Join our Newsletter — 33% off our NHI Course

What happens when an attacker can combine session 0 access, a logged-in Domain Admin, and NTLM relay on the same Windows host?

The attacker can coerce a privileged COM server into authenticating as the Domain Admin, then relay that authentication to a server they control. That lets a low-privilege user inherit elevated domain rights and, in the demonstrated case, become Enterprise Admin or gain DCSync permissions. The impact is full domain compromise from a single host-side foothold.

How the attack chain turns a single host into domain-wide control

Session 0 access matters because it places the attacker close to privileged Windows services that can be induced to authenticate on the attacker’s behalf. When that local foothold is combined with a logged-in Domain Admin session and ntlm relay, the attacker is no longer just abusing one token. They are using the host itself as a bridge from local execution to trusted domain authority.

The key mechanic is coercion plus relay. The attacker forces a privileged COM or service context to initiate authentication, captures the resulting NTLM exchange, and forwards it to a target that accepts the relayed logon. If the target action is privileged enough, the attacker can translate that borrowed trust into elevated directory rights without ever knowing the administrator’s password.

That is why the demonstrated outcome is so severe: the host-side foothold becomes a path to enterprise-level impact. The attack does not require a classic password dump first. Instead, it abuses the fact that Windows authentication and local privilege boundaries can be chained in ways defenders may not expect when an admin is already logged on.

Why the logged-in Domain Admin changes the blast radius

A logged-in Domain Admin session is valuable because it supplies a live high-privilege security context that can be coerced into authenticating. If that session is present on the same machine the attacker controls, the attacker can turn an otherwise modest local compromise into credential relay against a far more powerful identity. Active Directory and Entra ID Hardening Guide covers why tier-zero exposure and privileged session placement matter so much in Windows environments.

The practical consequence is lateral privilege conversion. The attacker is not simply “moving around” the network. They are converting one host-local compromise into directory trust abuse, which can lead to Enterprise Admin, DCSync capability, or other rights that let them replicate directory secrets and expand control across the domain. That makes the presence of a privileged logged-in user a decisive condition, not just background context.

This is also why service accounts, delegation, and privileged sessions belong in the same defensive conversation. A local attacker needs only one path to reach a privileged identity that can be induced to authenticate. Once that path exists, NTLM relay becomes the amplifier, not the starting point. Service Account Security Guide is relevant here because the same governance problem, over-trusted identities with weak session boundaries, often affects both human admins and non-human accounts.

What defenders should verify before they treat this as contained

The right question is not whether a single host was compromised, but whether that host could reach a privileged authentication context and relay it to something valuable. If a low-privilege user can interact with session 0, privileged COM objects, or auto-elevating services on a machine where an admin is logged in, the containment boundary is already weaker than it looks.

Defenders should verify three things quickly: whether privileged users ever log into workstations they do not control; whether NTLM is still allowed where stronger authentication is possible; and whether local privilege boundaries are protected against coercion of authentication. The 52 NHI Breaches Report is useful background on how stolen or relayed identity material repeatedly turns limited access into broader compromise.

If the answer to those checks is weak, the event should be treated as a domain incident, not an endpoint incident. In that condition, the attacker may already be able to mint new privileged access, force directory replication, or persist with a trust path that survives ordinary local cleanup.

Risk and Threat Considerations

This attack pattern is dangerous because it collapses the boundary between local access and domain authority. The risk is not just privilege escalation on one machine, but the ability to transform a session co-location event into domain compromise, especially where NTLM remains relayable and privileged users are exposed on the same host.

Failure mechanism: A privileged Windows context authenticates on demand, the attacker relays the NTLM exchange to a target they control, and the resulting trust is used to perform actions that exceed the attacker’s original rights.

Impact: The attacker can convert a low-privilege foothold into directory-wide control, including Enterprise Admin level access or DCSync-capable rights, which creates full domain compromise potential from a single host-side intrusion.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
MITRE ATT&CK T1557 — Adversary-in-the-Middle NTLM relay is a classic adversary-in-the-middle credential abuse path.
Recommendation — Detect relay-capable coercion paths and block authentication forwarding opportunities.
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Privileged user sessions and authentication strength determine whether the relay succeeds.
AC-6 — Least Privilege The attack becomes catastrophic when a relayed session inherits excessive rights.
IA-5 — Authenticator Management Credential material and NTLM use are central to the relay and coercion chain.
Recommendation — Require strong authentication for privileged users and restrict where those sessions can occur. Limit privileged access so a relayed logon cannot reach domain-wide authority. Reduce reliance on relayable authenticators and manage credential lifecycle tightly.
ISO/IEC 27001:2022 A.5.15 — Access control This is an access-boundary failure where local control becomes domain authority.
Recommendation — Enforce access boundaries that prevent local footholds from reaching privileged domain actions.

Practitioner Guidance

What to prioritise: Treat logged-in Domain Admin presence on non-tier-zero hosts as an exposure that materially changes the risk profile of the workstation. If those sessions exist, the first priority is reducing where privileged users authenticate, not only hardening the endpoint after the fact.

What to verify: Confirm whether NTLM relay paths are still reachable from that host class, whether COM or service coercion is possible, and whether privileged users are segregated from machines that lower-privilege users can interact with. If you cannot answer those questions confidently, you do not yet have a reliable containment model.

Practitioner takeaway: The decisive control is not just patching the machine, it is preventing local access from being able to hijack a live privileged authentication context in the first place.