Privileged access and shadow admin analysis

Privilege that arrives indirectly behaves exactly like privilege that was granted.

Who can become a domain administrator

Domain administrator rights are rarely held only by the accounts that appear to hold them. MagenX names every identity that can reach the top of Active Directory and Microsoft Entra ID, whether the rights were granted, inherited, delegated or carried over from an older directory. The answer is a named list of people, service accounts and applications, each with the evidence that puts it there.

Where the privilege comes from

Reviewing the membership of the privileged groups misses the accounts that can add themselves to those groups at will.

  • Rights inherited from the directory structure rather than granted to the account
  • Authority delegated over accounts, groups, computers and group policy
  • Historical identifiers carried by accounts after a migration or a merger
  • The accounts that synchronise and administer the directory itself
  • Cloud roles held by identities that are weak on the on-premises side

What you get

Privileged accounts are scored into the same graph as the machines they sign in to and the network paths that reach them. Attack simulation walks that graph from a foothold you choose and names the single change that closes the most routes. Crown jewels works backwards from an asset you name and shows who can reach it. Scheduled scans record an administrator who appears between scans as an event.

FAQ

What is a shadow administrator?

An account that can obtain domain administrator rights without belonging to any group that says so. The rights usually arrive through inheritance, through delegation, or through an identity carried over from an older directory.

Does it cover cloud identities as well as on-premises accounts?

Yes. Microsoft Entra ID roles are read alongside the on-premises accounts they correspond to, so a privileged cloud role held by a weakly protected identity is one problem rather than two.

Every finding above is evidence you can hand to the person who owns the object.

Get a demo