Microsoft Active Directory is a core identity and access management system that controls access to critical systems and data, making it a prime target for malicious cyber threats. It acts as an organisation's digital gatekeeper, verifying users, managing permissions, and enabling single sign-on.
Because Active Directory controls access to so many systems, it is a highly attractive target for malicious actors. If malicious actors take control of your Active Directory, they can effectively gain complete control over an organisation’s enterprise IT network. In many cases, they can use the permissions already granted to standard users to investigate the environment, discover weaknesses, and gradually increase their access.
Alongside our international partners, we have released updated guidance on Detecting and mitigating Active Directory compromises, to help organisations improve their network defences against these threats. The updated guidance provides mitigation and detection advice for 18 common Active Directory compromise techniques including a new novel DCSync detection technique; and a new section covering shadow credentials.
This guidance provides an overview of each technique and how it can be leveraged by malicious actors, as well as recommended actions to mitigate these techniques. By implementing the recommendations in this guidance, organisations can significantly improve their Active Directory security, and strengthen their overall network security against cyber threats.
Read more about detecting and mitigating Active Directory compromises.