The risk comes from chaining two weaknesses: coercing a privileged principal to authenticate and then relaying that authentication to a service that accepts it. In AD CS, Web Enrollment services can be abused to issue certificates tied to the victim identity, which can outlive the original session and be reused for authentication or silver ticket style abuse.
Why the relay step makes coercion so dangerous in AD CS
Authentication coercion is serious because it turns a trusted principal into an unsolicited client, and ntlm relay turns that client-side trust into usable server-side access. In AD CS, the target is often not a generic web app, but a certificate service that can mint long-lived credentials. That changes a one-time authentication event into durable identity abuse.
The core problem is that the attacker does not need to crack the victim’s password or keep the victim online. They only need a momentary authentication response, then a service path that will accept it without strong channel binding or mutual authentication. Once a certificate is issued, the attacker can often reuse it long after the original coerced session has ended.
Why AD CS Web Enrollment is such a high-value relay target
AD CS Web Enrollment matters because it can bridge a short-lived inbound authentication into a certificate tied to the victim identity. That is a stronger outcome than a transient web session, since the resulting certificate can support later logon, impersonation, or chained abuse against other services. The risk is highest when enrollment templates, issuance permissions, or Web Enrollment exposure are too broad.
This is why the attack path is so effective in enterprise Windows environments: coercion produces the authentication, relay preserves the protocol weakness, and AD CS converts the relayed proof into an artifact the attacker can keep. Where certificate services are reachable and enrollment is not tightly constrained, the attacker may not need further privilege escalation to obtain a reusable foothold.
Why this is more than a single-hop compromise
Once a certificate is issued, the impact extends beyond the original relay endpoint. The attacker may be able to authenticate as the victim, request additional access, or use the certificate as an identity substitute in other workflows. That persistence is what makes this pattern more dangerous than simple NTLM capture, because the abuse survives password changes and many session defenses.
In practice, the blast radius depends on which principal is coerced, what template is available, and whether the issued certificate can be used for logon or privilege-bearing workflows. A relay against a low-value account is noisy but limited; a relay against an administrator, help desk operator, or other privileged principal can become a domain-wide compromise path.
Risk and Threat Considerations
When coercion and relay are combined, the main risk is not just unauthorized authentication, but durable identity conversion. If the attacker can steer a privileged principal into a relayable service and that service can issue certificates, the result is a credential that can outlast the original authentication exchange and bypass many password-centric controls.
Failure mechanism: An attacker forces a machine or user to authenticate over NTLM, relays that authentication to AD CS Web Enrollment or a similar accepting service, and obtains a certificate or equivalent reusable authentication artifact for the victim identity.
Impact: The attacker gains persistent impersonation potential, possible lateral movement, and a path to reauthenticate after the original session ends, making containment harder than with ordinary relay abuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Relayed auth becomes durable abuse when credentials and authenticators are issued or reused insecurely. |
| IA-9 — Service Identification and Authentication | NTLM relay abuses service-to-service authentication paths that should not accept unauthenticated or relayed proofs. | |
| AC-6 — Least Privilege | Privileged principals are the highest-value coercion targets, so excessive rights magnify the attack impact. | |
| Recommendation — Restrict and manage authenticators so relayed or reusable authentication material cannot become lasting access. Require strong service authentication and constrain accepted authentication flows to prevent relay abuse. Reduce privileged exposure so coerced authentications cannot yield broad administrative impact. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The subject hinges on controlling which identities can authenticate and what services accept that access. |
| A.8.5 — Secure authentication | The attack succeeds when authentication can be relayed and converted into reusable access material. | |
| A.8.2 — Privileged access rights | Privileged principals are the main coercion and relay targets in AD CS abuse paths. | |
| Recommendation — Limit authentication paths and enrollment access to only the identities and services that need them. Use authentication methods and channel protections that prevent replay and relay. Tighten privileged access rights so high-value identities are harder to coerce and abuse. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | The issue is fundamentally about controlling who can authenticate, enroll, and reuse access paths. |
| Recommendation — Harden and review access paths that could convert a coerced login into durable certificate-based access. | ||
Practitioner Guidance
What to verify: Confirm whether AD CS Web Enrollment is exposed where relayable authentication can reach it, and whether certificate templates allow enrollment or authentication use that would be meaningful if issued to a privileged principal. The most important question is not whether NTLM exists somewhere, but whether a coerced authentication can be converted into a reusable credential.
Decision rule: If a service can issue authentication-capable certificates from relayed inbound auth, treat that path as a high-priority identity exposure and restrict it before focusing on downstream detection. If the enrollment path is not necessary, remove it or narrow it so coerced authentication cannot become a durable artifact.
What practitioners underestimate: Teams often focus on relay as a network or protocol weakness and miss the certificate issuance step, which is what turns a momentary compromise into something that can survive resets, logoff, and many response actions.
Practitioner takeaway: The key defensive mindset is to stop thinking of relay as “stolen auth” and start treating AD CS issuance as credential creation, because that is where transient abuse becomes lasting access.
Related resources from NHI Mgmt Group
- Why do NTLM relay attacks against AD CS create such high privilege risk?
- Why do Windows admin gateways create such high-risk identity exposure when AD CS is nearby?
- Why do shared signing keys create such a serious authentication risk?
- Why do authentication bypass flaws combined with remote code execution create such high risk for identity and access systems?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org