Security researcher Matt Weeks has discovered a way to abuse the Microsofts PowerShell feature Just Enough Administration (JEA) to escalate user profiles. The expert published an interesting analysis to explain that the JEA profiles dont represent an obstacle for an attacker that can escalate themselves to sysadmin. Weeks did not exploit any zero-day flaw in the JEE technology, he added/switched a machine to a domain then pulled group policy from a Domain Controller managed by the attacker.”]
Source: https://securityaffairs.co/wordpress/52084/hacking/jea-profiles-abuses.html