.1规定必须有十二个月的审计日志历史,且最近三个月的日志需立即可供分析。仅靠本地保留不足,因此持有转发副本的收集器通常成为记录系统。
常见挑战及其克服方法
以下障碍是文化和运营方面的,因此更换工具很少能解决它们。
- 管理员将监控视为制度性不信任,有些人试图禁用它: 通过将日志转发到系统管理员无法访问的系统,保持对管理域之外的监督,并在控制措施实施前解释哪些威胁针对其凭据。限时、单独分配的权限在不将管理员视为嫌疑人的情况下保留审计轨迹。
- 合法的的 privileged 活动产生大量数据,掩盖了有意义的警报: 评分基线偏差,而非每个事件都报警。将检测工程与战术、技术、和程序(TTPs)对齐 这样,运行已知更新脚本的管理员将被抑制而非呼叫。
- 共享、紧急访问(break-glass)和供应商账户难以进行个人归属,且紧急账户设计上没有指定所有者: Use dedicated administrator accounts(CIS Control 5),并至少每季度审查一次服务账户。为每个服务账户分配指定所有者,并在每次break-glass使用时触发severity 0警报。
Netwrix如何帮助特权用户监控
Netwrix将这些职责分配到四个产品中,每个阶段一个。Netwrix Access Analyzer负责发现,Netwrix Privilege Secure负责减少。
Netwrix Auditor 和 Netwrix Threat Manager 共同涵盖了证据问题的两部分:已更改内容的历史记录以及偏离身份既定模式的行为检测。
发现超越组成员资格的有效权限
Netwrix Access Analyzer自动确定 Active Directory 域、OU、组、用户和计算机上的有效权限。其有效访问报告解析嵌套的组成员身份和 ACL 授予的权限,以显示账户实际拥有的访问权限,并在同一过程中标记过时的受托账户。该清单支持权限缩减,因为没有缩减的清单只会扩大监控列表。
将持续的特权访问替换为任务范围访问
Netwrix Privilege Secure 是一款Privileged Access Management产品,用以替代常驻管理员权限,改为任务范围访问。它会发放一个Activity Token,这是一个仅用于单次活动的唯一时限账户。Netwrix Privilege Secure在活动完成后移除此账户,因此使用间不会存在持续的提升权限凭据。
Eastern Carver County Schools 从为9,300名学生和2,000多名员工服务的网络交换机管理、VMware和安全摄像头系统中移除了常驻特权账户,替换为任务结束时过期的临时访问权限。团队在几天内完成了部署。
记录权限和配置更改的前后值
重新认证和审计员的历史查询都依赖于对环境早期状态的记录。
Netwrix Auditor 是一款 IT 审计和合规报告产品,监控 Active Directory、Group Policy、Entra ID、Exchange、文件服务器和 SQL Server,记录谁在何时何地更改了什么,变更前后值也会记录在变更详情中。
时点报告 从每日快照中重建所选时刻的配置。要报告过去的日期,必须先导入该历史快照。
检测异常的特权和服务账户行为
基线设定是团队最常推迟的阶段,Netwrix Threat Manager对此进行了自动化。Identity Threat Detection 产品会标记偏离既定模式的特权账户和服务账户行为。
异常行为检测在账户活跃至少30天后开始,基于最多120天的活动数据建立该账户的基线,并每15分钟重新评估每个用户。超过配置阈值的偏差将创建威胁记录以供调查。
对于大多数团队来说,有用的问题是他们当前的程序实际上完成了哪些阶段。Netwrix Access Analyzer、Netwrix Privilege Secure、Netwrix Auditor 和 Netwrix Threat Manager 各自针对不同的阶段。
涵盖CISA的账户对策
CISA的驱逐策略工具按ID编目了事后补救措施。其中五项针对特权和过期账户,每项背后都有Netwrix产品支持:
- 删除多余和过时的账户 (CM0112): Netwrix Access Analyzer 标记已禁用和不活跃的用户账户,并自动执行清理。
- 监控用户、服务和管理员账户的权限(CM0043): Netwrix Access Analyzer 解析嵌套组和ACL授予的权限,以显示每个账户的有效权限。
- 监控账户创建和权限更改(CM0044): Netwrix Auditor 记录新账户和安全组成员变更的“谁、什么、何时、何地”。
- 审核 Active Directory 中的 Group Policy 对象 (CM0085): Netwrix Auditor 记录 Group Policy 变更的前后值。
- 调查可疑登录尝试(CM0063):Netwrix Threat Manager 标记相对于每个身份基线的异常认证。
将管理信任转化为可审查的记录
授权系统会对有效凭证持续响应“是”,无论背后的人是管理员还是通过钓鱼获得凭证的攻击者。监控才是区分两者的关键,而且只能作为程序运行。
该程序意味着已发现的用户群、减少的攻击面、行为基线、审查间捕获的权限漂移、相关警报而非无人阅读的队列,以及被监控管理员无法悄然编辑的证据。
审计员、董事会和网络保险公司现在要求的是确切的记录,而不是监控工具存在的政策声明。两者之间的差距正一步步缩小,从您当前程序尚未完成的阶段开始。
请求演示,了解Netwrix如何覆盖您的特权账户的发现、减少、证据和检测。
关于特权用户监控的常见问题
分享到
了解更多
关于作者