Blog, Identity and Access Management Blog, LOGON Blog
Password Resets Aren’t Enough: What the Updated Five Eyes Active Directory Guidance Means for Identity Security
LOGON BLOG
Password Resets Aren’t Enough:
What the Updated Five Eyes Active Directory Guidance Means for Identity Security

Author: Sandy Chu, LOGON Software Asia
Once an attacker owns your Active Directory, resetting passwords won’t get it back.
That’s the uncomfortable truth behind the September 2026 update to the Five Eyes joint guidance on Active Directory compromises—published by CISA, the NSA, the Australian Signals Directorate, the Canadian Centre for Cyber Security, New Zealand’s NCSC, and the UK’s NCSC.
The original guidance landed in 2024. This update sharpens the focus on two attack techniques that survive traditional incident response: shadow credentials and expanded DCSync abuse.
Here’s why that matters to you: your security team may complete every remediation step on the checklist—reset passwords, wipe endpoints, remove malware—and still leave the attacker with a working key to your environment.
The real question after an identity compromise isn’t “Did we finish remediation?” It’s “How do we know we can trust this environment again?”


Why Active Directory Is Still So Hard to Defend
The guidance is blunt about the structural problems:
Weakness |
What It Means in Practice |
|---|---|
| Permissive defaults | Any authenticated user can query a lot of directory information |
| Legacy protocols | NTLM and RC4 still supported in most environments |
| Tangled trust relationships | Nested groups, inherited permissions, undocumented delegation |
| Excessive privileges | Over-privileged service accounts and admin groups |
| Limited visibility | Nobody fully understands how users, groups, computers, and services connect |
The guidance notes: attackers can sometimes develop a better operational understanding of your directory than your own administrators do.
Aging domains accumulate abandoned accounts, undocumented delegation, legacy apps, and permissions inherited through layer after layer of nested groups. Attackers map those paths. Most defenders haven’t.
The Hybrid Risk: Your Cloud Is Only as Safe as Your On-Prem
If you run Microsoft 365, Azure, or other cloud services, the guidance has a direct warning: on-premises compromise can walk straight into your cloud.
Golden SAML is the headline threat. An attacker steals the token-signing certificate and private key from AD FS, then forges SAML responses that look like they came from your trusted identity provider. If a relying party accepts the identity provider’s MFA claim, the forged response appears to have satisfied MFA—even though no legitimate authentication happened.
Entra Connect is the other bridge. A compromised sync server can let an attacker extract service-account credentials, gain directory-replication rights, or manipulate cloud identities.
The agencies’ advice: keep on-premises and cloud admin identities separate, don’t sync privileged AD accounts into Entra ID, enforce phishing-resistant MFA for cloud admins, and lock down access to Entra Connect servers.

Where IAM Fits—and Why It’s Not Optional
The Five Eyes guidance treats Active Directory security as an enterprise resilience issue, not a server-hardening chore. That reframing is where Identity and Access Management earns its place in your strategy.
An IAM layer doesn’t replace AD hardening. It adds verification, control, and visibility exactly where attackers concentrate their effort.
1. Authentication That Doesn’t Rely on Passwords Alone
Kerberoasting, AS-REP roasting, and password spraying all exploit the same weakness: credentials can be stolen, cracked, or guessed.
What IAM delivers:
-
MFA across all users—not just admins—so a stolen password isn’t a skeleton key
-
Adaptive authentication that adjusts requirements based on location, device, and behavior
-
A compensating control for legacy protocols like NTLM that may not invoke MFA at all
For distributed workforces, adaptive authentication matters. A login from Singapore and one from Jakarta carry different risk profiles. Your IAM layer should treat them differently.
2. Session Control and Least Privilege
What IAM delivers:
-
Session monitoring that flags accounts used from multiple locations at once—a classic sign of credential theft or password sharing
-
Concurrent session limits that make password sharing operationally useless
-
Just-in-Time (JIT) access that grants temporary, time-bound elevation for admin tasks
-
Least-privilege enforcement with regular access reviews
3. Secure Remote and Hybrid Access
What IAM delivers:
-
Secure remote access through encrypted gateways that authenticate before granting entry
-
Context-based access controls that evaluate device posture and user location
-
Continuous monitoring of remote sessions with automated alerts on anomalies
4. Audit Trails and Compliance Evidence
The guidance stresses centralized logging across domain controllers, certificate authorities, federation, and sync servers. It calls out specific events to watch—like Event ID 5136 for msDS-KeyCredentialLink modifications.
What IAM delivers:
-
Detailed audit trails capturing who accessed what, and when
-
Automated compliance reporting ready for auditors
-
Centralized visibility into directory changes—including the key credential anomalies that signal shadow credential attacks
For organizations operating across multiple Asian jurisdictions, automated reporting eases the burden of meeting Singapore’s Cybersecurity Act, Malaysia’s PDPA, and other evolving requirements.
Conclusion
The Five Eyes update isn’t just another advisory. It’s a signal that attacker tradecraft has moved toward persistence mechanisms that survive conventional incident response.
For CISOs and IT leaders across Asia—navigating rapid digital transformation, AI-accelerated threats, and a patchwork of regulations—identity security is no longer a technical checkbox. It’s a strategic imperative.
An IAM strategy built on strong authentication, session control, least privilege, and comprehensive auditing gives you the verification layer that modern identity security demands.
Contact LOGON Software Asia today. Let’s talk about how we can support your organization’s security posture across Asia.


