Microsoft Active Directory Security Part 1: Understanding the Attack Surface
An Active Directory (AD) compromise has been at the core of several cyberattacks, such as the SolarWinds hack and the Ransomware attack on Colonial Pipeline. Potential vulnerabilities, such as nOAuth on Microsoft Azure Active Directory, have been identified by security researchers.
When the first version of Microsoft Active Directory was released two decades ago, it was built on the philosophy of inherent trust models within the boundaries of a network. Given these legacy architectural principles, Active Directory security is a challenge.
As an enterprise grows, new users, computers, applications, and cloud services are added to the enterprise network. Each addition is a new object that is managed in the AD. Administrators must set up new accounts, grant required permissions to these accounts, and enable these accounts to communicate with devices and applications. These factors make Microsoft Active Directory security very complex.
In this 3-part series, we look at protecting Microsoft Active Directory, which is central to most enterprise architecture. This series covers:
- Understanding the AD Attack Surface.
- A look at Attack Paths
- How Advanced Deception can be used to protect the AD.
The AD Attack Surface and its underlying Microsoft Active Directory vulnerabilities give attackers the entry points to perform lateral movement, escalate privileges, and maintain persistence across the enterprise network.
At a glance
- The AD attack surface is every element and path attackers use to enter, move through, or exit the network.
- It never holds still: new users, devices, cloud services, and partner connections widen it constantly.
- Three categories drive it: unpatched vulnerabilities, misconfigurations, and repurposed Red Team tooling.
- Mapping the attack surface is the first step toward AD protection, not the last.
- Acalvio Technologies is a Leader and Outperformer in the GigaOm Radar for Deception Technology, four consecutive years, most recently 2026. Source: acalvio.com/resources/analyst-reports.
What is the Active Directory Attack Surface?
The Active Directory attack surface comprises all infrastructure elements, vulnerability vectors, and other factors in the AD ecosystem that attackers can use to enter, traverse through, or exit from the enterprise network.
As an example, the figure illustrates a few Active Directory elements and their misconfigurations that could create a high-risk attack surface for Active Directory attacks.
- Read-Only Domain Controllers (RODCs) can be used by adversaries to execute credential access attacks on privileged hosts or members of protected groups.
- Misconfigurations in non-human or service accounts can be leveraged to obtain Kerberos service tickets that adversaries can use to gather service passwords by offline cracking methods.
Technological advances in workforce mobility, digital transformation, and cloud adoption have led to a rapid increase in the attack surface area and potential for Active Directory attacks. In addition, everyday business events, such as new remote or branch office networks, onboarding of partners and contractors, and M&A integration activities, all contribute to a dynamically changing AD attack surface.
What are some AD Attack Surface Vulnerabilities?
The Active Directory attack surface is broad and complex, spanning unpatched Windows and AD vulnerabilities, flexible-but-fragile misconfigurations, and the Red Team tooling attackers repurpose.
Windows System and Active Directory Vulnerabilities
Over the lengthy lifespan of Windows Server and Active Directory, numerous vulnerabilities have been identified with low to critical scores on the CVSS scale. The ZeroLogon AD vulnerability (CVE-2020-1472) scored a 10/10 on the CVSS scale. This vulnerability allows an attacker to compromise the entire domain without even requiring a valid domain credential.
Microsoft regularly releases security patches. Security analysts closely track these vulnerabilities for disclosures, testing, and fix validations. However, deploying a patch and ensuring that the AD infrastructure is always on the latest release is a non-trivial task for any enterprise and leaves the network vulnerable to Active Directory attacks in the interim.
AD Misconfigurations
One of the most powerful Active Directory capabilities is flexible policy constructs. Unfortunately, this also is one of its biggest security drawbacks. User provisioning, computer/server management, groups management, ACLs, ACEs, GPOs, attribute populating for multiple object types are managed using various scripts and native methods for administration, such as PowerShell.
Although administration scripts provide a lot of flexibility, they create a high level of management complexity in the environment. As complexity grows, it causes numerous unknown dependencies and security misconfigurations.
Such misconfigurations can create security holes and widen the attack surface. The issue is compounded by the fact that these misconfigurations are hard to find and fix. They can also lead to undesired exposure.
Availability of Advanced Tools
Over the last few years, the cybersecurity community has made many technological advances in developing open-source Red Team tools. While these tools have been very beneficial for security teams, attackers have also adopted these tools which they can use to attack the Active Directory.
BloodHound, PowerSploit, MetaSploit, Mimikatz, Hashcat, Rubeus, ADRecon, Kekeo, DeathStar, PowerView, and many others are relatively easy to obtain. A tool like BloodHound can be used to very quickly discover relationships between various entities in the domain and calculate the shortest path between entities.
In addition to these open-source tools, attackers often use Living-off-the-Land (LotL) techniques by employing tools like Windows PowerShell, which are already available on endpoints and servers in the enterprise network. This approach helps attackers evade detection and stay hidden in the network for a long time.
Living-off-the-land movement and why it is hard to judge
Yes. Deception detects living-off-the-land activity because a decoy account, share, or credential has no legitimate purpose. The interaction itself is the signal, regardless of which native utility the attacker rides in on.
PowerShell and the other native utilities named above ride on legitimate administrator credentials, so distinguishing an attacker’s session from routine administration means correlating context: time of day, source host, command history, account baseline. That correlation gets harder as the estate grows and administrative activity multiplies across scripts, service accounts, and scheduled tasks. A 360 Deception decoy sidesteps the problem entirely. No legitimate account or process has any reason to touch it, so any interaction is inherently suspicious, independent of which tool executed it.
What are some common AD Attack Surface Vulnerability Exploits?
The following examples show how attackers can leverage and exploit specific AD elements and vulnerabilities to carry out Active Directory attacks.
Upgrade Deferral
An enterprise often runs critical applications, non-Windows servers, and systems that have been configured through older AD versions. Since an upgrade will be a huge task, Administrators may choose to defer even a recommended AD upgrade. This gives attackers a chance to exploit known vulnerabilities in the AD.
Over-Privileged Accounts
As user roles change, user accounts are given privileges by adding their accounts to groups such as the Domain Administrators and Enterprise Administrators groups. These privileges are not always withdrawn when they are no longer applicable. Attackers look at such accounts as prime targets for compromise.
Additional Domain Controller Apps
A Domain Controller (DC) sometimes runs additional applications and utilities unrelated to Active Directory. These applications and utilities significantly add to the AD attack surface by requiring configuration settings that open ports, access users who should not be connected to the DC, and create high-privileged service accounts.
Users often use a high-privilege account to log in to a DC and then use the same account, for example, to access the Internet and download freeware utilities. If such an account is compromised, attackers gain direct access to the DC.
Configuration Changes
Constant changes in AD object configurations may also lead to a transient attack surface and make Active Directory protection more difficult. In such situations, a dormant, persistent threat can exploit these for attack progression.
Patch Management Gaps
An enterprise may have gaps in its patch management systems and processes. Non-Windows operating systems, commercial applications, and networking devices may get patched only sporadically.
Patching that is incomplete or terminates with errors may not be reviewed and rectified. Since all assets are managed in the AD, any poorly patched asset that is compromised gives attackers a path to Active Directory attacks.
Outdated Antivirus Protection
Antivirus and antimalware software in server subnets may be misconfigured or outdated. Attackers can exploit these weaknesses to compromise a server, gain a foothold in the network, and reach the AD.
Legacy Protocol Risks
An enterprise may configure the AD to store LAN Manager hashes or reversibly encrypted passwords to support legacy authentication protocols. Attackers can employ standard methods to crack these passwords and gain access, weakening Active Directory protection.
How automation changes attack surface exploitation
Stopping machine-speed credential testing means detecting the first touch, not the pattern. Agentic tooling now enumerates AD objects, tests credentials, and chains privilege escalation paths at a speed and breadth no human operator could sustain manually, the kind of compression Acalvio has documented in a recent AI-orchestrated cloud exploit that reached administrative access in under ten minutes. The technique itself is not new: Kerberoasting, over-privileged account abuse, and misconfiguration exploitation are the same credential access and privilege escalation techniques MITRE ATT&CK catalogs. What changes is the window. An attacker working by hand might probe a handful of accounts overnight; an agentic process can test thousands before a SOC analyst reviews the first alert. Correlation-based detection, built to notice patterns over time, strains against that compression. A control that fires the moment a decoy account or credential is touched does not need the pattern to accumulate. It needs one contact.
How to monitor and reduce the AD attack surface
Monitoring the AD attack surface is a continuous discipline, not a once-a-year audit. Every new account, delegation, and service ticket reopens the map drawn above, so a point-in-time review is stale before the report is read.
A monitoring capability should surface the paths attackers actually walk: shadow admins, accounts privileged through nested group inheritance or a forgotten delegation rather than direct Domain Admins membership, so they rarely surface in an access review; over-permissioned delegations left over from a project or migration; and Kerberoastable service accounts running with weak or unrotated passwords. Delegations sprawl in particular compounds quietly, because each grant looks reasonable in isolation.
Reduction and detection are separate jobs. Closing a delegation does not tell a team whether an attacker is already inside; a decoy fired the moment it is touched does, the same deception-based identity threat detection and response principle applied at the credential layer. The ShadowPlex Preemptive Cybersecurity Platform pairs both: ShadowPlex InSights builds this attacker’s-eye view passively, without domain admin rights or agent deployment, an important distinction when the asset under assessment is Active Directory itself. Learn how ShadowPlex maps and protects the AD attack surface.
Next Steps
Identifying all the elements and factors that make up the AD attack surface is the first step toward Active Directory protection. But this is a challenging task for security teams because the attack surface is constantly changing and expanding.
Given the central function of the AD, managing and minimizing its attack surface is not just a security responsibility, it requires cross-functional collaboration and commitment to AD attack surface monitoring and minimization.
A single compromised account rarely ends there. Decoding Active Directory attack paths to high-value targets traces how attackers chain that first foothold, through this attack surface, into escalation and lateral movement toward their real objective.
Request a 360 Deception Attack Path Assessment to map which attack paths this attack surface leaves open.
Frequently Asked Questions
The Active Directory attack surface comprises all infrastructure elements, vulnerability vectors, and other factors in the AD ecosystem that attackers can use to enter, traverse through, or exit from the enterprise network.
Understanding and mapping out the AD Attack Surface is the first step towards Active Directory security. Defense teams can use this information to mitigate vulnerabilities and preemptively reduce the attack surface.
In any enterprise, with continuous growth and restructuring, there is a complex and evolving ecosystem of users, computers, groups, GPOs, and other objects. This makes Microsoft Active Directory security very complex. Management blind spots, misconfigurations, inconsistent application of the latest patches, over-permissioned accounts, and inadequate access controls in the AD present significant security risks.
Attackers leverage several tools that were originally developed as Red Team tools for security teams. Tools such as BloodHound, PowerSploit, MetaSploit, Mimikatz, Hashcat, Rubeus, ADRecon, Kekeo, DeathStar, PowerView, and many others are relatively easy to obtain and can be leveraged to attack the AD.
The list of some common Active Directory attacks includes the following:
- Kerberoasting
- AS-REP Roasting
- Unconstrained Delegation Computer Attacks
- Recon Attacks
- DCSYNC
- Azure AD Connect Attacks
- ADFS/Golden SAML Attacks
Continuous assessment treats the AD attack surface as a moving target, rescanning as accounts, delegations, and service tickets change, rather than relying on a periodic audit that is stale before it is read. An effective monitoring capability surfaces shadow admins, over-permissioned delegations, and Kerberoastable service accounts, the specific paths attackers use to escalate privilege and move laterally.
Yes. Deception does not need to identify which native utility an attacker is riding in on. A decoy account, share, or credential has no legitimate purpose, so any interaction with it is inherently suspicious regardless of the tool used to reach it.
