M1036Account Use Policies
Reduce brute-force and abuse with account lockout, logon time/location restrictions, and concurrent session limits.
Loading…
Credential theft
Techniques in this tactic (7)
Reduce brute-force and abuse with account lockout, logon time/location restrictions, and concurrent session limits.
Advanced audit policy + command-line auditing + Sysmon + directory access auditing: the telemetry that detection requires.
Block common attack behaviors using Defender ASR rules and Office macro restrictions.
Visibility and control over SaaS/cloud application usage; OAuth application and data flow monitoring (Defender for Cloud Apps).
Layered platform protections that reduce theft of in-memory and on-disk credentials (LSASS, Protected Users, WDigest, cache).
Monitoring credential exposure in breach databases, paste sites, and dark web forums; over 30% of initial accesses use previously stolen credentials.
Encrypting sensitive data at rest and in transit so it cannot be used even if stolen.
Restricting inbound/outbound traffic with default-deny filtering, egress control, and anti-spoofing (uRPF/BCP38).
Identity governance (Access Reviews, entitlement, cross-tenant) that prevents privilege creep and unmonitored external access.
PIM that makes privileged roles eligible rather than permanent, used via approved and time-limited activation.
Multi-factor authentication that stops the vast majority of password-based attacks; enforced in Entra via Conditional Access.
IDS/IPS that detects and blocks known malicious patterns and anomalies in network traffic, with proper sensor placement.
Long passwords + breach/dictionary checks + MFA; reversible encryption disabled.
Keep the number and use of privileged accounts to a minimum: Domain Admins hygiene, LAPS, JIT/PIM.
Narrows egress channels with DNS hardening (protective DNS/RPZ + sinkhole) and web proxy/filtering.
Account lifecycle management: proper creation, assignment with least privilege, timely disabling, and periodic access reviews.
Reducing human-originated risk by training users on phishing, social engineering, and secure behavior.
A least-privilege architecture that rejects the assumption of a trusted internal network and verifies every access request by identity, device, and context.