Overview
Curated: · Written: · Reviewed:
Operate the directory as a security-critical distributed database
LDAP is a protocol for accessing directory entries; Active Directory Domain Services is a directory platform that combines LDAP-compatible access with domains, forests, schema, replication, Kerberos, DNS dependencies, group policy, and Windows security semantics. Neither “LDAP” nor “AD” is itself an application login strategy. Applications must decide how they authenticate, locate a stable user, map groups or attributes, establish a local session, authorize each resource action, and handle disablement or directory outage.
Model entries in a directory information tree using schema-governed object classes and attributes. A distinguished name locates an entry in the tree but can change when the object is renamed or moved; use a stable immutable identifier for application correlation. Define naming, normalization, case, multi-valued attributes, required fields, uniqueness, and lifecycle. Organizational units are administrative and policy containers, not automatically business authorization roles.
Secure LDAP transport and authentication. Anonymous or simple binds may be acceptable only in narrowly designed cases; a simple bind carries a reusable password and requires confidentiality protection. Validate the server certificate and expected identity, define StartTLS downgrade behavior, and require signing or channel binding where applicable. Prefer federated or Kerberos-integrated authentication for applications rather than collecting a directory password. Never use a highly privileged directory bind account merely to search public profile attributes.
Construct LDAP filters with a library and escape assertions according to filter syntax. Distinguished-name escaping is different from filter escaping; SQL parameter rules do not apply. Restrict search base, scope, requested attributes, result size, time, paging, dereferencing, and referral behavior. Normalize but do not concatenate attacker input into filters or DNs. LDAP injection can change the search meaning and return or authenticate an unintended entry.
Authorization needs effective group semantics. Direct member attributes may omit nested membership, dynamic groups, primary group behavior, foreign principals, or target-specific expansion. Nested groups can hide transitive privilege and cycles; token or query limits can produce incomplete answers. Keep privileged groups small, owned, monitored, and separated from ordinary collaboration groups. Applications should fail safely when group resolution is partial rather than treating “lookup error” as “administrator.”
Kerberos uses a trusted key distribution center to issue time-bounded tickets for service principals. Service principal names, DNS, time synchronization, encryption types, delegation configuration, and key lifecycle all matter. A service ticket authenticates a principal to a service; the application still enforces authorization. Constrained delegation must limit which front end may act toward which back-end service. Unconstrained or broadly configured delegation turns compromise into lateral movement.
Active Directory is replicated and multi-master for most data, so a successful write on one domain controller does not mean every reader immediately observes it. Design for convergence, site and link topology, domain-controller discovery, replication health, conflict behavior, and read-after-write needs. Security-sensitive disablement has an end-to-end propagation objective that includes sessions, tickets, tokens, application caches, and disconnected systems. Replication success is not session revocation.
Protect domain controllers and directory administration as crown-jewel control planes. Separate standard and privileged identities, minimize standing membership, use hardened administrative hosts, phishing-resistant authentication, JIT/JEA where supported, protected service identities, strict delegation, patching, and independent monitoring. Control who can change schema, replication, trusts, certificate services, identity federation, group policy, privileged groups, DNS, backups, and audit configuration. Directory administrators can often manufacture authority elsewhere.
Service and workload identities need owners, purpose, hosts, allowed services, effective privilege, credential type, rotation, expiry, and retirement. Prefer managed service accounts or workload identity to static shared passwords. Prevent interactive sign-in when unnecessary, restrict delegation and SPNs, rotate keys without outage, and find dependencies before removal. A password rotation that breaks production encourages permanent exemptions; an over-broad service account remains dangerous even if rotated daily.
Recovery must assume compromise, not only hardware loss. Maintain known-good system-state and required supporting backups, isolate recovery credentials and media, document forest and domain recovery order, practice in a separated environment, and validate DNS, time, replication, trusts, SYSVOL, authentication, and privileged objects before reconnecting. A restored controller or directory backup may resurrect deleted accounts, stale group memberships, old keys, or attacker persistence; reconcile against trusted evidence.
Measure bind and search failures, unsigned or weak authentication, certificate expiry, privileged group and ACL changes, replication latency and failures, stale controllers, time skew, ticket anomalies, delegation and SPN changes, dormant and ownerless service accounts, nested effective privilege, directory-to-application revocation latency, backup age, restore success, and recovery exercise findings. A disabled account whose Kerberos TGT still authorizes a service for eight hours is not contained. Test injection, certificate mismatch, StartTLS failure, referral escape, nested-group limits, duplicate names, rename, replication partition, KDC outage, clock skew, ticket replay, service-key rotation, DC compromise, backup restoration, and application behavior when directory evidence is incomplete.
