Active Directory is one of those things that "just works" in most Windows environments, which is exactly why attackers love it. When something in the authentication chain can be bent the wrong way, the blast radius isn't a single machine. It's the entire domain.

