Active Directory remains the backbone of identity management for the vast majority of UK businesses. It controls who can access what, manages authentication across the entire estate, and stores the credentials that protect everything from email to financial systems. When Active Directory falls, everything falls with it.
Privilege escalation in Active Directory rarely requires sophisticated exploits. Attackers chain together misconfigurations, excessive permissions, and poor password hygiene to climb from a standard user account to domain administrator. The entire journey often takes less than a day, and in many environments, less than an hour.
How Escalation Happens
Kerberoasting targets service accounts with Service Principal Names registered in Active Directory. Any authenticated domain user can request encrypted service tickets for these accounts, then crack the encryption offline without generating alerts. Service accounts running with weak passwords and domain administrator privileges give attackers the keys to the kingdom through a completely legitimate protocol request.
Unconstrained delegation allows certain servers to impersonate any user that authenticates to them. If an attacker compromises a server with unconstrained delegation enabled, they can capture and reuse the credentials of any user who connects, including domain administrators. This feature exists for legitimate reasons but creates devastating attack paths when applied too broadly.
Group Policy Preferences stored old password data in SYSVOL shares that any domain user could read. Although Microsoft patched this years ago, many organisations never changed the passwords that were exposed. Those credentials, often belonging to local administrator accounts shared across hundreds of workstations, remain valid and exploitable.
William Fieldhouse, Director of Aardwolf Security Ltd, comments: “Active Directory attacks follow predictable patterns. We start with Kerberoasting, check for unconstrained delegation, look for misconfigured group policies, and examine trust relationships between domains. The same paths work in nearly every environment because the underlying misconfigurations are so common. Fixing them requires an Active Directory security review alongside regular penetration testing.”
Defending Active Directory
Set strong, unique passwords on every service account and rotate them regularly. Remove unnecessary Service Principal Names. Disable unconstrained delegation on every system where constrained or resource-based delegation can serve the same purpose. Implement a tiered administration model that prevents domain administrator credentials from ever touching standard workstations.
Regular internal network penetration testing specifically targeting Active Directory reveals the escalation paths that exist in your environment today. Generic network scans will not find Kerberoasting opportunities, delegation misconfigurations, or abusable group memberships. Request testing that explicitly includes Active Directory attack techniques.
AS-REP Roasting targets accounts where Kerberos pre-authentication is disabled. These accounts respond to authentication requests with encrypted data that can be cracked offline, similar to Kerberoasting but requiring no initial authentication. Even a single account with this setting enabled provides an attack opportunity that requires only network access to the domain controller.
Bloodhound and similar Active Directory analysis tools map every relationship, group membership, and delegation path in your environment. Attackers use these tools to find the shortest path from any compromised account to domain administrator. Defenders should run the same analysis proactively to identify and eliminate these paths before an attacker maps them.
If your organisation has not assessed its Active Directory security recently, request a penetration test quote that covers identity infrastructure alongside network and application testing. Active Directory compromise gives an attacker access to everything. Protecting it should be a top priority.