Typical severity: High. Likelihood of attack: High. An adversary guesses or obtains (i.e. steals or purchases) legitimate credentials (e.g. userID/password) to achieve authentication and to perform authorized actions under the guise of an authenticated user or service.
Leverage multi-factor authentication for all authentication services and prior to granting an entity access to the domain network. | Create a strong password policy and ensure that your system enforces this policy. | Ensure users are not reusing username/password combinations for multiple systems, applications, or services. | Do not reuse local administrator account credentials across systems. | Deny remote use of local admin credentials to log into domain systems.