Best Practise around honeytoken accounts?

%3CLINGO-SUB%20id%3D%22lingo-sub-2217838%22%20slang%3D%22en-US%22%3EBest%20Practise%20around%20honeytoken%20accounts%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2217838%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20considering%20using%20honeytoken%20accounts%20with%20high%20privileges%20(in%20order%20to%20prevent%20the%20obvious%20lure)%2C%20however%20how%20can%20you%20prevent%20abuse%20as%20soon%20as%20an%20authentication%20is%20made%20with%20the%20account%3F%20What's%20the%20best%20practice%20here%3F%3C%2FP%3E%3CP%3EIdeally%20I%20would%20like%20the%20account%20to%20be%20disabled%20within%20seconds%20on%20all%20domain%20controllers.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

I'm considering using honeytoken accounts with high privileges (in order to prevent the obvious lure), however how can you prevent abuse as soon as an authentication is made with the account? What's the best practice here?

Ideally I would like the account to be disabled within seconds on all domain controllers.

0 Replies