m365expertise MICROSOFT SECURITY EXPERTISE

Active Directory

Why Active Directory is target #1

Active Directory authenticates users, applies policies and distributes rights across the entire IT estate. Whoever controls the directory controls the estate: in nearly every ransomware compromise, the attacker took control of AD before encrypting. The root domain, its domain controllers and the accounts that administer them form the Tier 0 — the most critical perimeter of your organization.

forest.local TIER 0 · ROOT DOMAIN paris.forest.local Child domain lyon.forest.local Child domain two-way trust two-way trust partenaire.ext External forest · one-way trust

The difficulty: a directory lives. Years of delegations, GPOs, service accounts and migrations build up a security debt invisible to the naked eye, but perfectly readable to a tooled attacker.

Classic attack paths

Kerberoasting

Offline extraction of service account passwords via their Kerberos tickets (SPNs).

Pass-the-Hash / Ticket

Reuse of stolen hashes or tickets to move laterally without knowing the password.

DCSync & replication

Abuse of replication rights to extract all domain secrets, including krbtgt (Golden Ticket).

ACLs & delegations

Forgotten permission chains (GenericAll, WriteDACL, Kerberos delegations) leading to privileged accounts.

Hijacked GPOs

Modification of Group Policies to deploy a payload across an entire scope in a single action.

Misconfigured AD CS

Permissive certificate templates (ESC1-ESC8) providing silent, persistent privilege escalation.

Our approach to AD security

We treat the directory as a critical system in its own right, in three phases: measure the real attack surface with our AdGUARD tool (173 checks aligned with ANSSI, NIS2, DORA and MCSB), segregate privileges with a pragmatic tiering model, then harden over time — protocols, GPOs, delegations, monitoring — with a follow-up audit that proves the gain. Each service opposite covers one step of this trajectory.

Video demo

See AdGUARD in action: connector setup, audit run and report review.

Unsure about your exposure?
Audit, assessment or incident response — let's talk.
Request an audit
‹ Back to home