TL;DR: Active Directory visibility, misconfiguration detection, and governance workflows still need to catch up with sprawl and hidden trust paths, even as Netwrix folds PingCastle into its portfolio to extend AD scanning, including discovery of known and shadow domains and misconfigurations, according to the company.
Editorial analysis by NHI Mgmt Group, based on content published by Netwrix: “Unlock the Power of Netwrix PingCastle: Your Gateway to Enhanced AD Security”.
Key questions
Q: How should teams govern unknown or shadow Active Directory domains?
A: Treat unknown AD domains as unmanaged identity assets until they have an owner, a trust-map, and a review cycle.
Q: Why do misconfigured Active Directory trusts create such a high security risk?
A: A trust extends authentication and resource access across domains, so a weak configuration can expand who can reach sensitive systems.
Practitioner guidance
- Map every AD domain and trust relationship Establish a complete inventory of known and unknown or shadow domains, then validate how each domain participates in authentication, delegation, and trust inheritance.
- Tie scan findings to remediation owners Assign each misconfiguration or exposure to a named team, with a tracked remediation path and evidence of closure for audit and recertification.
- Review privileged group nesting and delegation Look for nested groups, inherited admin rights, and legacy delegation that extend access beyond current business need or expected administrative boundaries.
Bottom line: Active Directory risk rises sharply when domains or trust paths exist outside the team’s inventory, because unseen directory objects cannot be governed.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Directory visibility is now an identity governance requirement, not just an AD administration task. The acquisition reinforces a pattern NHIMG sees repeatedly: organisations treat directory discovery as a technical scan when the real issue is whether the identity programme can govern what it cannot yet see. Unknown domains, stale trusts, and unmanaged delegation paths expand the attack surface outside normal lifecycle control. Practitioners should treat directory inventory as a governance input, not a one-time assessment.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, with 38% having no or low visibility and 47% having only partial visibility, according to The State of Non-Human Identity Security.
- Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.
A question worth separating out:
Q: How do organisations know if AD security tooling is actually working?
A: It is working when the findings lead to measurable reductions in exposed privileges, unresolved trusts, and unowned domains. If the output only increases alert volume or produces a static report, the tool is improving visibility without changing the control posture.
👉 Read our full editorial: Netwrix PingCastle acquisition and what it changes for AD security
Directory visibility is now an identity governance requirement, not just an AD administration task. The acquisition reinforces a pattern NHIMG sees repeatedly: organisations treat directory discovery as a technical scan when the real issue is whether the identity programme can govern what it cannot yet see. Unknown domains, stale trusts, and unmanaged delegation paths expand the attack surface outside normal lifecycle control. Practitioners should treat directory inventory as a governance input, not a one-time assessment.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, with 38% having no or low visibility and 47% having only partial visibility, according to The State of Non-Human Identity Security.
- Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.
A question worth separating out:
Q: How do organisations know if AD security tooling is actually working?
A: It is working when the findings lead to measurable reductions in exposed privileges, unresolved trusts, and unowned domains. If the output only increases alert volume or produces a static report, the tool is improving visibility without changing the control posture.
👉 Read our full editorial: Netwrix PingCastle acquisition and what it changes for AD security
Active Directory discovery is a governance control, not just an inventory task. When organisations cannot see unknown or shadow domains, they cannot govern them. That makes visibility the first condition of identity assurance, because trust relationships and delegated rights only become manageable once they are known. Practitioners should treat AD discovery as part of the control environment, not as a separate technical exercise.
A question worth separating out:
Q: Should organisations prioritise AD discovery or remediation first?
A: Discovery comes first because you cannot remediate what you have not enumerated. But discovery should move immediately into remediation planning, ownership assignment, and review cycles. If teams stop at visibility, they improve reporting while leaving the underlying directory estate unchanged.
👉 Read our full editorial: Netwrix PingCastle acquisition and what it changes for AD security