Join our Newsletter — 33% off our NHI Course
Home› Glossary› Architecture & Implementation› Writable Domain Controller
Architecture & Implementation

Writable Domain Controller

← Back to Glossary
By NHI Mgmt Group Updated October 11, 2026 Domain: Architecture & Implementation

A writable domain controller is an Active Directory controller that can accept directory changes, not just read them. For this topic, its importance is that a writable controller will process the manipulated dMSA state and link data that make BadSuccessor possible.

What Makes a Writable Domain Controller Different

A writable domain controller is not just a passive directory replica. It can process updates to Active Directory objects, replication metadata, and linked attributes, which means compromise of that role affects the directory itself rather than only directory visibility.

That distinction matters because attack paths that rely on directory mutation, such as manipulating delegated admin state, group membership, or linked data, require a controller that will accept writes. Read-only controllers do not provide that same modification surface.

Why Writable Status Matters in Active Directory Security

Writable controllers sit on the trust boundary where identity data becomes authoritative. If an attacker reaches one, they may be able to change security-sensitive directory state that other systems will later trust and replicate across the domain.

This is why writable controllers are central to directory integrity, privilege assignment, and abuse of replication-backed state. In practical terms, the attack surface is larger than authentication alone, because the controller can become the place where bad changes are introduced and then propagated.

Operational Role in Directory Change Processing

In normal operations, writable controllers handle account changes, group updates, password-related events, policy-linked directory changes, and other state transitions that define who can do what in the environment. They are the systems that make directory administration possible at scale.

That operational role also means they must be treated as high-value infrastructure. Hardening, monitoring, tiering, and administrative separation matter because a writable controller is both a service endpoint and a source of authoritative change.

How Writable Controllers Enable Abuse Paths

Writable controllers become especially important when an adversary is trying to turn directory write capability into durable privilege. If the attacker can alter linked state, delegation paths, or other security-relevant attributes, the directory itself can be used to sustain access.

This is why understanding writable versus read-only controllers is not a naming exercise. The ability to accept change is what makes the controller relevant to privilege escalation, persistence, and domain-wide impact when the surrounding directory trust model is abused.

Risk and Threat Considerations

Writable domain controllers create a materially different risk profile from read-only controllers because they can accept and replicate directory changes. If an attacker gains sufficient access, the controller can become the place where malicious state is written into the directory and then trusted elsewhere.

Failure mechanism: Compromised administrative access, weak segregation, or abuse of replication-aware directory features can let an attacker modify security-sensitive objects on a writable controller, turning a single foothold into broader domain compromise.

Impact: Unauthorized directory changes can enable privilege escalation, persistence, lateral movement, and loss of trust in Active Directory as an authoritative source of identity and authorization data.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1098 — Account ManipulationWritable DC abuse can change directory state that affects accounts and access.
T1556 — Modify Authentication ProcessWritable directory state can be abused to influence authentication or trust paths.
Recommendation — Monitor and alert on unexpected directory object changes that alter account or group state. Hunt for directory modifications that could alter authentication-related behavior or trust.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeWritable DCs demand strict privilege limits because write access changes authoritative identity data.
AU-12 — Audit Record GenerationDirectory mutation on a writable DC should be fully logged for change detection.
SC-7 — Boundary ProtectionWritable controllers are high-value boundary assets that need segmentation and restricted access paths.
Recommendation — Restrict administrative write access to domain controllers to the minimum required set. Generate and retain detailed logs for directory write activity on domain controllers. Segment domain controllers and limit administrative access paths to reduce exposure.

Practitioner Guidance

Why practitioners should care: Writable controllers are not interchangeable with read-only replicas. If you classify them too loosely, you can understate where directory mutation is possible and overestimate the protection provided by passive replication.

Governance implication: Treat writable controllers as tier-0 assets with tightly controlled administration, because the ability to accept changes makes them part of the core identity control plane rather than a routine server role.

Practitioner takeaway: The key security question is not just whether a controller is available, but whether it can be made to accept directory changes that later become trusted enterprise state.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org