Huntress detailed how on-premises Microsoft Active Directory Rights Management Services (AD RMS) relies on the cluster’s Server Licensor Certificate (SLC) private key to protect encrypted documents. Standard domain users can identify AD RMS clusters and protected files, retrieve public certificate data, and enumerate rights-policy templates, while the administrative SOAP interface is limited to members of the local AD RMS Service Group.
A member of that Service Group can potentially extract a software-protected SLC private key from the AD RMS configuration database and decrypt protected content offline. Because SLC keys cannot practically be rotated for documents already protected by a deployment, compromise may expose all data encrypted under that key even after wider Active Directory remediation; the risk principally affects on-premises AD RMS, rather than cloud-held Azure Information Protection or Microsoft Purview tenant keys unless organizations retain those keys on-premises.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Huntress demonstrated that compromise of a software-keyed on-premises AD RMS Service Group member can enable extraction of the Server Licensor Certificate private key, allowing offline decryption of protected documents without RMS access, rights, or victim credentials. The research also showed that the stolen key can sign forged Rights Account Certificates that impersonate authorized identities and obtain use licenses from the live RMS service.
Huntress documented that authenticated domain users can discover on-premises AD RMS clusters, obtain public certificate data, enumerate rights-policy templates, and identify protected files. The research reported that compromise of the deployment Server Licensor Certificate private key could permit offline decryption of content protected under that key, with prior content remaining tied to the old key if a new key is generated.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
huntress.com
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.