Skip to content

Glossary

AdminSDHolder

AdminSDHolder is a protected AD object whose ACL is periodically reapplied to privileged accounts, and a common target for persistence.

AdminSDHolder is a special container object in Active Directory that holds a template access control list (ACL). Every 60 minutes, by default, a background process called SDProp compares this template against the ACLs of members of protected groups (such as Domain Admins and Enterprise Admins) and overwrites any that have drifted, ensuring privileged accounts cannot be quietly given weaker or additional permissions through group membership changes alone.

This matters because attackers have learned to abuse the mechanism itself for persistence: by adding a malicious ACE directly to the AdminSDHolder object, that entry gets propagated to every protected account on the next SDProp cycle, granting stealthy, self-healing control over privileged accounts even after other remediation. Defenders should treat any modification to AdminSDHolder's ACL as a high-severity alert and periodically audit it against a known-good baseline.

See ACL and object security.