惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
IT之家
IT之家
博客园_首页
博客园 - 【当耐特】
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
G
Google Developers Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
GbyAI
GbyAI
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
I
InfoQ
H
Help Net Security
T
Tailwind CSS Blog
B
Blog RSS Feed
Martin Fowler
Martin Fowler
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
博客园 - 叶小钗
雷峰网
雷峰网
量子位

The Duo Blog

Duo Vs Okta IAM identity comparison | Cisco Duo Cisco Duo for education: identity security | Cisco Duo Identity security priorities for 2026 [CISO report] | Cisco Duo What is FedRAMP High Class D? Duo Federal, explained | Cisco Duo Authentication protocols compared: SAML, OAuth 2.0, OIDC | Cisco Duo Identity orchestration & cloud-native IAM: Time to rethink | Cisco Duo Active Directory security: how to stop modern threats | Cisco Duo Duo + PlainID: Dynamic Authorization Meets Enterprise Identity | Cisco Duo Continuous identity security explained | Cisco Duo Salesforce The modern MFA toolkit: push, biometrics, and security keys | Cisco Duo Cisco Duo Identity Summit Preview | Cisco Duo Duo Brings Identity and Authorization Across AI Agent Gateways | Cisco Duo Passwordless for Microsoft 365 starts with federation Custom Admin Roles: Granular control for every Duo admin Token theft, vendor abuse, and the new identity threat surface How Duo Directory automates user lifecycle management Cisco Systems Named a Customers’ Choice in Gartner Peer Insights™ 2026 Voice of the Customer for Access Management Identity provider resilience: backup and split IdP approaches | Cisco Duo Agentic AI Security: Three Threats Your Team Should Know | Cisco Duo Secure client access at scale with Duo and Meraki | Cisco Duo IdP Concentration Risk: Why Single-IdP Dependency Puts You at Risk | Cisco Duo Endpoint Management as an Attack Vector: Lessons from Stryker | Cisco Duo Passwordless authentication without cookies: Duo Push updates Introducing Duo Agentic Identity Solving the double prompt: Better UX with AMR in Duo SSO Simplify compliance with MFA, device trust, and policies Cisco Systems Named a Customers’ Choice in Gartner® Peer Insights™ 2026 Voice of the Customer for User Authentication Why identity-led security matters for MSPs right now The Hitchhiker’s Guide to Shibboleth
Active Directory security: Why CISOs can’t walk away | Ci...
Katherine Yang · 2026-09-01 · via The Duo Blog

Product & Engineering

Why Active Directory is the identity problem CISOs cannot walk away from

Headshot of Katherine Yang, Product Marketing Specialist

8 minute read

Today's security leaders often find themselves stuck between a rock and a hard place: Active Directory (AD) continues to be a foundational legacy infrastructure (in fact, 90% of the Fortune 1000 still uses AD) but inherent technical debt, visibility gaps, and an inability to extend MFA to these legacy authentication paths have created a serious security gap that enterprising threat actors are actively targeting.

Cisco recently surveyed 28 CISOs from around the world to better understand their concerns about the AD security dilemma. The consensus is that it would be impractical to walk away from AD despite the inherent security risks—forcing them to implement new security strategies and controls that harden this legacy identity infrastructure.

For a comprehensive dive into all our conversations, visit our CISO Perspectives homebase. Here's how security leaders are securing their legacy identity infrastructure for modern architectures.

Organizations can't walk away from AD

The 28 security and IT leaders surveyed in the Cisco report are clear on one point: AD is a foundational infrastructure that they cannot walk away from despite inherent security challenges. So, rather than replace AD, CISOs and their teams are having to harden AD by strengthening the security controls around the legacy authentication infrastructure, making it hard for today's threat actors to exploit known vulnerabilities to gain access and move laterally across the network.

"AD has been in place for 20 years and it’s got 20 years of stuff. People are trying to move away from it, but I don’t know anyone who has. The problem is that there's been so many hands inside of AD that nobody wants to touch what other people did because it’s indecipherable. You end up with foundational pieces built into AD that might not be implemented properly. And, unfortunately, you drag that baggage with you."

-CISO, ecommerce transportation company

Backbone of authentication protocols

These foundational identity systems, passed from owner to owner and relying on older protocols, grow in complexity while inherently lacking security controls like visibility and MFA. Attackers take advantage of these blind spots in the heart of enterprise access, ripe with misconfigurations and accumulated tech debt. So, why not replace AD with newer cloud-based IdP options that are better aligned with today’s modern networks?

It's not that simple. Mandy Andress, now the CISO at AI search company Elastic, has been on both sides of the AD dilemma. In past roles, AD was central to her organizations' identity management strategies—ensuring users had fast, reliable access to resources.

However, in her new role at Elastic, AD was never implemented because it is a new company that didn't inherit legacy identity infrastructure. Andress was able to build the company's identity strategy from scratch, forgoing the Microsoft identity standard in favor of more flexible cloud-based IdP options. While CISOs would love to rip and replace AD, that’s just not practical for established organizations with decades of legacy infrastructure.

"Active Directory has been this backbone of identity for decades, and it would be a significant challenge to remove AD from an existing organization where it is embedded in the network architecture," Andress said. "It would be very, very, very hard—if not impossible—to make that shift."

The reality is that AD isn't going anywhere, and CISOs are under pressure to come up with reliable and efficient ways to defend the vulnerable identity infrastructure.

The Active Directory attack landscape in 2026

The combination of its ubiquitous nature inside legacy infrastructures and the inherent security gaps that often remain unaddressed has made AD a tempting target for today’s threat actors. In fact, 44% of identity-related attacks target AD today, using a variety of tactics and techniques specifically designed to exploit the visibility gaps that exist in the legacy authentication protocol.

Here is a rundown of the most common attack techniques targeting AD:

Kerberoasting is a post-exploitation attack technique that targets service accounts in AD. It exploits the way the Kerberos protocol handles authentication to steal password hashes, which are then cracked offline to gain unauthorized access and escalate privileges. This type of attack does not exploit a software "bug" but rather abuses the legitimate design of the Kerberos protocol, typically using phishing to gain initial access to the network through a low-privileged domain user account. This stealthy attack gives the attacker the "keys to the kingdom" that they can then use to escalate their own privileges and move unfettered across the network. Since the exploit relies on the fundamental way Kerberos was designed and subsequent hacking happens offline on the attacker's own hardware, no logs on the corporate network are created and observable activity looks like legitimate behavior.

A Pass-the-Hash (PtH) attack is a method where an attacker steals a hashed user credential and uses it to create a new authenticated session on the same network, bypassing the need for the user's plaintext password. This access allows the attacker to jump from machine to machine, harvesting additional hashes until they find a Domain Admin or high-privileged account. While Kerberoasting involves cracking a service ticket hash offline to find a password, PtH allows an attacker to use the hash directly as a functional equivalent to a password.

An NTLM Relay attack is a sophisticated Man-in-the-Middle (MitM) technique where an attacker intercepts an authentication attempt from a victim and relays it to a target server. It works by exploiting the three-way "Challenge-Response" handshake used by the NTLM protocol, granting the attacker an authenticated session that gives them the same permissions as the victim on the server, allowing them to install malware or dump more credentials. Unlike PtH, where you steal a stored hash to use later, an NTLM Relay attack happens in real-time. The attacker doesn't need to crack a password or even possess a stored hash. They simply act as a transparent proxy for a legitimate authentication session.

Why Active Directory is vulnerable

Common attack methods are just the beginning of AD vulnerabilities. Less publicized are the challenges unmonitored technical debt can lead to.

The visibility and complexity problem

Most organizations have less-than-ideal visibility into what's in their Active Directory, and that’s a serious problem. After all, it's hard to protect what you can't see.

"Legacy authentication systems like AD are filled with visibility gaps that prevent you from knowing what is going on in your environments," said Nigel Miller, deputy CISO of Maximus. "They provide certain level of access, but you don't really know what that access is and why it may pose a risk."

Years or decades of piecing together disparate AD groups have led to growing technical debt and a rising total cost of ownership. The consequences of these visibility gaps are dormant accounts, over-privileged service accounts, old admin identities, and potential identity drift between on-premises AD and cloud-based IdP protocols. However, it's rarely a priority to achieve continuous visibility of these until it’s too late and a gap is exploited.

To comply with rising security needs, organizations are forced to configure complex workarounds or juggle costly point solution trade-offs.

The compliance and insurance problem

The AD dilemma isn't just about a lack of visibility and complexity. It's also about the mounting pressure from auditors. Increasingly rigid regulations and insurance requirements demand complete security coverage and reportable visibility—especially for privileged and non-human identities. 

"We have the behavior analytics, we have all those tools that are able to attribute who’s doing what to see what is and is not normal and alert and auto-respond. It's the regulatory compliance side that keeps me up at night because they're coming back next year, and they're going to look at this area very closely."

-CISO, regional bank

What modern AD defense looks like

Hardening AD infrastructures is critical to a security-first identity strategy. Here are five tips to get started:

  1. Treat AD as a contemporary attack surface: AD is not going anywhere. Organizations need to acknowledge this first and make a commitment to hardening AD infrastructures as much as their cloud apps—especially given the increased scrutiny of privileged NHI.

  2. Close the visibility gap first: You cannot defend what you cannot see, and most organizations cannot see what's hidden in their on-prem IdPs. Gain visibility into AD infrastructures in conjunction with cloud providers, adding identity security posture management that discovers identity drift, dormant service accounts, over-privileged accounts, and other potential misconfigurations.

  3. Extend MFA to legacy Kerberos and NTLM authentication paths: MFA is an essential security control—and many regulations and insurance premiums require complete coverage. Inserting MFA at the domain controller-level can protect custom or legacy applications that rely on authentication flows without native MFA support.

  4. Audit privileged accounts more aggressively: Over-privileged accounts are the highest-leveraged attack target—for good reason. Breach these, and you have the "keys to the kingdom" that allow you to move laterally across the environment.

  5. Plan for hybrid identity, not AD replacement: The realistic path in 2026 is defending, hardening and modernizing AD infrastructure that is already in place.

Go deeper into CISO Perspectives

AD has emerged as a tempting target for modern threat actors. CISOs from around the world are under pressure to harden AD infrastructure security, using new technologies and solutions to close the visibility gap, reduce complexity, and improve defenses against today’s threat actors.

In the meantime, check out how Cisco Duo can help harden AD infrastructures while reducing technical debt with Active Directory Defense.