Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Directory & tiering

Hardening Active Directory

An Active Directory is rarely designed: it accumulates. Twenty years of one-off delegations, service accounts created to unblock something, and group memberships never reviewed end up drawing paths nobody intended. Here is how we close them.

The challenge

It is not a flaw, it is an accumulation

In an internal penetration test the scenario repeats itself: an ordinary office workstation, a service account whose password has not changed in years, a forgotten delegation — and domain administration falls within hours. No vulnerability in the classic sense was exploited: only rights that already existed.

The underlying cause is the absence of separation. When a domain administrator opens a session on a user workstation, they leave behind enough to replay their identity. As long as administration tiers are not separated, every office workstation is a way into the directory.

Our role is to rebuild the real map of the paths, then reduce it in stages: separate the tiers, regain control of service accounts, clean up delegations and protect the directory backups — without interrupting operations.

What is at stake
  • A short path from an office workstation to domain administration
  • Service accounts with high privileges and passwords never changed
  • Delegations and inherited rights nobody can justify any more
  • Administration carried out from ordinary workstations
  • Directory backups reachable from the domain itself
Diagram

Three tiers, no administration across them

Separating administration into tiers T0Control of the directorydomain controllers · PKI · backupsT1Servers & applicationsfiles · databases · line of businessT2Workstationsoffice work · mobilityAttack pathsdelegationsservice accountsACLs & GPOs
Each tier is administered from within itself: a tier 0 account never signs in to a workstation, which removes the shortest path to the directory.
Our approach

How we proceed

We first map what actually exists, then close the paths in order of severity.

01

Mapping the paths

A survey of the real control relationships between accounts, groups and machines — the ones that follow from the rights in place, not from the org chart. This is almost always the most revealing step.

02

Tiering model

Defining the three tiers (directory, servers, workstations), which accounts belong to each, and the sign-in rules that stop an account from descending into the lower tiers.

03

Service accounts and delegations

Inventory, reduction of privileges to the strict minimum, a move to managed accounts where the application allows it, and removal of delegations that no longer have a justification.

04

Dedicated admin workstations

Putting in place workstations reserved for administration, isolated from email and the web, the only ones allowed to carry the most sensitive accounts.

05

Backups and monitoring

Isolating the directory backups outside the domain, a proven restoration procedure, and detection of the behaviour characteristic of an attack on the directory.

Services involved

Several disciplines, a single point of contact

The subject touches architecture, operations and detection; offensive testing serves both as the starting point and as the validation.

Deliverables
  • Map of the attack paths to domain administration
  • Documented tiering model and sign-in rules
  • Inventory of service accounts and delegations
  • Hardening plan prioritised by severity
  • Retest to validate the remediation
Frequently asked questions

Frequently asked questions

Almost never. Rebuilding is long, risky and rarely necessary: most of the gain comes from separation and from cleaning up rights, both of which are done on the existing directory. It is only worth discussing if the domain has already been compromised.

It does change habits: you no longer administer everything from your own workstation. In exchange, teams finally know which account to use for what. We support the transition, because a model that gets worked around protects nothing.

The on-premises directory is almost always still there, and it is then synchronised with the cloud — which extends the attack paths rather than reducing them. Hardening the local directory becomes more important in that case, not less.

Through the map of paths. It is drawn before, then after remediation: the number of paths leading to domain administration, and their length, are concrete figures that stand up to scrutiny.

How many paths lead to your directory?

A map of the attack paths answers that within days, and the answer is almost always a surprise.