Active Directory Penetration Testing: A Guide for MSPs

Test a client's domain before an attacker does. Get a white-label engagement scoped in 24 hours.
Get a Pentest Quote
Active Directory Penetration Testing title graphic with a key icon on a dark MSP Pentesting branded background.

Active Directory penetration testing is a manual test of a client's Windows domain, the identity system almost every business runs on, to see whether an attacker holding one ordinary login can end up as Domain Admin. For MSPs, it's one of the highest-value tests you can offer, because once someone owns Active Directory, they own every server, every file, and every backup on the network.

Here's why it matters. AD is old, sprawling, and full of defaults nobody revisits, and the attacks against it don't lean on a fresh zero-day. They lean on misconfigurations that have been sitting there for years. MSP Pentesting runs the test under your brand, channel-only, and hands back a report with your logo showing exactly how far an attacker gets and how to shut it down. Below is what it targets, how it runs, and how you deliver it without an in-house red team.

What Active Directory penetration testing actually is

It's a hands-on assessment that starts where a real attacker usually starts: as a low-privileged user, or an unauthenticated device sitting on the network. From there the tester works the domain, collecting credentials, abusing misconfigurations, and climbing toward full control. The point isn't a list of settings. It's proof of how a breach actually plays out on this specific network.

The attack paths it goes after

Attack paths an Active Directory penetration test goes after: Kerberoasting, AS-REP roasting, LLMNR and NBT-NS poisoning, Pass-the-Hash and Pass-the-Ticket, unconstrained delegation abuse, DCSync, Golden and Silver ticket forgery, and weak Domain Admin passwords.
The attack paths that turn one login into Domain Admin.

Most of these aren't exotic. Kerberoasting pulls crackable passwords out of service tickets. AS-REP roasting hits accounts that never required pre-authentication. LLMNR and NBT-NS poisoning grabs credential hashes straight off the wire. Pass-the-Hash and Pass-the-Ticket reuse those credentials without ever cracking them. DCSync quietly pulls the entire password database from a domain controller. Golden and Silver tickets forge Kerberos tickets that look completely legitimate. And underneath all of it, the plain old weak or reused Domain Admin password still does most of the damage. This is the default state of a domain nobody has hardened, not some rare edge case.

How an Active Directory pentest works

Five-step Active Directory penetration testing process: enumerate the domain, capture credentials, escalate privilege, reach Domain Admin, report and retest.
One weak account is usually all it takes. We prove it, then help you close it.

It starts by enumerating the domain, the users, groups, service accounts, and trust relationships that make up the attack surface. Then the tester captures credentials, through poisoning, roasting, or whatever the environment hands over. From there they escalate, chaining misconfigurations until they reach Domain Admin or its equivalent. Every step is documented as it happens, and once the client remediates, the tester retests to confirm the paths are closed.

Why a scan will not find this

A vulnerability scanner checks patch levels and known CVEs. Most AD attacks aren't missing patches. They're misconfigurations and trust relationships a scanner can't reason about. Kerberoasting a service account looks like valid behavior right up until it isn't. Only a person following the chain from one account to the next actually finds it, which is exactly why this is a manual test.

When your clients need one

Any client running a Windows domain, which is most of them, especially after a migration, a merger, or years of IT staff turnover leaving old accounts and permissions behind. Any client under SOC 2, PCI DSS, or HIPAA, where internal testing is expected. And any client who has been breached before, because Active Directory is where attackers dig in to stay.

How MSPs deliver AD pentests without a red team

You don't need to hire domain-attack specialists to offer this. Scope the engagement with your client, hand the testing to a channel-only partner, and the report comes back under your brand. Your client sees your logo and your expertise, not ours. That's what white-label pentesting is built for, and AD testing is one of the most impressive deliverables you can put in front of a client, because the attack-path story lands hard.

What the report gives you

The report walks the exact path from first foothold to domain control, so the client can see the movie, not just a list. Each finding is rated by real impact, with concrete fixes: tiered admin, disabling LLMNR, cleaning up delegation, rotating service account passwords, deploying LAPS. Then a retest confirms the fixes held. Branded to you, clean, and specific enough that the client's IT team can actually act on it. If you want to brush up on one of the mechanics behind these attacks, our explainer on NTLM covers a big piece of it, and you can get a pentest quote when a client is ready.

Frequently asked questions

Is Active Directory penetration testing the same as a network pentest?

Not quite. A network pentest is broader. An AD pentest is a focused internal test of the domain and its identity layer, and it's often the most valuable part of an internal engagement. Many clients want both scoped together.

Can a vulnerability scan catch these issues?

No. Most AD attacks are misconfigurations and credential abuse, not missing patches, so a scanner walks right past them. They need manual testing.

What do you need from the client to start?

Usually either a standard low-privileged domain account and network access, which mirrors a phished employee, or a fully unauthenticated position on the network. Both are common starting points depending on what the client wants to simulate.

How often should a domain be tested?

At least once a year, and again after any major change, a migration, a merger, a domain restructure, or a big shift in IT staff.

The bottom line

Active Directory is the master key to almost every client network, and it's usually full of quiet misconfigurations that a scanner will never surface. Active Directory penetration testing proves how an attacker turns one login into total control, then gives the client a clear path to shut it down. Enumerate the domain, capture the credentials, walk the path to Domain Admin, prove it, and hand the client a report with your brand on it.

Author

Sunil Kande

Pentest Expert

Sunil is a pentester focused on web and mobile security, specializing in finding deep vulnerabilities beyond surface-level testing. His approach combines manual analysis, reverse engineering, and creative problem-solving to uncover impactful security issues.

Join our MSP Partner Program

Want Access to Reseller Pricing? Sample Reports? Resources?
Meet with a member of MSP Pentesting to get access.