Skip to content
← All insights
Research1 min read

Certificate services are now the shortest path to domain admin

Active Directory Certificate Services is deployed almost everywhere and reviewed almost nowhere. On internal engagements it is consistently the fastest route from a standard user account to full domain control.

Most internal network assessments still open with Kerberoasting and password spraying. Those still work often enough to be worth running, but on a reasonably maintained estate they increasingly do not. Certificate services do.

Why it keeps working

Active Directory Certificate Services is installed as a matter of course — it underpins smartcard logon, machine authentication, VPN and internal TLS — and then it is left alone. It sits outside the patch conversation because there is usually nothing to patch: the exposure comes from template configuration, not from a missing update.

A certificate template that permits the requester to supply their own subject, allows client authentication, and can be enrolled by ordinary domain users is enough. An attacker holding any standard account requests a certificate naming a domain administrator, and authenticates as one. There is no exploit and no malware — the request is valid, and the CA answers it exactly as configured.

What to check

  • Which templates allow the enrollee to specify the subject alternative name.
  • Which of those permit client authentication or smartcard logon.
  • Who holds enrollment rights on each — Domain Users appears here far more often than anyone expects.
  • Whether manager approval is required, and whether that requirement is actually enforced.
  • Permissions on the CA object itself, and who can alter template configuration.

The uncomfortable part

This is not obscure. The template abuse classes have been publicly documented since 2021 and the tooling to find them is mature and free. What makes it reliable on engagements is not novelty — it is that certificate services rarely sit inside anyone’s scope, so nobody has looked.

If your last internal test did not name your certificate templates, it did not cover this. That is worth asking your previous assessor about before you commission another one.

  • Active Directory
  • ADCS
  • Privilege escalation