Onelogon flaw targets Active Directory Netlogon settings

Onelogon is an Active Directory weakness linked to legacy Netlogon, enabling authentication bypass and potential domain controller compromise.

Atlas Newsdesk ·

Onelogon flaw targets Active Directory Netlogon settings

A newly identified security weakness affecting Microsoft Active Directory is drawing attention to organizations that still run legacy-compatible Netlogon settings. The issue, referred to as Onelogon , can enable an attacker to bypass authentication in certain enterprise environments by exploiting how the Netlogon protocol behaves, according to officials familiar with the matter.

Those officials said the weakness is associated with predictable cryptographic patterns inside Netlogon. As a result, earlier security updates introduced to address the related Zerologon issue may not fully remove this newer bypass method in every configuration.

How the Onelogon path can reach domain controllers How the Onelogon path can reach domain controllers According to the technical description of the issue According to the technical description of the issue, the attack chain can end with a domain controller compromise. Domain controllers are central to identity and access management in many organizations, which can make the impact of a successful compromise especially severe for enterprise security operations. The same technical description says the method can be executed using brute-force attempts or by applying a meet-in-the-middle approach against protocol behavior. It also states that compromise can be achieved in under 40 minutes in affected environments, depending on the conditions described. Why legacy Netlogon behavior remains a risk Onelogon is described as part of an ongoing class of Netlogon weaknesses rather than a completely separate defect. In that framing, the concern is not only whether organizations applied past patches, but whether protocol characteristics still allow an authentication bypass when specific conditions exist. This places the focus on configuration decisions and This places the focus on configuration decisions and inherited defaults. Where environments continue to rely on older Netlogon behaviors, the bypass avenue may remain possible even after organizations carried out remediation aimed at Zerologon.

Microsoft’s position and the mitigation approach

Microsoft has indicated it will not issue a fix for this vulnerability, citing the need to maintain backwards compatibility for legacy systems. In practice, this leaves residual risk for organizations that still depend on older protocol expectations. Microsoft Active Directory The company has said adopting secure Remote Procedure Calls (RPCs) is the primary mitigation. This shifts the response from a single patch event to a longer migration away from legacy-compatible configurations that preserve older behavior.

Audits point to exposure, with an open question for defenders Recent audits have identified enterprise networks that were active and exploitable under the described conditions. This indicates the mitigations cited by Microsoft are not universally deployed and that legacy configurations remain in use.

For organizations that cannot move to secure RPC standards, the issue represents an ongoing security gap. Stakeholders have urged prioritizing audits of Netlogon configurations to identify which systems remain exposed and to remediate environments where the bypass method can be applied.

The immediate uncertainty for defenders, as presented in the source material, is not whether the weakness exists, but which parts of their environment still rely on legacy protocol behavior.

More stories