Active Directory (AD) is the identity and access management backbone of most corporate networks. It controls who can log in, what they can access, and how systems trust each other. For an attacker who has gained access to an internal network, AD is the primary target — because compromising it means compromising everything.

Why Active Directory is the target

AD is not just a directory service. It is the central authority that governs:

  • Authentication. Every user, every service account, every computer authenticates through AD.
  • Authorisation. Group memberships, group policies, and access control lists define what every identity can do.
  • Trust. Domain and forest trusts extend authentication across organisational boundaries.
  • Configuration. Group Policy Objects push configuration — including security settings — to every domain-joined machine.

An attacker who achieves Domain Admin privileges effectively controls the entire Windows environment: every machine, every user account, every piece of data accessible from the network. This is why AD compromise is the objective of nearly every internal penetration test and red team engagement.

Common attack paths

The following techniques represent the most commonly exploited AD weaknesses. Penetration testers use these to demonstrate the gap between an initial foothold (a standard user account) and full domain compromise.

Kerberoasting

Kerberos is the authentication protocol used by AD. When a user requests access to a service, the domain controller issues a service ticket encrypted with the service account’s password hash.

Any authenticated domain user can request a service ticket for any service with a Service Principal Name (SPN). The ticket is encrypted with the service account’s password hash — and that hash can be cracked offline.

If the service account has a weak password, a tester can crack it in minutes or hours. Service accounts frequently have weak passwords because they were created years ago, are not subject to regular password rotation, and are often excluded from password complexity requirements.

Kerberoasting requires no elevated privileges and generates minimal noise on the network. It is one of the most commonly exploited AD weaknesses.

AS-REP roasting

Similar to Kerberoasting, but targets accounts that have Kerberos pre-authentication disabled. When pre-authentication is not required, any user can request an encrypted response from the domain controller for the target account, and the encrypted portion can be cracked offline to recover the password.

This setting is occasionally disabled for compatibility with legacy systems or specific applications. Each account with pre-authentication disabled is a potential entry point.

NTLM relay

NTLM is an older authentication protocol that is still widely used in Windows environments. NTLM relay attacks intercept an NTLM authentication attempt and relay it to a different service, effectively authenticating as the victim.

For example, if a tester can trick a machine into authenticating to them (through techniques like LLMNR/NBT-NS poisoning or printer bug exploitation), they can relay that authentication to another service — potentially gaining access to file shares, databases, or even the ability to execute commands.

NTLM relay is particularly dangerous in environments where SMB signing is not enforced, LDAP signing is not required, or NTLM is not restricted.

Group Policy Object abuse

Group Policy Objects (GPOs) push configuration to domain-joined machines. If a tester can modify a GPO — or create a new one and link it to an organisational unit containing target machines — they can push arbitrary configuration, scripts, or scheduled tasks to those machines.

GPO abuse often results from excessive permissions: a user or group has been granted write access to a GPO that applies to sensitive machines, or has been granted the ability to link GPOs to organisational units.

Unconstrained and constrained delegation

Delegation allows a service to act on behalf of a user when accessing other services. Unconstrained delegation is particularly dangerous: a machine configured for unconstrained delegation stores the Kerberos tickets of any user who authenticates to it. If a tester compromises that machine, they can extract those tickets and impersonate any user — including Domain Admins.

Constrained delegation is more restrictive but can still be abused through protocol transition and other techniques.

ACL abuse

AD uses access control lists (ACLs) to define permissions on objects — users, groups, computers, GPOs. Misconfigured ACLs can create attack paths that are invisible to standard security reviews:

  • A user with “GenericWrite” on another user can modify their attributes, including setting an SPN (enabling Kerberoasting) or changing their password.
  • A user with “WriteDACL” on a group can grant themselves membership — including membership of Domain Admins.
  • A user with “ForceChangePassword” on a target can reset their password without knowing the current one.

Tools like BloodHound map these ACL relationships across the entire domain and identify the shortest path from any compromised account to Domain Admin.

Privilege escalation: from user to Domain Admin

In practice, compromising AD rarely involves a single technique. It is a chain:

  1. Start with a standard user account (from assumed breach, phishing, or credential theft).
  2. Enumerate the domain to identify misconfigurations, weak accounts, and attack paths.
  3. Harvest additional credentials through Kerberoasting, NTLM relay, or memory extraction.
  4. Escalate privileges by exploiting misconfigured delegation, GPO permissions, or ACLs.
  5. Achieve Domain Admin and demonstrate full control of the environment.

The number of steps varies — in some environments, a single Kerberoasted service account with a weak password is also a Domain Admin. In well-hardened environments, the chain might involve five or six linked techniques.

Post-compromise: what Domain Admin means

Once a tester achieves Domain Admin, they typically demonstrate what an attacker could do with that access:

DCSync. Using Domain Admin privileges to replicate the AD database, extracting the password hashes of every account in the domain — including the krbtgt account, which is used to sign Kerberos tickets.

Golden ticket. With the krbtgt hash, an attacker can forge Kerberos tickets for any user, granting unlimited access to any resource in the domain. A golden ticket persists even after the compromised account’s password is changed — only resetting the krbtgt password twice invalidates it.

Silver ticket. A forged service ticket that grants access to a specific service without touching the domain controller. Useful for targeted, stealthy access.

Persistence. Creating hidden admin accounts, modifying group memberships, deploying scheduled tasks, or installing services that survive remediation efforts.

Hardening Active Directory

The findings from an AD penetration test inform targeted hardening measures:

Tiered administration. Separate administrative accounts for different tiers: Tier 0 (domain controllers and AD management), Tier 1 (servers), Tier 2 (workstations). Tier 0 accounts should never log into lower-tier machines.

LAPS (Local Administrator Password Solution). Automatically rotates local administrator passwords on every machine, preventing credential reuse across the estate.

Credential hygiene. Strong, unique passwords for service accounts. Regular rotation. Managed Service Accounts or Group Managed Service Accounts where possible.

Reduce delegation. Eliminate unconstrained delegation. Review and restrict constrained delegation to the minimum required services.

Enforce SMB and LDAP signing. Prevents NTLM relay attacks.

Disable NTLM where possible. Move to Kerberos-only authentication for services that support it.

Monitor and alert. Detect Kerberoasting (unusual service ticket requests), DCSync (replication requests from non-DC sources), and other common attack indicators.

Regular AD security assessments. AD is not a set-and-forget system. Regular testing identifies new misconfigurations introduced by changes to the environment.

Active Directory is the single highest-value target in most internal environments. Testing it thoroughly — and acting on the findings — is one of the most impactful security investments an organisation can make.