You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Sep 12, 2023. It is now read-only.
Hi,
so far the T0 list is limited to group objects, but i'd suggest to extend it to several built-in objects which should always considered T0, such as:
Domain root object
AdminSDHolder object
TrustedDomain objects
krbtgt user account
RID-500 account
AAD Connect object(s)
Even possibly extending it to whole OUs and GPOs.
Let me know what you think, cheers
The text was updated successfully, but these errors were encountered:
Hi,
so far the T0 list is limited to group objects, but i'd suggest to extend it to several built-in objects which should always considered T0, such as:
Even possibly extending it to whole OUs and GPOs.
Let me know what you think, cheers
The text was updated successfully, but these errors were encountered: