Active Directory Identity Infrastructure

Identity infrastructure

What is Active Directory identity infrastructure?

AD's purpose is to act as a mechanism for managing identities on-premise using a single identity and access management (IAM) database controlling authentication, access control, and centralized governance. This is based on a core of services, protocols, and administrative objects:

  • The identity store

AD's Crown Jewels, the ntds.dit identity database that makes the whole system function, stored by default on a Domain Controller (DC) in the NTDS system root.

  • Authentication protocols

The authentication protocols verify user and device identities and manage network permissions. Originally implemented using the insecure and recently deprecated NTLM, and more recently by the more secure Kerberos.

  • Authorization & Governance Objects

AD's engine room comprising Security Identifiers (SIDs) assigned to users and devices, Organizational Units (OUs), Group Policy Objects GPOs), Security Groups, Access Control Lists (ACLs) .

Why does protecting AD identity infrastructure matter?

If an attacker can compromise AD, they gain huge, initially invisible power over their victim. This makes AD a major security risk, including for organizations heavily invested in hybrid and cloud services where AD can act as an insecure bridge.

Limitations of Active Directory (AD) infrastructure security

AD can be described as a security system in the sense that its purpose is to authenticate users and devices against its internal database. But this definition has limits; once AD has carried out authentication it performs no further checks and user access becomes unconditional. This falls some way short of the modern ideas of security and reflects outdated design assumptions from the era of perimeter security.

Today, AD is brought up to modern standards by implementing MFA authentication, access controls, and privilege management. 

AD's security architecture and hardening

While the binary aspect of AD – users are either authenticated with full permissions without additional monitoring or they aren't – its internal security architecture contains several layers through which admins can still exert control if properly implemented.

Admin tiering

A hierarchy which imposes strict isolation between the Tier 0 which includes enterprise and Domain admins with full Forest and management powers, more restricted Tier 1 which includes Server and Database admins who can manage specific applications, and Tier 2 which covers limited admins roles reside such as helpdesk and IT support.

Privileged Access Workstations (PAWs)

A privileged Tier 0 workstation or laptop used for high-risk tasks in which many interfaces are locked down, and only approved tools will work. The alternative is that admins log into perform tasks from random network machines, potentially compromising cached credentials (Kerberos tickets, password hashes, tokens) later exposed to an attacker should that machine be compromised.

Group Managed Service Accounts (gMSAs)

The gMSA was introduced in Sever 2012, to reform the insecure way service accounts were previously run using standard domain accounts. A gSMA account implements several security upgrades, including automatic password rotation.

Local Administrator Password Solution (LAPS)

Originally released as a separate tool but included natively since 2023, LAPS's primary purpose is to manage and rotate static local admin accounts which attackers target to gain lateral access. Although AD admin accounts are always more valuable that un-rotated workstation accounts, local admin status is often a starting point for wider compromise.

Protocol hardening

Although not an architectural feature, removing components is another dimension of AD security. This begins with insecure legacy authentication protocols such as NTLMv1/2 and SMBv1.

What are the biggest identity infrastructure challenges?

Identity verification

In IAM, identity verification is the process of a user proving they are who they say they are, for example using biometrics. This is critical when users first enter the AD database as part of onboarding.

Identity governance

Describes the rules, policies, and auditing processes that govern the way IAM is implemented inside an organization, also ensuring it meets regulatory requirements.

Hybrid identity security

How identities are security managed across hybrid environments spanning both on-premise AD and cloud Entra ID or equivalents. In hybrid identity, the security risk always depends on the security systems in the weakest environment.

Non-Human Identity (NHI)/Machine identities

Accounts used by a non-human service to automate a process. On most networks they outnumber humans by a large margin and are not always well monitored.

Privilege sprawl

The way that ordinary user accounts acquire temporary privileges over time that are never revoked. As these accumulate across users, numerous hidden backdoors are created that undermine security policies.  An example are shadow admins where ordinary user accounts acquire powerful privileges which are forgotten about and missed from audits.

Securing external Identity Providers (IdPs)

AD integrates with external Identity Providers (IdPs) like Okta, Microsoft Entra ID (formerly Azure AD), Ping Identity, and Google Workspace through federated authentication (for example, SSO) and hybrid synchronization. This becomes a potential security risk  if the connectivity between these environments is not properly secured. Achieving this is challenging because on-premises and cloud systems rely on fundamentally different security designs.

Identity data sovereignty

In larger AD environments, data must be partitioned inside AD to conform to regulations such as GDPR or sovereign cloud requirements in highly regulated sectors. The security challenge arising from this is that managing multiple domains cerates complexity, raising the risk of misconfiguration.

Single sign-on (SSO)

Just as AD emerged to allow users to access multiple resources using a single credential on early LANs, Active Directory SSO does the same job for cloud credentials across different SaaS services. It's a convenience that comes with the downside – stealing that credential gives criminals access to the same systems. This demands protection using MFA and conditional access as a  minimum.