ActiveDirectory User Passwords encryption Used

Craig Garland 1 Reputation point
2021-10-26T22:53:36.453+00:00

Hi

We are undertaking a security review and need to confirm the Encryption used by AD to encrypt user passwords.

We have a few options but want to ensure we select the correct one. I have search the web but cannot find a clear answer so hoping someone can help.

We have Windows 2016 server, with 2012 Forest and domain level. My understanding is that password are hashed but I am not sure of the encryption.

Options are
Hash with MD4, MD4, Sha-1
Hashed SHA-2
Salted and Hashed with industry standard

Hope someone can you let me know the encryption and point me to information that covers this?

Thanks for your time in advance.

Craig

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,110 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,840 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Craig Garland 1 Reputation point
    2021-10-26T22:59:53.98+00:00

    Hi

    I did find this article.
    https://floriansailer.wordpress.com/2019/05/31/active-directory-password-encryption/

    Which seems to indicate Pre 2016 use MD5 and Salted.
    2016 plus uses AES, Salted and PEK Encryption.

    Regards
    Craig

    0 comments No comments