Repeated attempted changes tp DACL since update to CU19 and Hafnium patch

Will T 101 Reputation points
2021-03-11T16:10:39.74+00:00

Hi all, since the update to the above, I've noticed that every hour, changes are attempted to the DACL for exchange admins to deny exchange trusted subsystem access to those objects. Would anybody know if this is as i suspect, a process that runs since the patch to assist in keeping things 'safe' ?

Thanks

Will

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,359 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 142.3K Reputation points MVP
    2021-03-11T16:39:16.24+00:00
    0 comments No comments

  2. Xzsssss 8,861 Reputation points Microsoft Vendor
    2021-03-12T05:41:07.687+00:00

    Hi @Will T ,

    Agree with Andy. This is more likely to be expected. You could check it with changing AdminSDProtectFrequency.

    https://techcommunity.microsoft.com/t5/microsoft-security-and/active-directory-access-control-list-8211-attacks-and-defense/ba-p/250315

    Regards,
    Lou


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.