P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Identity

Directory service (Active Directory): what it is and how it is attacked

The system that holds every account and computer, and decides what each one is allowed to do.

Also known as

  • Active Directory
  • AD
  • DC
  • LDAP
  • domain controller
  • staff directory
  • identity store

Typing any of them into the editor finds this object.

Why it matters on a security diagram

Control of it is control of the whole estate, which is why it is the usual objective of an intrusion.

How it gets attacked, and what reduces it

How it gets attacked

  • Escalating from an ordinary account to an administrative one
  • Old accounts and permissions nobody removed

What reduces it

  • Tier administrative accounts so an ordinary workstation compromise cannot reach a domain administrator
  • Review delegated permissions, which accumulate into a path to full control nobody granted deliberately
  • Protect backups and replicas as strongly as the live system, since the account database can be taken from either

Where it sits

Group
Identity · Who something claims to be, and what proves it.
Whose side, by default
Ours · Belongs to the organisation the diagram is about.
Catalogue identifier
directory

Reviewed . CC BY 4.0.

Others in identity

The identity group lists all 6 of them side by side.

Directory service on your own diagram

Open the editor, press N, and type Active Directory. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.

Open the diagram maker