The update adds detections defenders can actually build

Australia’s ASD published the updated joint guidance with CISA, NSA, the Canadian Centre for Cyber Security, New Zealand’s NCSC, and the UK NCSC on 15 September 2026. The publication covers common compromise paths across Active Directory Domain Services, Certificate Services, and Federation Services.

The clearest additions are a preferred RPC-based method for detecting suspicious directory replication and a new section on shadow credentials. The guidance also expands its practical advice on canary objects and the event data needed to turn known attack techniques into useful detections.

The central lesson

Active Directory attacks often use legitimate protocols and permissions. A single event ID rarely proves compromise. The signal comes from knowing which identities, systems, and workflows are allowed to perform a sensitive action—and investigating activity outside that baseline.

Start with replication and key credentials

Use caseTelemetryWhat makes it meaningful
DCSync via RPCSecurity Event ID 5712 on domain controllersMatch the DRS replication interface and operation, then alert when the account or remote IP is outside the approved replication baseline.
DCSync correlationEvent 5712 with Event 4624 when neededUse the logon identifier to recover connection context where a non-default SMB replication path omits the remote IP.
Shadow credentialsSecurity Event ID 5136Filter for changes to msDS-KeyCredentialLink and compare the actor with approved Windows Hello for Business or other passwordless provisioning services.
Directory enumeration canaryFailed Event ID 4662Match the GUID of a deliberately unreadable canary object. A read attempt is high-value because normal users and services should never touch it.

The RPC approach requires Windows Server 2019 or later on every domain controller and the October 2025 cumulative update or later. Where that prerequisite is not met, teams should follow the document’s directory-service-access alternative and record the telemetry cost.

Turn the document into an identity defense backlog

  1. 1

    Map Tier 0. Identify domain controllers, privileged groups, KRBTGT, AD CS, AD FS, Entra Connect, backup systems, administrative workstations, replication identities, and every route that can administer them.

  2. 2

    Baseline legitimate replication. List the domain controllers and approved services that replicate directory data, along with their accounts, source addresses, schedule, and expected volume. Test the Event 5712 collection path before writing an alert.

  3. 3

    Govern msDS-KeyCredentialLink. Limit who can modify the attribute, review delegated rights, inventory objects with key credentials, and maintain a list of authorised passwordless provisioning services.

  4. 4

    Build behavior-led detections. Correlate Kerberos, directory changes, logons, privilege changes, certificate activity, and endpoint telemetry. Tune against service accounts and administrative workflows rather than suppressing noisy events wholesale.

  5. 5

    Plant and protect canaries. Use well-documented canary objects that legitimate operations will not query. Restrict who knows their purpose, monitor their GUIDs, and rehearse the investigation that follows a hit.

  6. 6

    Exercise domain recovery. Tabletop a stolen replication identity, a malicious key credential, and suspected domain-admin compromise. Include evidence preservation, credential rotation, KRBTGT reset sequencing, cloud trust, backups, and business recovery.

Detection cannot compensate for uncontrolled privilege

  • Use separate privileged accounts and prevent Tier 0 credentials from being exposed to lower-trust systems.
  • Replace conventional service accounts with group Managed Service Accounts where supported; otherwise use long, unique, managed credentials and minimal privilege.
  • Reduce membership in Domain Admins, Enterprise Admins, Key Admins, and Enterprise Key Admins, and review nested or delegated privilege paths.
  • Disable legacy authentication and unnecessary services only through a tested migration plan, with exceptions documented and monitored.
  • Keep domain controllers dedicated to directory services, centralise their logs, and validate that logging survives an attacker’s attempt to interfere with it.
  • Use separate privileged identities for on-premises Active Directory and Microsoft Entra ID so one compromise does not automatically bridge both environments.

Canaries and event IDs are layers, not verdicts

Event 5136 records many legitimate directory changes. Event 5712 becomes useful only after the organisation identifies expected replication. A canary can reveal broad enumeration, but it may not trigger when an attacker targets a small set of known objects.

The publication is a strong control catalogue, but each environment still needs its own inventory, baselines, retention, response thresholds, and testing. Teams should measure whether the necessary events reach the SIEM with enough context to support a decision—not merely whether an audit policy says they are enabled.

How this analysis was prepared

This topic was surfaced by The Cyber Security Hub newsletter on LinkedIn. Threat Field Notes independently reviewed the updated joint guidance and produced this operational summary in original language.