AD privileges & permissions
TL;DR
Active Directory decides who can do what across a Windows network. A handful of groups and rights are effectively game over if the wrong account holds them, so most of the value is in knowing which ones matter and keeping them to as few people as possible.
What it is
Active Directory (AD) is the directory most Windows networks run on: it holds the users, computers and groups, and domain controllers enforce who can do what. Permissions are what an account can do to a specific object (a file, a group, another user). Privileges (user rights) are broader powers, like logging on as a service or acting as part of the operating system.
The ones that matter
You do not need to memorise everything. A short list of memberships and rights carries most of the risk:
| Group / right | Why it matters |
|---|---|
| Domain Admins | Full control of the domain. The classic target. |
| Enterprise Admins | Control across every domain in the forest. Bigger still. |
| Account / Server Operators | Often overlooked, but powerful enough to be a stepping stone. |
| DCSync (Replicating Directory Changes) | Lets an account pull password data as if it were a domain controller. |
| Unconstrained delegation | A machine that can impersonate anyone who connects to it. |
How to review it
Defending AD is mostly knowing who holds these and shrinking the list:
- Audit the membership of the sensitive groups above, and ask why each account is in there.
- Adopt a tiering model, so admin accounts for high-value systems are not used on ordinary workstations.
- Map the relationships. Tools like BloodHound show, visually, who can reach Domain Admin and by what path.
- Watch the “stepping stone” rights (delegation, DCSync) that are easy to grant and hard to spot.
Reference: Microsoft’s Best Practices for Securing Active Directory.