Zerologon: Emergency Active Directory Response Lessons
CVE-2020-1472, known as Zerologon, affected the Netlogon Remote Protocol and could allow an unauthenticated attacker with network access to a domain controller to obtain domain administrator access. Microsoft released updates and moved toward enforcement of secure Netlogon connections.
The vulnerability's potential impact made domain-controller patching urgent, while the staged enforcement model required administrators to find incompatible devices and eliminate insecure exceptions.
Domain control and compatibility collided
A domain controller anchors authentication for much of a Windows environment. Compromise can undermine accounts, policy, trust relationships, and the evidence used to investigate other systems.
At the same time, legacy devices could depend on vulnerable Netlogon behavior. Permanent broad exceptions would preserve the attack path, so compatibility work needed owners and deadlines.
Protect the identity control plane
Patch every domain controller, monitor the vendor-defined events for vulnerable connections, identify noncompliant devices, and move them to secure behavior. Restrict network access to domain controllers and minimize privileged administration paths.
If exploitation is suspected, activate domain-compromise procedures rather than performing a routine password reset. Preserve evidence, isolate carefully, rotate credentials in a planned order, and rebuild trust from known-good systems.
- Patch all domain controllers, not only the primary site.
- Use enforcement telemetry to find legacy dependencies.
- Give exceptions owners and expiry dates.
- Maintain a rehearsed domain-compromise recovery plan.
Put the lesson into practice
- Confirm update coverage on every domain controller.
- Review Netlogon events for vulnerable connections.
- Remediate or isolate incompatible devices.
- Restrict domain-controller management and network paths.
- Exercise forest recovery and privileged credential rotation.
Related Outfaze guidance
- Patch management
- Vulnerability assessment
- Managed multi-factor authentication
- Managed detection and response
- Digital forensics and incident response
