Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Webinars
  • IAM Leaders and AD Admins: Are AD CS Misconfigurations and Similar Issues Giving Every User a Path to Your Domain Admin? current page
Link copied

IAM Leaders and AD Admins: Are AD CS Misconfigurations and Similar Issues Giving Every User a Path to Your Domain Admin?

with James Maude, Field Chief Technology Officer; David Faulk, Sr Solutions Architect, BeyondTrust
Webinars default
IAM Leaders and AD Admins: Are AD CS Misconfigurations and Similar Issues Giving Every User a Path to Your Domain Admin?

Get Instant Access to this Content

Learn more about how to secure your business from threats in places you didn't even know existed.

To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video

00:39:23

Attackers are navigating hidden pathways to privilege in IT environments, compromising the entire interconnected system – on-premises, cloud, and SaaS. Misconfigurations in Active Directory Certificate Services (ADCS) such as Enterprise CA Security Configuration (ESC1) and ESC4 with Key Escrow are particularly notorious for enabling attackers to escalate privileges using standard accounts to gain full control of an AD domain and beyond.

These vulnerabilities are just one example of numerous hidden paths to privileges present in most organizations. Attackers can easily exploit dormant accounts, obscure connections between siloed systems, overprivileged and unmanaged accounts, and other identity and privilege related gaps to move laterally and escalate privileges throughout your IT landscape. Without a clear understanding of the “true” privileges of identities (not just explicitly assigned privileges) and the paths to privileges that attackers can exploit, it’s a losing battle to find and address the most critical issues.

Watch our experts and discover:

  • Common ADCS misconfigurations that attackers exploit to become domain admin starting from standard domain users, achieving full control of your interconnected IT environment.
  • Other security posture issues attackers use to pivot from compromised standard users to high privilege in unexpected ways.
  • Proactive strategies to identify these risks from an attacker’s perspective and address identity hygiene issues across your identity estate using Identity Security Insights®.

Don’t wait for your annual penetration tests or vulnerability assessments to uncover the paths to privilege attackers will use. Learn how to take a proactive approach to harden your identity security posture against evolving identity-driven threats.

Meet the Presenters

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
James Maude Headshot 2024
James Maude
Field Chief Technology Officer

James Maude is the Field Chief Technology Officer (FCTO) at BeyondTrust. With his broad experience in security research, both in academia and industry, James has spent the past decade analyzing cyber threats to identify attack vectors and trends in the evolving security landscape. He is an active member of the security community and hosts Adventures of Alice and Bob, a podcast that shines a light on the people making a difference in security. As an expert voice on cybersecurity, he regularly presents at international events and hosts webinars to discuss threats and defense strategies.

David Faulk
David Faulk
Sr Solutions Architect, BeyondTrust

David Faulk is a Sr. Solutions Architect at BeyondTrust with almost three years at the company. David started in Open Source software before moving into Cybersecurity. He enjoys Muay Thai, lifting weights, and Drones.

Latest
  • 2026 July Product Road Map: Endpoint Privilege Management Unix & Linux and Active Directory Bridge
    Jun 4, 2026 2026 July Product Road Map: Endpoint Privilege Management Unix & Linux and Active Directory Bridge
    Webinar
Related
  • AI Security: From a Threat Researcher’s Perspective
    Dec 17, 2025 AI Security: From a Threat Researcher’s Perspective
    On-demand we...
    29m
Share this Article
  • Link
Relevant Tags
  • Active Directory Webinars
  • AD Admin Training
  • AD Admin Webinars
  • AD CS Misconfigurations
  • Admin Best Practices
  • Admin Credentials Security
  • Admin Security Training
  • Best Practices
  • Cyber Security Education
  • Cyber Security Webcasts

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.