Glossary
Honeytoken
A honeytoken is a decoy account, credential or object planted in AD that has no legitimate use, so any interaction with it signals an intruder.
A honeytoken is bait. In Active Directory it can be a user account that looks privileged but is never used, an account with a fake service principal name (a "honey SPN") that tempts Kerberoasting, a decoy credential left where attackers look for passwords, or an object with an attractive-looking ACL. Because nothing legitimate should ever authenticate as, request a ticket for, or read these objects, the alerting logic is simple: any matching event — a 4769 ticket request, a 4625 failed logon or a 4662 object access — is suspicious by definition.
It matters because most detection rules must separate attacker behaviour from normal noise, which is hard in busy domains. Honeytokens flip that problem: they produce very few, high-confidence alerts early in an intrusion, during reconnaissance and credential harvesting, before real damage. Make them believable (realistic names, group memberships, password age), make sure they cannot actually grant access, configure the relevant auditing, and route their alerts to responders with a clear playbook.
See Honeytokens and deception in AD and AD auditing and detection.