
Active Directory Security: Hardening Against Modern Attacks
An Active Directory security guide — how modern attacks like Kerberoasting, DCSync and Pass-the-Hash work, the tiered admin model, and a practical AD hardening checklist to break the attack chain.
For the vast majority of enterprises, Active Directory is the keys to the kingdom. It authenticates your users, authorises access to almost everything, and — because it has been quietly accreting permissions, service accounts, and legacy trust for decades — it is also the single most-targeted system in a modern intrusion. Strong Active Directory security is what stands between one phished laptop and full domain compromise.
Attackers rarely "hack" AD with an exotic exploit. They log in, look around, and abuse the misconfigurations and excess privilege that accumulate in every long-lived domain: an over-privileged service account, a stale admin, a weak Kerberos password, an ACL nobody remembers granting. In a ransomware case, the path from initial foothold to Domain Admin is often measured in hours — and AD is the highway.
This guide explains how modern AD attacks actually work — Kerberoasting, DCSync, Pass-the-Hash, Golden Tickets and more — then gives you a practical, prioritised hardening checklist to break the attack chain at every step. It's written for identity, infrastructure, and security teams who need to move from "AD works" to "AD is defensible."
- 01 AD is compromised through misconfiguration and excess privilege, not usually zero-days.
- 02 Know the attack chain: foothold → recon/escalate → lateral movement → domain dominance — and harden every step.
- 03 The highest-leverage controls: a tiered admin model, PAWs, LAPS, and least-privilege for privileged accounts.
- 04 Kill the classics: no unconstrained delegation, strong service-account passwords (gMSA), protect Tier 0.
- 05 Assume breach — monitor AD telemetry in a SOC and validate defences with red teaming and attack-path analysis.
Why Active Directory Is the Attacker's Favourite Target
Active Directory was designed in an era that prized interoperability and convenience over adversarial resilience. Two decades later, most domains carry deep technical debt: default configurations never re-hardened, service accounts with domain-wide rights, nested group memberships nobody has audited, and trust relationships that quietly widen the blast radius. Attackers don't need to break the cryptography — they simply enumerate this sprawl and walk the paths it creates.
Because AD underpins single sign-on to file shares, applications, and often cloud identity too, a Domain Admin foothold is effectively game over: the adversary can create accounts, disable defences, deploy ransomware fleet-wide, and forge credentials that survive password resets. That is why AD hardening is not an infrastructure nicety — it is the core of enterprise identity security.
Attackers map AD relationships with tools like BloodHound, which visualise the shortest path from any low-privileged user to Domain Admin. Defenders can — and should — run the same analysis first: if a tool can draw that line in your domain, so can an intruder.
The Modern AD Attack Chain
Almost every AD compromise follows the same four stages. Understanding them tells you exactly where to place defences.
| Stage | Technique | What it does |
|---|---|---|
| Foothold | Phishing, exposed service, weak/sprayed creds | Gains a first authenticated user on the network |
| Recon & escalate | Kerberoasting, AS-REP roasting, ACL abuse, BloodHound | Cracks service-account passwords, finds privilege paths |
| Lateral movement | Pass-the-Hash, Pass-the-Ticket, overpass-the-hash | Reuses stolen credentials/tickets to hop between hosts |
| Domain dominance | DCSync, Golden/Silver Ticket, DCShadow | Extracts all secrets, forges tickets, achieves persistence |
The Foundation: A Tiered Administration Model
The single most impactful AD hardening decision is tiering — separating identities and workstations by privilege so a compromised laptop can never expose Domain Admin credentials.
The rule: credentials from a higher tier are never exposed on a lower tier. Tier 0 admins use dedicated Privileged Access Workstations (PAWs) that don't browse the web or read email. This one pattern defeats the most common escalation — harvesting a Domain Admin's cached credentials from an ordinary workstation.
Start tiering with Tier 0. Inventory every account and group with domain-control rights, remove everything that doesn't need them, and enforce that Tier 0 logons only happen from PAWs. Protecting a small, well-defined Tier 0 yields more risk reduction than any single tool.
Core Hardening Controls
Pair AD hardening with an assume-breach posture: extend controls into a Zero Trust architecture, protect identity attack paths with a cloud identity & access review (hybrid AD/Entra ID), and validate everything with red teaming and internal network penetration testing that specifically targets AD.
Detect & Respond — Assume Breach
Prevention buys time; detection wins. Because a determined attacker will get a foothold, you must see AD attacks in progress. Feed domain-controller security events, authentication anomalies, and identity telemetry into a managed SOC / MDR, and hunt for the tell-tale signs — abnormal ticket requests (Kerberoasting), replication requests from non-DCs (DCSync), Pass-the-Hash patterns, and suspicious group changes. Threat hunting and rehearsed incident response turn "we have logs" into "we caught it at stage two."
Collecting domain-controller logs but never building detections for AD-specific attacks. Raw event volume isn't detection — you need tuned use cases for Kerberoasting, DCSync, and anomalous privileged logons, actively monitored by analysts.
The Active Directory Hardening Checklist
Use this as a working checklist. If you can't confidently tick an item, it's a gap worth prioritising.
- ✓ Tiered admin model (Tier 0/1/2) enforced
- ✓ Domain/Enterprise Admins minimised & audited
- ✓ PAWs for all Tier 0 administration
- ✓ Just-in-time / PIM for privileged access
- ✓ Phishing-resistant MFA for admins
- ✓ Protected Users group for sensitive accounts
- ✓ LAPS for unique local-admin passwords
- ✓ gMSA / 25+ char service-account passwords
- ✓ Stale/disabled accounts removed regularly
- ✓ krbtgt password rotated on schedule
- ✓ No admin accounts with SPNs (Kerberoast risk)
- ✓ Modern password policy / banned-password list
- ✓ No unconstrained delegation
- ✓ Dangerous ACLs (WriteDacl/GenericAll) removed
- ✓ NTLM restricted; SMB signing enforced
- ✓ LLMNR / NBT-NS disabled
- ✓ DC & GPO baselines to CIS/Microsoft standards
- ✓ Legacy OS & protocols retired
- ✓ DC & identity logs feeding a 24×7 SOC
- ✓ Detections for Kerberoasting, DCSync, PtH
- ✓ Attack-path analysis (BloodHound) run internally
- ✓ Periodic AD-focused penetration test / red team
- ✓ Tested AD backup & forest recovery plan
- ✓ IR playbook for domain compromise
Have a tested AD forest recovery plan. Ransomware crews deliberately corrupt or encrypt domain controllers; if you can't rebuild the forest cleanly from offline backups, an AD compromise becomes an existential outage — not just a security incident.
Common Mistakes
1. Admins that log in everywhere
Domain Admins using their privileged account on ordinary workstations leave harvestable credentials on every machine they touch.
2. Weak, static service-account passwords
Service accounts with short passwords and SPNs are Kerberoasting gold — and they often hold high privilege.
3. Privilege sprawl & nested groups
Years of "just add them to this group" leave hidden paths to Domain Admin nobody intended.
4. Set-and-forget
AD drifts constantly. A domain hardened two years ago and never re-assessed is almost certainly exposed again today.
5. Ignoring hybrid identity
On-prem AD and cloud identity (Entra ID) are linked; attackers pivot between them. Harden and monitor both.
How Adayptus Helps
Adayptus secures identity from the inside out. We run Active Directory security assessments that map real attack paths (as an adversary would) and deliver a prioritised, business-aware hardening plan; internal network penetration testing and red team / purple team exercises that target AD end to end; and hybrid identity reviews across on-prem AD and Entra ID. We build the detections and feed them to a 24×7 managed SOC / MDR with threat hunting and incident response, extend the model into Zero Trust, and prove resilience with continuous validation and ransomware readiness — all governed under GRC and, where needed, a virtual CISO. Related reading: our ransomware defence playbook and Red Team vs Penetration Testing guide.
How defensible is your Active Directory?
Talk to Adayptus about an AD security assessment with real attack-path analysis — and a clear, prioritised hardening roadmap your team can actually execute.
Conclusion
Active Directory security isn't about a silver-bullet product — it's about systematically removing the misconfigurations and excess privilege that let attackers turn one foothold into total control. Tier your administration, protect Tier 0 with PAWs, kill the classic escalation paths (Kerberoasting, delegation, ACL abuse), deploy LAPS and gMSA, and assume breach by monitoring AD telemetry in a SOC. Then validate it the way an attacker would — with red teaming and attack-path analysis — and keep re-checking, because AD drifts. Break the chain at every stage and Domain Admin stops being one phish away.
Disclaimer: This article is an original, informational overview of Active Directory security and hardening as understood in 2025-2026. Configuration guidance is indicative; always validate against current Microsoft security documentation, the CIS Benchmarks, and your environment before making changes to a production directory.
References
- Microsoft — Best Practices for Securing Active Directory & the tiered access model.
- CIS — CIS Benchmarks for Windows Server / Active Directory.
- MITRE — ATT&CK (Credential Access, Lateral Movement techniques).
- NSA/CISA — guidance on identity & access hardening.
- Microsoft — Windows LAPS and Protected Users documentation.
Frequently Asked Questions
Click any question to expand the answer.
QWhy is Active Directory such a common target?
Active Directory authenticates users and authorises access to almost everything, so compromising it usually means controlling the whole environment. Long-lived domains accumulate misconfigurations, excess privilege, and legacy trust, and attackers exploit that sprawl by logging in and walking the privilege paths rather than using exotic exploits. A Domain Admin foothold lets them deploy ransomware, disable defences, and forge persistent credentials.
QWhat is Kerberoasting and how do I prevent it?
Kerberoasting lets any authenticated domain user request a Kerberos service ticket for accounts that have a Service Principal Name (SPN), then crack that ticket offline to recover the service-account password. Prevent it by using group Managed Service Accounts (gMSA) or very long (25+ character) passwords for service accounts, removing SPNs from privileged accounts, and monitoring for abnormal service-ticket requests.
QWhat is the tiered administration model?
The tiered model separates administrative identities by privilege level: Tier 0 (domain controllers and anything controlling identity), Tier 1 (servers and applications), and Tier 2 (workstations and users). Higher-tier credentials are never used or exposed on lower-tier systems, and Tier 0 administration happens only from dedicated Privileged Access Workstations. This prevents an ordinary workstation compromise from exposing Domain Admin credentials.
QWhat is a DCSync / Golden Ticket attack?
DCSync abuses replication rights to impersonate a domain controller and extract password hashes for any account, including krbtgt. With the krbtgt hash, an attacker forges a Golden Ticket — a Kerberos ticket granting near-unlimited, long-lived access that survives password resets. Defences include tightly restricting replication rights, monitoring for replication requests from non-DCs, protecting Tier 0, and rotating the krbtgt password (twice) after any suspected compromise.
QHow often should we assess Active Directory security?
At least annually, and after any significant change (migrations, mergers, new applications, or an incident). Because AD configuration and group memberships drift continuously as teams operate, many organisations also run continuous attack-path monitoring and periodic red-team or internal penetration tests focused on AD to catch newly-introduced privilege paths before an attacker does.
QHow does Adayptus help secure Active Directory?
Adayptus runs Active Directory security assessments with real attack-path analysis, internal network penetration testing and red/purple team exercises targeting AD, and hybrid identity reviews across on-prem AD and Entra ID. We build AD-specific detections feeding a 24x7 managed SOC / MDR with threat hunting and incident response, extend hardening into Zero Trust, and validate resilience with continuous validation and ransomware readiness, all delivered with prioritised, actionable remediation guidance.
Infosec Team
Security Research, Adayptus
The Adayptus Infosec Team is a group of offensive and defensive security practitioners — penetration testers, red teamers, and SOC analysts — who assess, harden, and defend enterprise environments across BFSI, healthcare, SaaS, and critical infrastructure. They publish practical guidance drawn from real-world assessments and incident response engagements.
On This Page
- Why Active Directory Is the Attacker's Favourite Target
- The Modern AD Attack Chain
- The Foundation: A Tiered Administration Model
- Core Hardening Controls
- Detect & Respond — Assume Breach
- The Active Directory Hardening Checklist
- Common Mistakes
- How Adayptus Helps
- Conclusion
- References
- Frequently Asked Questions


