AdminSDHolder Misconceptions & Misconfigurations | SO-CON 26

AdminSDHolder Misconceptions & Misconfigurations | SO-CON 26

Source: YouTube · SpecterOps · published Jun 4, 2026 · 42:37

Identity & Access Management
No ratings yet Log in to rate
Transcript Available
Description

[BLUF]
Jim Sikora debunks common myths regarding Active Directory administration, specifically targeting the incorrect belief that the ntds.dll process (STprop) or the adminSDHolder object directly apply permissions in real-time 1:05.

Key Takeaways:
• The speaker’s deep interest in the adminSDHolder topic stems from widespread misinformation found online, where many technical "facts" are actually false 0:17.
• A common misconception is that the System Topic Process (STprop) is the background process responsible for applying adminSDHolder permissions; this is not true 0:50.
• Numerous widely accepted phrases and technical details in the cybersecurity community are myths and should be treated with skepticism until verified 0:47.

[Closing statement]
Understanding the actual mechanics of Active Directory security is crucial for effective administration. Relying on unverified online information can lead to significant misunderstandings of how permission inheritance and protection actually work.

Sources:

  • 0:17 Explanation of the speaker's motivation for writing about adminSDHolder due to online errors.
  • 0:47 Identification of common technical phrases as myths.
  • 0:50 Specific debunking of the STprop process myth.
  • 1:05 Introduction to the session's goal of clarifying these misconceptions.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

My name is uh Jim Sikora, as was said. Uh she's already introduced me a little bit. And you might like wonder, you know, like my personal blog's website is adminSDHolder. Why am I so interested in this topic that I wrote a book about it? I've made it part of my identity. Um and really the reason is that somebody was wrong on the internet. So, to get started, I'm just going to flash a few phrases across the screen here. There's something that ties all of these things together. What is it? They're not true. They're all All of these things, including that ST prop is the background process that applies adminSDHolder permissions, are myths and misconceptions. They're not true. So, what are we going to talk about today? Like, you know, I'm going to be attempting to condense that 100 and almost 6…