CISA Active Directory Guidance is the central development. The CISA Active Directory Guidance is a multinational update for detecting and mitigating attacks on the identity layer that controls access across many enterprise networks. Australia’s cyber agency first published the update on September 14 with CISA, NSA and Canadian, British and New Zealand partners. It adds attention to shadow credentials and a newer way to detect DCSync activity.

CISA Active Directory Guidance: the verified facts

Verified facts and disclosure boundaries
Earliest disclosure September 14, 2026 Australian Cyber Security Centre
Scope Active Directory Domain Services, Certificate Services and Federation Services Joint guidance
New emphasis Novel DCSync detection and shadow credentials Cyber.gov.au
Authors Australian, U.S., Canadian, U.K. and New Zealand cyber agencies Joint guidance
Count note The Australian update says 18 techniques; some partner summaries say 17 Primary and independent sources

CISA Active Directory Guidance operational pathFour connected stages explain the practical sequence.CISA Active Directory Guidance operational pathLogScopeEvictRecover

The CISA Active Directory Guidance is a multinational update for detecting and mitigating attacks on the identity layer that controls access across many enterprise networks. Australia’s cyber agency first published the update on September 14 with CISA, NSA and Canadian, British and New Zealand partners. It adds attention to shadow credentials and a newer way to detect DCSync activity.

Active Directory compromise is rarely one isolated alert. Attackers often begin with an ordinary account, discover permissions, escalate privileges, move between systems and create persistence that survives a password reset. The joint guidance is useful because it organises techniques around that progression across Domain Services, Certificate Services and Federation Services.

Defenders should start with visibility before containment. Domain-controller logs, certificate-service changes, privileged group membership and replication activity need enough retention to reconstruct the path of an intrusion. Rotating credentials too early can erase useful evidence or leave a certificate-based persistence route untouched. Preserve data, scope the compromise and then execute a clean recovery sequence.

Shadow credentials deserve special attention because certificate-based authentication can outlive a conventional password change. Teams should audit certificate templates, enrollment permissions, subject alternative name settings and changes to key-credential links. A successful review connects identity events to endpoint and network telemetry instead of assuming the directory log alone tells the whole story.

DCSync detection also requires context. Legitimate domain controllers replicate directory data, while an attacker can request similar information from an unauthorized host or account. A practical rule therefore combines replication permissions, source system identity, account history and timing. Static allowlists become risky when privileged service accounts or management servers are compromised.

There is a small but important publication discrepancy: the Australian update describes advice for 18 techniques, while CISA-linked summaries and several independent reports refer to 17. Security teams should use the full current document and its tables rather than treat the headline count as an implementation checklist. The operational controls matter more than the marketing number.

For Indian enterprises running hybrid Microsoft estates, the priority is to identify Tier 0 assets, separate administrative workstations, require phishing-resistant authentication and test forest-recovery plans. Organizations should also know which business services fail when directory trust is unavailable. Identity resilience is an availability issue as much as a security issue.

Related Lapaas Voice coverage

Read Google Pixel zero-day response and NVIDIA CUDA-Q Logical platform for adjacent security and infrastructure context.

Frequently asked questions

What is the CISA Active Directory Guidance?

It is joint government guidance for detecting and mitigating common techniques used to compromise Microsoft Active Directory environments.

What changed in the 2026 update?

The Australian publisher highlights a novel DCSync detection method and a new section on shadow credentials.

Why do reports differ between 17 and 18 techniques?

The Australian update says 18, while some partner summaries say 17. Defenders should follow the full current guidance and its control tables.

Sources

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.