Active Directory Penetration Testing
Also known as:AD Pentest · AD Penetration Test
Active Directory Penetration Testing is an authorized security assessment focused on Microsoft Active DirectoryActive DirectoryMicrosoft directory service for the centralized management of identities and resources. environments — forests, domains, trusts, group policies, certificate services, and the authentication protocols that underpin enterprise identity management. The objective is to identify misconfigurations, weak permissions, and attack paths that could allow an adversary to escalate from an unprivileged domain user to Domain AdminPrivilege EscalationObtaining higher privileges than originally intended. or equivalent control over the environment.
Because Active Directory is the backbone of authentication and authorization in most enterprises, a single misconfiguration can cascade into full domain compromise. AD pentests systematically map these risks using the same techniques real attackers employ — KerberosKerberosTicket-based protocol for secure authentication in insecure networks. abuse, credential harvesting, delegation attacks, and certificate exploitation.
Who commissions this test?
AD penetration tests are typically commissioned by CISOs, IT directors, internal audit teams, or compliance departments in enterprises that rely on Active Directory for identity and access management. The request often arises during regulatory compliance programs (ISO 27001, SOC 2, PCI DSS), after a security incident involving credential compromise, or as part of due diligence during mergers and acquisitions where AD forests need to be evaluated before trust relationships are established.
Test objectives
The primary objective is to determine how far an attacker with initial domain access — such as a compromised employee workstation — could escalate privileges within the AD environment. This includes mapping all viable attack paths from standard user to Domain Admin, identifying accounts and configurations vulnerable to known attack techniques, evaluating the effectiveness of detective controls (SIEM rules, EDR alerts), and assessing whether existing hardening measures hold up under adversarial pressure.
What is tested?
Testing covers the full AD attack surface: domain controllersDomain ControllerServer running Active Directory Domain Services that replicates directory data and supports authentication and authorization for a domain. and their configurations, forestActive Directory ForestTop-level Active Directory structure whose domains share a schema, configuration, global catalog, and mutual trust foundation. and trustActive Directory TrustRelationship allowing identities from one Active Directory domain or forest to be authenticated in another security domain. architectures, groupActive Directory GroupDirectory object used to assign permissions collectively or to form email distribution lists. memberships and nested group chains, Group Policy Objects (GPOs) and their permissions, Kerberos configuration (SPNs, delegation settings, encryption types), NTLM authentication behavior, LDAP signing and channel binding, AD Certificate Services (AD CS) templates and enrollment permissions, DNS configurations (AD-integrated DNSActive Directory-Integrated DNSDNS zone model in which zone data is stored in Active Directory, replicated, and protected through AD permissions.), replicationActive Directory ReplicationMulti-master synchronization of directory changes between domain controllers with partition, site, and conflict handling. permissions, LAPS deployment, password policies, and service account hygiene.
Common findings
- Kerberoastable service accounts — SPNs set on accounts with weak passwords, allowing offline cracking of their Kerberos TGS tickets
- AS-REP roastable accounts — Accounts with Kerberos pre-authentication disabled, enabling offline password attacks
- Excessive Domain Admin memberships — Service accounts, shared accounts, or former administrators still in privileged groups
- Unconstrained delegation — Servers configured to impersonate any user to any service, enabling token theft
- AD CS misconfigurations (ESC1 through ESC8) — Overly permissive certificate templates allowing low-privileged users to request certificates for privileged accounts
- NTLM relay opportunities — Missing SMB signing, LDAP signing, or EPA enforcement enabling credential relaying
- Weak GPO permissions — Non-admin users able to modify group policies applied to privileged systems
- Stale privileged accounts — Dormant accounts with elevated rights that were never deprovisioned
- Missing LAPS — Local administrator passwords identical across workstations, enabling lateral movement via Pass-the-HashPass-the-HashAuthentication attack that uses a stolen hash instead of the plaintext password.
- DCSync-capable accounts — Non-DC accounts with replication permissions, allowing extraction of all password hashes
- LLMNR/NBT-NS poisoning — Name resolution fallback protocols enabling credential interception on the local network
- BloodHound attack paths — Multi-hop privilege escalation chains through group memberships, ACLs, and session data that are invisible without graph analysis
Typical engagement workflow
Initial inquiry — The organization contacts the pentest provider, motivated by compliance requirements, an upcoming audit, a recent incident, or an AD migration project. Basic information about the AD environment size (number of domains, forests, users, sites) is gathered.
Scoping conversation — A detailed discussion with the IT security team, AD administrators, and stakeholders to understand the AD architecture, existing hardening measures, monitoring capabilities, and specific concerns. The testing approach (Black-Box from a domain user perspective, Gray-Box with partial information, or White-Box with full documentation) is agreed upon.
Proposal and approval — A formal proposal specifies the assessment methodology, tools to be used, expected duration, and any limitations. The proposal is reviewed by IT management, legal, and security leadership.
Scope definition — Target domains, forests, trusts, and specific systems (domain controllers, AD CS servers, ADFS servers) are documented. Exclusions (production-critical servers, specific accounts) are noted. Test account credentials and network access are defined.
Letter of engagement — Signed authorization that covers legal protection, defines the rules of engagement, specifies escalation procedures for critical findings (e.g., an active compromise discovered during testing), and lists emergency contacts.
Additional authorizations — If Azure AD / Entra ID hybrid environments or cloud-connected components are in scope, relevant cloud provider testing policies are addressed.
Information exchange — Based on the agreed approach, the client provides domain architecture documentation, network diagrams, a standard domain user account, and potentially access to AD administrative tools or read access to AD for White-Box assessments.
Kick-off call — Final alignment with AD administrators, security operations, and the pentest team. Communication channels, working hours, and the handling of disruptive tests (e.g., account lockouts from password spraying) are confirmed.
Execution — Testing follows a structured kill chain: enumeration of the AD environment (BloodHound collection, LDAP queries, SPN scanning), identification of quick wins (Kerberoasting, AS-REP roasting, credential harvesting), exploitation of misconfigurations (delegation abuse, ACL attacks, GPO manipulation, AD CS exploitation), lateral movement (Pass-the-HashPass-the-HashAuthentication attack that uses a stolen hash instead of the plaintext password., Pass-the-TicketPass-the-TicketMisuse of stolen Kerberos tickets to assume an identity., session hijacking), and privilege escalation toward Domain Admin. Stakeholders are kept informed of progress, and critical findings are reported immediately.
Vulnerability assessment and rating — Findings are documented with full attack chains, rated by severity and exploitability, and mapped to industry frameworks (MITRE ATT&CK, ANSSI AD hardening guide).
Final report — A comprehensive report provides each finding with technical proof, the attack path exploited, affected objects, and specific remediation steps including PowerShell commands or GPO changes where applicable.
Presentation — Results are presented to security leadership, IT management, and AD administrators. The presentation walks through the most impactful attack chains and prioritizes remediation.
Project closure — Remediation timelines are agreed, and recommendations for ongoing AD security monitoring and periodic reassessment are provided.
Who should commission this test — and when?
Every organization that uses Active Directory for identity management — which includes the vast majority of enterprises — should periodically assess its AD security posture. AD pentests are especially important after AD migrations or forest/trust restructuring, before and during mergers and acquisitions (where AD trusts will be established between formerly separate organizations), following the deployment of AD Certificate Services, after significant changes to GPOs or delegation models, and as part of annual security assessment cycles.
Regulatory frameworks including ISO 27001, PCI DSS, and SOC 2 increasingly expect evidence that identity infrastructure has been tested. Organizations that have experienced phishing or ransomware incidents should prioritize AD assessment, as these attack vectors frequently lead to AD-based privilege escalation.
Related concepts
- Active DirectoryActive DirectoryMicrosoft directory service for the centralized management of identities and resources.: Microsoft’s directory service for enterprise identity and access management.
- KerberosKerberosTicket-based protocol for secure authentication in insecure networks.: The authentication protocol used by Active Directory for ticket-based single sign-on.
- Pass-the-HashPass-the-HashAuthentication attack that uses a stolen hash instead of the plaintext password.: A lateral movement technique using captured NTLM hashes to authenticate without knowing the plaintext password.
- Pass-the-TicketPass-the-TicketMisuse of stolen Kerberos tickets to assume an identity.: A technique that reuses stolen Kerberos tickets to impersonate authenticated users.
- Privilege EscalationPrivilege EscalationObtaining higher privileges than originally intended.: Gaining higher-level permissions than originally granted, often the central objective of AD pentesting.
- Penetration TestingPenetration TestingAuthorized, methodical testing of a system for exploitable weaknesses, to find them before real attackers do.: Authorized, methodical testing of systems for exploitable weaknesses.
- Domain ControllerDomain ControllerServer running Active Directory Domain Services that replicates directory data and supports authentication and authorization for a domain.: The server that authenticates users and enforces security policy in an AD domain.