Navigation
  • SEARCH HERE
  • SOLUTIONS
    • Information Security Solutions
      • Enterprise Application Security Solutions in Asia
      • Network & Infrastructure Security Solutions
      • Zero Trust Security
      • Security Information and Event Management
      • Remote Monitoring & Management (RMM)
      • File Integrity Management
      • Systems Administration Tools
      • Data Loss Prevention
      • Data / Password Recovery
      • IT Management Solution Offering | Distributor in Asia
      • Identity and Access Management Solution Offering | Distributor in Asia
      • Employee Activity Monitoring (EAM)
      • Digital Forensic Investigation
    • Software Development Solutions
      • Integrated Development Environments
      • Development Components
        • UI Tools
        • Networking Components
        • Office Components
        • Barcode Components
        • Communication Components
      • Imaging Solutions
      • Software Localization
      • Release Automation & Management
      • eLearning Authoring Solutions
      • Charting Solutions
      • PDF Solutions
      • Reporting Solutions
      • Testing & QA
      • Text Retrieval / Enterprise Search
      • Database
  • Services
    • Live Solution Walkthroughs
    • Implementation Services
    • Best Practices Consulting
    • Pre-Sales and Post-Sales Services
  • What's New
    • Our Event
    • Our Blogs
    • Special Offers
  • About
    • About LOGON Software Asia
    • Our Partnership
  • Publishers - Join our network
  • Resellers - Expand your portfolio
Site logo
  • Solutions
    • Information Security Solutions
      • Identity and Access Management
        • Privileged Access Management (PAM)
        • Multi-Factor Authentication (MFA)
        • Identification Verification (IV)
        • Self-Service Password Reset (SSPR)
      • Network & Infrastructure Security
        • DDoS Mitigation and Protection
        • Digital Forensic Investigation
        • Malware Detection & Analysis
        • Network Monitoring Software
        • Email Security
        • Log Monitoring
      • Endpoint & Device Security
        • Patch Management
        • Remote Monitoring & Management (RMM)
        • Employee Activity Monitoring (EAM)
        • Mobile Device Management (MDM)
      • IT Management
        • IT Service Management
        • IT Asset Management
        • Software Asset Management
        • Hardware Asset Management
        • Software License Management
        • Systems Administration Tools
      • Application Security
        • Development Security | Shift Left AppSec | SAST, SCA, IAST
        • Runtime Protection Solutions | DAST, RASP, WAF, Container Security
        • Strategic Management Solutions | ASPM, MAST, VAPT
      • Data Security
        • Data Loss Prevention
        • File Integrity Management
        • Data / Password Recovery
        • Data Security Posture Management
      • Cloud Security
        • Cloud Security Posture Management
        • Cloud Work Protection
      • External Attack Surface Management
        • Cyber Threat Intelligence
        • Third Party Risk Management
      • Security Operations & Incident Management
        • Security Information and Event Management
        • Security Orchestration, Automation and Response (SOAR)
      • Zero Trust Security
    • Software Development Solutions
      • Integrated Development Environments
      • Imaging Solutions
      • UI Tools
      • Charting Solutions
      • Database
      • Networking Components
      • Office Components
      • Barcode Components
      • Release Automation & Management
      • Software Localization
      • Communication Components
      • Automated Testing
      • eLearning Authoring Solutions
      • Reporting Solutions
      • Text Retrieval / Enterprise Search
      • Testing & QA
  • Services
        • Live Walkthrough Sessions

          Experience the full feature of our key solutions through live platform

          View All Sessions >
        • Implementation Services
        • Pre-Sales and Post-Sales Services
        • Best Practices Consulting
  • Partners
    • Our Partners
    • Partner with LOGON Today!
      • Vendors - Join Our Network
      • Resellers - Expand Your Portfolio
      • Procurement Managers
  • Resources
        • ABOUT US

        • About Us
        • Our Locations
        • Careers@LOGON - We are hiring !
        • DISCOVER

        • Our BlogsNEW BLOGS
        • Our EventsJOIN UPCOMING EVENTS
        • LOGON to CyberSecurity PodcastNEW EPISODES
        • GET HELP

        • Contact Us
        • Help Desk
        • Request a Demo
        • Request a Quote
        • COMPLIANCE

        • 🇭🇰 Hong Kong PDPO
        • 🇮🇳 India DPDP Act
        • 🇸🇬 Singapore PDPA
        • 🇹🇭 Thailand PDPA
  • More results...

View large
Blog, Identity and Access Management Blog, LOGON Blog

Password Resets Aren’t Enough: What the Updated Five Eyes Active Directory Guidance Means for Identity Security

LOGON BLOG

Password Resets Aren’t Enough:

What the Updated Five Eyes Active Directory Guidance Means for Identity Security

Updated Five Eyes Active Directory Guidance Means for Identity Security

Author: Sandy Chu, LOGON Software Asia

Once an attacker owns your Active Directory, resetting passwords won’t get it back.

That’s the uncomfortable truth behind the September 2026 update to the Five Eyes joint guidance on Active Directory compromises—published by CISA, the NSA, the Australian Signals Directorate, the Canadian Centre for Cyber Security, New Zealand’s NCSC, and the UK’s NCSC.

The original guidance landed in 2024. This update sharpens the focus on two attack techniques that survive traditional incident response: shadow credentials and expanded DCSync abuse.

Here’s why that matters to you: your security team may complete every remediation step on the checklist—reset passwords, wipe endpoints, remove malware—and still leave the attacker with a working key to your environment.

The real question after an identity compromise isn’t “Did we finish remediation?” It’s “How do we know we can trust this environment again?”


Why This Hits Asia Harder

Attacks are getting faster. Akamai’s 2026 APAC outlook warns that AI-driven attacks now compress breach timelines from weeks into hours. Attackers use autonomous tools to scan, test, and exploit with minimal human involvement—raising risk sharply in digital hubs like Singapore, Korea, and Japan.

Ransomware is now an off-the-shelf product. Ransomware-as-a-Service subscriptions have turned what was once a specialized operation into a mass-market criminal economy.

The mid-market is squarely in the crosshairs. Across Asia-Pacific, roughly 1 in 3 cyberattacks occur—and 7 in 10 small businesses reported a cyber incident in the past year.

Regulation is tightening, unevenly. ASEAN’s Cybersecurity Cooperation Strategy 2026–2030 is pushing for harmonized standards, but the region remains fragmented today. Organizations that align with international guidance like the Five Eyes advisory will be better positioned when local rules catch up.

Translation for your board: the threat is faster, cheaper, and more widespread than it was two years ago—and your identity layer is the primary target.

Active Directory security risks for enterprises in Asia Pacific - threat indicators over major digital hubs

New Updates in the Guidance

The update examines 17 attack techniques against Active Directory Domain Services, Certificate Services, and Federation Services, and two areas received major expansions.

Shadow Credentials: The Persistence That Survives Password Resets

An attacker with permission to modify a user or computer object adds their own public-key material to the msDS-KeyCredentialLink attribute. They then authenticate as that identity using the matching private key.

What this means: Legitimate and malicious key credentials can coexist. Resetting the account password does not remove the attacker’s certificate-based access. Your incident response can look “complete” while the intruder still walks through the front door.

Expanded DCSync Guidance: Stealing the Keys to the Kingdom

DCSync abuses the same replication functionality domain controllers use to sync directory data. An attacker with replication permissions impersonates a domain controller and requests credential data directly—including current and historical password hashes and Kerberos keys.

The update also explains a nastier variant: combining DCSync with the “store passwords using reversible encryption” setting. Enable it, wait for passwords to change, and a subsequent replication request hands over recoverable passwords—no offline cracking required.

The Rest of the Hit List

Kerberoasting, AS-REP roasting, password spraying, Golden Ticket and Silver Ticket attacks, Golden SAML against AD FS, ntds.dit theft, and abuse of default computer-account permissions.

Shadow credentials and DCSync attacks - two key Active Directory persistence techniques in the 2026 Five Eyes update

Why Active Directory Is Still So Hard to Defend

The guidance is blunt about the structural problems:

Weakness
What It Means in Practice
Permissive defaults Any authenticated user can query a lot of directory information
Legacy protocols NTLM and RC4 still supported in most environments
Tangled trust relationships Nested groups, inherited permissions, undocumented delegation
Excessive privileges Over-privileged service accounts and admin groups
Limited visibility Nobody fully understands how users, groups, computers, and services connect

The guidance notes: attackers can sometimes develop a better operational understanding of your directory than your own administrators do.

Aging domains accumulate abandoned accounts, undocumented delegation, legacy apps, and permissions inherited through layer after layer of nested groups. Attackers map those paths. Most defenders haven’t.


The Hybrid Risk: Your Cloud Is Only as Safe as Your On-Prem

If you run Microsoft 365, Azure, or other cloud services, the guidance has a direct warning: on-premises compromise can walk straight into your cloud.

Golden SAML is the headline threat. An attacker steals the token-signing certificate and private key from AD FS, then forges SAML responses that look like they came from your trusted identity provider. If a relying party accepts the identity provider’s MFA claim, the forged response appears to have satisfied MFA—even though no legitimate authentication happened.

Entra Connect is the other bridge. A compromised sync server can let an attacker extract service-account credentials, gain directory-replication rights, or manipulate cloud identities.

The agencies’ advice: keep on-premises and cloud admin identities separate, don’t sync privileged AD accounts into Entra ID, enforce phishing-resistant MFA for cloud admins, and lock down access to Entra Connect servers.

Hybrid identity risk - how on-premises Active Directory compromise spreads to cloud services

Where IAM Fits—and Why It’s Not Optional

The Five Eyes guidance treats Active Directory security as an enterprise resilience issue, not a server-hardening chore. That reframing is where Identity and Access Management earns its place in your strategy.

An IAM layer doesn’t replace AD hardening. It adds verification, control, and visibility exactly where attackers concentrate their effort.

1. Authentication That Doesn’t Rely on Passwords Alone

Kerberoasting, AS-REP roasting, and password spraying all exploit the same weakness: credentials can be stolen, cracked, or guessed.

What IAM delivers:

  • MFA across all users—not just admins—so a stolen password isn’t a skeleton key

  • Adaptive authentication that adjusts requirements based on location, device, and behavior

  • A compensating control for legacy protocols like NTLM that may not invoke MFA at all

For distributed workforces, adaptive authentication matters. A login from Singapore and one from Jakarta carry different risk profiles. Your IAM layer should treat them differently.

2. Session Control and Least Privilege

What IAM delivers:

  • Session monitoring that flags accounts used from multiple locations at once—a classic sign of credential theft or password sharing

  • Concurrent session limits that make password sharing operationally useless

  • Just-in-Time (JIT) access that grants temporary, time-bound elevation for admin tasks

  • Least-privilege enforcement with regular access reviews

3. Secure Remote and Hybrid Access

What IAM delivers:

  • Secure remote access through encrypted gateways that authenticate before granting entry

  • Context-based access controls that evaluate device posture and user location

  • Continuous monitoring of remote sessions with automated alerts on anomalies

4. Audit Trails and Compliance Evidence

The guidance stresses centralized logging across domain controllers, certificate authorities, federation, and sync servers. It calls out specific events to watch—like Event ID 5136 for msDS-KeyCredentialLink modifications.

What IAM delivers:

  • Detailed audit trails capturing who accessed what, and when

  • Automated compliance reporting ready for auditors

  • Centralized visibility into directory changes—including the key credential anomalies that signal shadow credential attacks

For organizations operating across multiple Asian jurisdictions, automated reporting eases the burden of meeting Singapore’s Cybersecurity Act, Malaysia’s PDPA, and other evolving requirements.


Conclusion

The Five Eyes update isn’t just another advisory. It’s a signal that attacker tradecraft has moved toward persistence mechanisms that survive conventional incident response.

For CISOs and IT leaders across Asia—navigating rapid digital transformation, AI-accelerated threats, and a patchwork of regulations—identity security is no longer a technical checkbox. It’s a strategic imperative.

An IAM strategy built on strong authentication, session control, least privilege, and comprehensive auditing gives you the verification layer that modern identity security demands.

Contact LOGON Software Asia today. Let’s talk about how we can support your organization’s security posture across Asia.

Contact Us Today
Contact Us Today

FOLLOW US ON

  • LinkedIn
  • Facebook
  • Instagram
  • Twitter
  • YouTube
Read Next:
Acunetix BlogBlogInvicti Blog
Acunetix Is Now Invicti Web + API
BlogIdentity and Access Management BlogLOGON Blog
Password Resets Aren’t Enough: What the Updated Five Eyes Active Directory Guidance Means for Identity Security
BlogCloud Security BlogIdentity and Access Management BlogLOGON Blog
When Passkeys Become the Bait: A New Wave of Voice Phishing Targeting Microsoft 365

Privacy Policy Company Overview

COMPANY

Our Location Career with LOGON Our Partners

SERVICES

Training Services Implementation Services Pre-Sales and Post-Sales Services Best Practices Consulting

GET IN TOUCH

Phone:
Hong Kong: +852 2512 8491
India: +91 70220 22744 / +91 63668 26133
Email: [email protected] ©2025 LOGON International Ltd. All rights reserved
logon logo WHITE

Search engine

Use this form to find things you need on this site

More results...