Active Directory is the foundation of identity and access management in a Windows Server based IT infrastructure and virtually every aspect of IT management and security are completely tied to Active Directory, and in particular to Active Directory security access control lists (ACLs).
In addition, numerous administrative personnel with varying levels of administrative access have the authority required to modify permissions granted on thousands of objects stored in and protected by Active Directory, whether it be for delegating administration, or facilitating access via security groups, or providing helpdesk support.
The widespread impact that even a small change can have in Active Directory is worthy of note. For example, due to the inheritance of permissions in Active Directory, a single change made on a single object, has the potential to instantly and silently impact the security of thousands of objects.
Similarly, a simple change to the membership of an Active Directory group has the potential to instantly grant or revoke access to thousands of individuals on thousands of Active Directory objects and other IT assets stored on computers joined to the Active Directory.
Thus, ultimately, during the course of a day, the state of permissions granted in Active Directory and the membership of security groups invariably change every day, impacting the resultant access authorized consequently impacting delegation grants made in Active Directory. This core situation holds even when a proxy based solution is deployed.
That is why is it is very important to assess delegated grants in an Active Directory deployment on a daily basis.