Domain or Tenant Policy Modification: Group Policy Modification

ID Name
ATAGS-T1081.001 Group Policy Modification
ATAGS-T1081.002 Trust Modification

Threat Actors may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path \\SYSVOL\\Policies.

ID: ATAGS-T1081.001
Sub-technique of:  ATAGS-T1081
Targeted Components: Cloud Control Plane
Responsibility: Provider
Created: 18 April 2026
Last Modified: 18 April 2026

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.