Joint Guidance

Detecting and Mitigating Active Directory Compromises

This guidance addresses the most common AD DS, AD CS and AD FS techniques, providing an overview of each technique, as well as how to mitigate it.

PUBLISHED DATE: 16 September 2026

This joint guidance, Detecting and Mitigating Active Directory Compromises, provides an overview of each technique and how it can be leveraged by malicious actors, as well as recommended actions to mitigate these techniques. By implementing the recommendations in this guidance, organisations can significantly improve their Active Directory security and strengthen their overall network security against cyber threats.

Microsoft Active Directory is a core identity and access management system that controls access to critical systems and data, making it a prime target for malicious cyber threats. It acts as an organisation's digital gatekeeper, verifying users, managing permissions, and enabling single sign-on.

Because Active Directory controls access to so many systems, it is a highly attractive target for malicious actors. If malicious actors take control of your Active Directory, they can effectively gain complete control over an organisation’s enterprise IT network. In many cases, they can use the permissions already granted to standard users to investigate the environment, discover weaknesses, and gradually increase their access.

Read the guidance: 

Detecting and Mitigating Active Directory Compromises [PDF, 1.5 MB]

This guidance was co-authored by:

  • U.S. Cybersecurity and Infrastructure Security Agency
  • Australian Signals Directorate’s Australian Cyber Security Centre
  • U.S. National Security Agency’s Artificial Intelligence Security Center
  • United Kingdom National Cyber Security Centre
  • Canadian Centre for Cyber Security