Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response Why do non-transitive trusts create unexpected privilege risk…
Threats, Abuse & Incident Response

Why do non-transitive trusts create unexpected privilege risk in Active Directory forests?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 27, 2026 Domain: Threats, Abuse & Incident Response

Non-transitive trusts can create a false boundary because Kerberos referrals may be chained through intermediate domains. That can let an authenticated user move beyond the domain they were meant to reach and query or access more sensitive domains in the same forest. The practical risk is privilege expansion, reconnaissance, and attack path discovery across a forest.

Why This Matters for Security Teams

Non-transitive trusts in active directory forests are often mistaken for hard boundaries, but trust routing inside a forest can still expose more than the original business owner expected. That matters because once a principal can authenticate across a path, the security team is no longer managing a single domain boundary. It is managing an attack path problem that can expand with delegation, group membership, and directory visibility.

The risk is not theoretical. NHI Mgmt Group notes that 97% of NHIs carry excessive privileges in many environments, which is a strong signal that trust relationships and identity sprawl often move together. When that happens, even “limited” trust can become a reconnaissance bridge into more sensitive domains, especially if service accounts, admin groups, or legacy applications are involved. The same pattern is consistent with broader identity guidance in the OWASP Non-Human Identity Top 10 and the NIST Cybersecurity Framework 2.0, both of which emphasize least privilege and strong identity governance.

In practice, many security teams discover the privilege expansion only after attackers have already used directory queries or referral chaining to map the forest and identify a better target.

How It Works in Practice

In AD, a non-transitive trust is supposed to limit reach to a specific domain relationship, but Kerberos referrals can still create indirect paths that surprise defenders. An authenticated user may not have direct rights in a sensitive domain, yet the trust path can let the client ask for service tickets through intermediate domains until the request resolves. That means the real question is not just “is there a trust,” but “what can be reached through the trust chain, and with what privileges?”

Security teams should model the forest as a graph, not a set of isolated boxes. Practical review should include:

  • Which domains can issue referrals to which other domains
  • Whether privileged groups or delegated admin roles span trust boundaries
  • Which service accounts, SPNs, and legacy apps rely on cross-domain access
  • Whether LDAP, SMB, WinRM, or other services become reachable after referral-based authentication

That is why identity hygiene matters as much as trust design. The Ultimate Guide to NHIs — Key Challenges and Risks is a useful reminder that excessive privilege, weak visibility, and poor lifecycle control tend to amplify each other. A trust that looks constrained on paper can become materially broader when long-lived credentials, over-permissioned service identities, and weak monitoring line up. Guidance from NIST SP 800-53 Rev 5 Security and Privacy Controls supports this approach by requiring tighter access control, auditability, and monitoring around identity-driven access.

These controls tend to break down in large forests with legacy applications, where referral flows, delegated administration, and stale group memberships make the effective access path much wider than the intended trust scope.

Common Variations and Edge Cases

Tighter trust restriction often reduces operational flexibility, requiring organisations to balance safer segmentation against application compatibility and admin overhead. That tradeoff is especially visible in forests with mergers, shared services, or authentication dependencies that were never documented well.

There is no universal standard for every forest layout, but current guidance suggests treating non-transitive trusts as one control layer, not a complete boundary. In some environments, the biggest risk is not direct access but discovery: once a user can enumerate domains, groups, or service endpoints, the attack path becomes easier to stage. In others, the key issue is privileged lateral movement through legacy management tooling that was granted broad cross-domain access years ago.

Two practical edge cases deserve attention. First, shadow administrative groups can make a “limited” trust effectively privileged if membership is inherited or poorly reviewed. Second, cross-domain service identities can turn a business dependency into a standing access channel, especially when secrets are long-lived. The Top 10 NHI Issues and the Cisco Active Directory credentials breach illustrate how identity exposure and weak lifecycle controls can turn a trust relationship into a broader compromise path. For teams aligning to operational baselines, the right response is to verify actual reachability, remove unnecessary cross-domain privilege, and continuously test whether the trust still matches the business requirement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Trust chains expand NHI attack paths and hidden privilege exposure.
OWASP Agentic AI Top 10Graph-based privilege expansion mirrors autonomous path discovery risks.
CSA MAESTROMAESTRO addresses identity propagation and cross-boundary access in distributed systems.
NIST CSF 2.0PR.AC-4Least-privilege access and managed permissions are central to forest trust risk.
NIST AI RMFAI RMF governance supports continuous risk evaluation for complex identity relationships.

Continuously validate that identities can only reach approved resources at runtime, not through hidden chains.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org