BLOG

Windows enumeration in 2026: AD and Entra ID

Dit artikel is alleen in het Engels beschikbaar.

Enumeration is the quiet foundation of every internal assessment. Before any weakness is exploited, a tester builds a picture of the host, the domain, and the identities that hold power. This is a current view of Windows enumeration in 2026, and, as with every technique here, a view a defender can watch for. Only run this against systems you are authorised to test.

The local host

The first questions are simple: who am I, what can I do, and where am I. The built-in tools answer all three without installing anything.

whoami /all # user, groups, and privileges in one view
systeminfo # OS build, patch level, domain membership
net user; net localgroup administrators

The privileges list matters most. A token that holds SeImpersonatePrivilege or SeBackupPrivilege often changes what is possible on the host, which is why it is one of the first things a tester reads.

Active Directory

On a domain host, the interesting surface is the directory. The classic questions are which accounts exist, which groups are privileged, and which paths lead to them.

# Domain, users, and privileged groups
Get-ADDomain
Get-ADGroupMember "Domain Admins"
# Service accounts with a Service Principal Name are Kerberoast candidates
Get-ADUser -Filter {ServicePrincipalName -like "*"} -Properties ServicePrincipalName

The modern approach maps relationships rather than lists. Tooling such as BloodHound turns a directory into a graph of who can reach what, which surfaces indirect paths to high-value accounts that a flat list hides.

Enumeration in 2026 is about relationships, not lists; the shortest path to Domain Admin is rarely a direct one.

Entra ID and the hybrid boundary

Few environments are domain-only now. Most are hybrid, joining an on-premises directory to Entra ID, and the identity boundary is where interesting findings live. A tester checks how identities sync, which roles are held in the cloud tenant, and whether a foothold on premises can reach cloud-privileged accounts.

The point is the join. A device or account that bridges the on-premises directory and the cloud tenant is worth more than either side alone, because it can carry access across the boundary.

Living off the land, and what defenders see

Everything above uses signed, legitimate Windows tooling. That is deliberate; it avoids dropping files and blends into normal administration. It is also detectable, because the behaviour is unusual even when the tool is not.

Activity What a defender can watch for
whoami /all, net commands in sequence Recon-style command bursts from a single session
PowerShell AD queries Script block logging and LDAP queries from unusual hosts
Directory graphing tools Large, fast LDAP enumeration across the domain
Cross-boundary identity use Sign-ins that link an on-premises account to cloud-privileged roles

The defensive takeaway: enable PowerShell script block logging, alert on bulk LDAP queries, tier administrative accounts so a workstation foothold cannot reach Domain Admin directly, and treat the on-premises to cloud identity bridge as a critical control point.

Closing

Enumeration decides the rest of an internal test. Done well, it finds the short path that turns a single foothold into domain-wide access, and it does so with tools already present on the host. That is also the reason it is worth watching for; the tools are trusted, but the pattern is not.

For how this fits into a full internal assessment, see the infrastructure penetration testing service page.

Deel dit artikel LinkedIn X

Klaar om uw omgeving te beveiligen?

Plan een vrijblijvend intakegesprek om uw assessment af te stemmen. Pentrox identificeert kwetsbaarheden in uw applicaties, infrastructuur en cloudomgevingen voordat aanvallers dat doen.

Plan een intakegesprek