CISA, partners update guidance on Microsoft compromises

September 16, 2026 / By ICBA

The Cybersecurity and Infrastructure Security Agency and international partners updated guidance on detecting and mitigating Microsoft Active Directory compromises.

Details: The guidance:

  • Describes 17 common techniques threat actors use to compromise Active Directory.

  • Provides an expansion to the "Detecting DCSync" and "Shadow Credentials" sections, highlighting new methods for threat actors to gain access to accounts in a Windows domain while evading detection.