Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What happens when an attacker abuses Active Directory…
Threats, Abuse & Incident Response

What happens when an attacker abuses Active Directory Certificate Services through NTLM relay and certificate enrollment?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Threats, Abuse & Incident Response

An attacker can impersonate a user or a domain controller, request a certificate over HTTP, and then use that certificate to authenticate with elevated rights. In practice, that can move compromise from a low-privilege foothold to domain admin or even forest administrator access. Once those certificates exist, revoking the root cause is difficult if inventory and revocation processes are weak.

How NTLM relay turns AD CS certificate enrollment into elevated access

active directory certificate services becomes dangerous when the attacker can coerce or intercept authentication and then complete certificate enrollment on behalf of a more privileged identity. The key issue is not just obtaining a certificate, but obtaining one that the directory or the relying service will accept as proof of that identity. Once that trust is established, the certificate can outlive the original relay event and become a reusable path into higher privilege.

In practical terms, the relay gives the attacker a way to swap a low-value network interaction for a high-value authentication artifact. If enrollment templates, HTTP-based endpoints, or certificate mappings are permissive, the attacker can pivot from a trapped NTLM exchange to a certificate that authenticates as a user, server, or domain controller. That is why this pattern often produces a bigger impact than a one-time session hijack.

The important architectural detail is that certificate-based authentication changes the attack surface from password or hash theft to trusted credential issuance. Once a certificate exists, the attacker may no longer need the original NTLM relay path at all, which makes the compromise easier to operationalise and harder to reason about as a single incident.

Why the resulting access is so hard to contain

The danger escalates when the issued certificate is accepted for logon, service authentication, or privileged directory operations. A certificate that is valid for an administrative principal can grant broad access without ever revealing a password, and a certificate tied to a domain controller can be even more damaging because it can support directory impersonation and follow-on privilege escalation.

This is why Ultimate Guide to NHIs and the What are Non-Human Identities section are useful context for practitioners who want to think in terms of the credentialed actor, not just the transport used to obtain it. In the same way, NHI Lifecycle Management Guide is relevant because lifecycle blind spots are what let issued credentials remain useful after the original compromise path should have been closed.

Containment is difficult because certificates are often treated as legitimate trust material once issued. If inventory is weak, teams may not know which endpoints, templates, or principals can mint a usable certificate. If revocation is weak, they may know a certificate is bad but still be unable to remove its practical value quickly enough to prevent lateral movement or domain-wide abuse.

The issue is therefore both authentication and governance. The attack succeeds when issuance, mapping, and revocation are all trusted more than they should be, and when defenders assume the original NTLM relay is the only thing that needs to be fixed.

What defenders should watch for in AD CS relay abuse

Defenders should treat unexpected certificate enrollment, especially over HTTP-based enrollment paths, as a high-signal event when it is preceded by NTLM coercion or suspicious authentication relay behaviour. A certificate request that appears normal in isolation may be highly suspicious when the requester, template, and subject name do not align with the real host or user context.

Useful corroborating evidence includes unusual enrollment from non-administrative systems, certificate subjects that map to privileged accounts, and sudden use of certificate-based authentication from identities that normally do not use it. Cisco Active Directory credentials breach is a reminder that AD credential compromise and lateral movement often travel together once directory trust is broken, while The 52 NHI Breaches Report shows how frequently stolen or abused identity material becomes the practical bridge from initial access to broader compromise.

For deeper reading on certificate handling and trust chains, NIST SP 800-57 Key Management is useful for the lifecycle and trust-management perspective, while the CA/Browser Forum baseline requirements help frame issuance and revocation discipline as a control problem, not just a certificate-store problem.

Risk and Threat Considerations

The main risk is that a single relayed enrollment can create a durable authentication path that bypasses the original foothold. When the issued certificate maps to a privileged account or a high-trust server identity, the attacker can turn a transient network abuse into repeatable access and broader directory compromise.

Failure mechanism: NTLM relay abuses a trusted authentication exchange to satisfy certificate enrollment, and weak template, mapping, or revocation controls allow the resulting certificate to function as a valid high-privilege authenticator.

Impact: The attacker may impersonate privileged users or infrastructure, expand from a low-privilege foothold to domain-level control, and persist even after the original relay path is blocked.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-57 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-57Key Management RecommendationsCertificate abuse turns key lifecycle and trust material into the access path.
Recommendation — Enforce certificate lifecycle, revocation, and cryptoperiod discipline for privileged authentication material.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementIssued certificates function as authenticators that must be controlled and revoked.
IA-9 — Service Identification and AuthenticationRelay abuse can mint certificates for systems, services, or domain controllers.
AC-6 — Least PrivilegeThe attack is dangerous when enrollment or mapped certificates grant excess privilege.
Recommendation — Manage certificate issuance, rotation, and revocation as authentication assets. Require strong service authentication and restrict certificate-based service identities. Restrict certificate templates and mappings to the minimum privilege needed.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationRelay abuse exploits weak authentication paths into certificate issuance.
NHI-07 — Long-Lived SecretsCertificates can remain useful long after the original relay event ends.
Recommendation — Harden enrollment and authentication paths so relay cannot mint trusted credentials. Minimise certificate lifetime and rotate or revoke compromised credentials quickly.

Practitioner Guidance

What to verify: Confirm which enrollment endpoints accept HTTP, which templates permit requester-supplied subject or SAN data, and which certificate mappings can authenticate privileged principals. If you cannot answer those three questions quickly, you do not yet have enough visibility to trust the environment.

Common mistake: Treating revocation as a cleanup step instead of part of the attack path. If a certificate can still authenticate, then the compromise is not contained, even if the original NTLM relay vector has been disabled.

Practitioner takeaway: The decisive control is not merely stopping NTLM relay, it is preventing relayed authentication from becoming a valid, reusable certificate-based trust relationship with privileged reach.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org