The finding first: in the large majority of hybrid Active Directory and Entra ID environments we assess, a path exists from a standard user account to Domain Admin in three or fewer hops, built entirely from permissions that were granted deliberately. No exploit is involved at any step, which is why no detection tool reports it.
The path is assembled, not exploited
Privilege escalation in a mature directory is rarely a vulnerability. It is an accumulation. Each individual grant was reasonable when it was made; the combination was never reviewed because no single person owns the combination.
- Hop one — a dormant but enabled account with a static password, discoverable through an SPN.
- Hop two — a nested group membership added for a project that finished, never removed.
- Hop three — a delegation configured years ago that grants rights over a privileged object.
Why your SIEM is silent
Exposure is not an event. The delegation in hop three was created once, years ago, and has generated no log line since. When it is finally used, the resulting activity is a legitimately permissioned account performing a legitimately permitted action — indistinguishable from administration.
Detection answers “what happened?”. Exposure management answers “what could happen, and what would an attacker choose first?” They are different questions and most organisations only fund the first.
How many of these paths exist in your environment?
The free Exposure Assessment takes 90 seconds and tells you how likely paths like this are, based on how privilege and stale access are managed in your estate.
What closes it
- Measure the combination, not the components. Findings lists rank by severity; paths rank by reachability. Only the second tells you what to fix first.
- Remove the stale layer. Dormant enabled accounts and orphaned delegations are the cheapest exposure to remove and the most reliably present.
- Make review continuous. An annual audit measures a directory that changes weekly.
- Re-score and prove it. A closure you cannot evidence is indistinguishable from a closure you did not make.
The uncomfortable part
Most teams reading this already suspect a path like it exists. The reason it stays open is not capability — it is that nobody owns finding it, and it produces no alert to force the issue. That is a structural problem, and it is the one exposure management is for.
Written by the CyberDNA identity practice, from assessments run across ANZ enterprise environments.