The Next Internal Network: Why Your Old Playbook Doesn't Work

For more than two decades, internal penetration testing has followed a familiar objective: compromise Active Directory and become Domain Admin.

Our methodologies, tooling and even our mental models have been built around this goal. Kerberoasting, delegation abuse, AD CS attacks, DCSync and BloodHound became the playbook for understanding enterprise compromise.

But what happens when Domain Admin is no longer the most valuable privilege in the organisation?

Modern enterprises are rapidly shifting their trust away from traditional Windows domains. Identity providers grant access to critical business systems. SaaS platforms hold sensitive data and administrative control. Device management platforms decide which endpoints are trusted. Cloud management planes often provide broader influence than on-premises infrastructure, while OAuth applications and federated identity introduce entirely new attack paths.

This talk explores how the definition of the "internal network" is changing and why offensive security professionals need to rethink what successful compromise looks like.

Using examples inspired by real penetration testing engagements, we'll examine how attackers can chain together weaknesses across identity providers, cloud administration, SaaS platforms, device management and federated trust to achieve objectives that traditional Active Directory-focused methodologies may never uncover.

This isn't a talk about the death of Active Directory—it remains a critical component of many enterprise environments. Instead, it's about recognising that Active Directory is increasingly just one node in a much larger trust graph.

Whether you're a penetration tester, red teamer, blue teamer or security leader, you'll leave with a new perspective on where enterprise trust is moving, how attackers are adapting, and why the next generation of internal security assessments must look far beyond Domain Admin.


Today's organisations don't just run Active Directory—they run Microsoft 365, Entra ID, Intune, Google Workspace, cloud platforms, SaaS applications and dozens of interconnected identity providers. Yet many internal security assessments still focus primarily on compromising a Windows domain.

This talk challenges that assumption and offers a practical framework for understanding how enterprise trust is evolving. Rather than presenting isolated attack techniques, it encourages attendees to think differently about what constitutes meaningful compromise in modern environments and how both attackers and defenders need to adapt.

The speaker's profile picture
Dumi Masimini

Dumisani Masimini is a penetration tester and consultant at Worknest (former Pentest People), where he helps organisations understand and reduce their security risk through meaningful, action-focused assessments. With experience across internal infrastructure, web apps, and Active Directory environments, Dumisani is passionate about making technical findings accessible and impactful for every level of an organisation.