PERSIST-1 (ADCS Local Persistence - User Accounts)

Certificate remains valid (until expiry specified in certificate) even after user password is changed. Compromise a user who has enrollment rights to an AD CS template that has the Client Authentication EKU enabled, we can request and use a certificate that will be valid until the expiry specified in the template.


PERSIST-3 (Certificate Renewal)

Renew compromised/requested certificates before they expire. Note the Validity Period of a certificate!