Active Directory Identity Security

Identity Security

What is identity security?

As digital identities exploded in the early Internet, criminals noticed that many were poorly secured. Passwords could be easily guessed or stolen via phishing attacks, while many organizations blindly assumed that location was a reliable measure of trust. What emerged was the idea of identity security as the 'new perimeter'. This states that identities are a vulnerability that should be protected with improved authentication, real-time oversight, and a defined lifespan.

Why does identity security matter?

As the number of human and machine identities has expanded, identity has become every organization's biggest attack surface. There is hardly a major cyberattack of the last two decades that hasn't exploited identity compromise as its key pivot, usually by hijacking a privileged identity. It follows that securing identities should be top of the security admin to-do list.

How does Active Directory (AD) implement identity security?

Modern Active Directory security comprises five elements, not all of which are part of AD itself due to its age:

  • Authentication

Verifying that the user is who they say they are, validated using  password credentials, multi-factor authentication (MFA), one-time passcodes, biometrics, or hardware tokens.

  • Authorization

What they are allowed to do once they have authenticated, which involves group permissions, roles, and privileges.  

  • Monitoring

Monitoring user accounts for anomalous behavior relating to authentication, location/IP address,  machine identity,  working hours, connection type, or the number of concurrent connections.

  • Response

How the system responds if something unusual is detected, e.g. blocking access, disabling an account, or asking for additional authentication.

The identity lifecycle

How identities are onboarded into AD and how they are managed should access no longer be required when an employee leaves.

What are the critical elements of AD identity security?

  • Multi-factor authentication (MFA)

Once reserved for the paranoid but now essential to counter password compromise. MFA can be implemented using different factors – onetime passwords, push notification, hardware tokens – each of which balances convenience with security differently.

  • Least privilege

The principle that users should never be granted more privileges than necessary for their job roles.

  • Privileged access management (PAM)

Security controls to monitor and secure powerful and commonly targeted account types such as admins and domain admins.

  • Role-based access control (RBAC)

Assigning access permissions and rights according to a user's job role. For example, users outside a department might be able to view a file but not edit, delete, or move it.

  • Non-human identity management (NHIM)

Despite machine identities outnumbering humans on most networks, they are not always as well monitored as human accounts. NHIM involves the discovery, security, auditing and monitoring of these accounts.

  • Contextual access control

Allowing a user to authenticate after evaluating factors such as location, IP address, time of day, and session type (VPN, RDP, Wi-Fi, IIS).

  • Concurrent session control

The ability of users to open two or more concurrent sessions using the same credentials. Makes it possible for criminals to open a parallel session to a legitimate user using the same credentials amongst other risks.

  • AD group security

A way of giving groups of users access to applications, folders, or printers, usually by domain, without having to manage each one individually. Users acquire access rights by being members of a security group.

Active Directory IAM versus identity security: What's the difference?

AD is a traditional on-premises identity and access management (IAM) database which controls who is allowed to access a Windows network and what permissions and Group memberships they have once they've logged in. However, it was never designed to be an identity security system – in the AD IAM model, security features such as MFA, SSO, and real-time monitoring and account control are provided using separate systems.

In practice, this means that defenders must build layers of security around AD through access and contextual controls, the limiting of concurrent access, privilege management, and real-time alerting.

How easy is it to "harden" Active Directory?

Lists of hardening techniques designed to boost AD security, which in its default state lacks many features now viewed as essential, often run to pages, which underlines the operational complexity of the task. Easy wins include:

  • Disabling legacy authentication and file sharing protocols such as the now highly insecure NTLM v1 and SMB v1.

  • Manage admin passwords more securely using Microsoft's own tool, Windows Local Administrator Password Solution (LAPS). This automates and simplifies the process of securely storing and rotating randomized admin passwords.

  • Service accounts, which often have weak passwords, are a major AD vulnerability. This can be addressed by implementing Group Managed Service Accounts (gMSAs), which automate password management for service accounts across domains.

  • Clean up inactive and old accounts, including service accounts. Audit and clean up GPO permissions using tools like PingCastle or BloodHound to locate non-admin accounts with excessive permissions.

  • Eliminate 'shadow' admins, typically ordinary user accounts that have been granted powerful admin privileges without being added to managed admin groups.

Active Directory identity security challenges and threats

Identity security challenges can be divided into internal (relating to AD itself) and external (the threat of external compromise). Internal problems include poor management over time, for example over-privileged user accounts and identity sprawl which leads to a growth in accounts with limited or no oversight. External threats start with the ever-present danger of credential theft and account takeover, before moving to privilege escalation and lateral movement.

Can AD identity security support Zero Trust?

AD assumes trust based on password credentials, domain membership, and Group policies. The underlying Kerberos Ticket-Granting Ticket (TGT) system has no way of evaluating users once they have been authenticated. This model falls a long way short of modern Zero Trust security.

Bringing AD closer to ZT level requires a mixture of better authentication (MFA) across all connections, the continuous assessment of user behavior, careful management of privileges, and regular auditing of authorization to contain permission privilege sprawl.