Identity Security Blog

Expert insights on Active Directory and Azure security vulnerabilities, hardening guides, and remediation best practices.

123 articles
PrintNightmare, Point-and-Print, GPO Hardening, Active Directory: The Two-Value Fix Nobody Finished
ADGPOCompliance

PrintNightmare, Point-and-Print, GPO Hardening, Active Directory: The Two-Value Fix Nobody Finished

Stopping the spooler on your DCs removed one privileged target and left the driver-installation path open on every workstation. PrintNightmare is a two-value fix — here is the half most fleets never finished.

Entra Delegated Versus Application Graph API Permissions Least Privilege: The Consent Model Most Tenants Get Backwards
AzureApplicationsPermissions

Entra Delegated Versus Application Graph API Permissions Least Privilege: The Consent Model Most Tenants Get Backwards

Delegated Graph permissions are not the safe ones. A tenant-wide AllPrincipals grant pre-authorises an app against every user in your directory — and lives in a collection that app-role reviews never read.

ADCS ESC2, ESC3, ESC5, ESC7: Certificate Escalation Paths Between the Famous Ones
ADADCSAttack Paths

ADCS ESC2, ESC3, ESC5, ESC7: Certificate Escalation Paths Between the Famous Ones

ADCS ESC2, ESC3, ESC5, and ESC7 fill the gap between the well-known ESC1-ESC8 and ESC9-ESC11 paths: broad EKUs, enrollment agents, and PKI/CA object ACLs.

Conditional Access Session Controls, Sign-In Frequency, Named Locations: What Actually Revokes a Live Token
AzureConditional AccessIdentity

Conditional Access Session Controls, Sign-In Frequency, Named Locations: What Actually Revokes a Live Token

Sign-in frequency does not revoke a token that already exists — it only bites when the session is next evaluated. Here is when Entra ID actually re-checks a policy, why continuous access evaluation ignores country-based named locations, and how to audit both.

LDAP Channel Binding, Domain Controller, NTLM Relay, LDAPS: The Half of the 2020 Advisory Nobody Finished
ADNetworkAdvanced

LDAP Channel Binding, Domain Controller, NTLM Relay, LDAPS: The Half of the 2020 Advisory Nobody Finished

LDAP signing and LDAP channel binding are two controls, not one. Signing leaves port 636 open to relay, and the channel binding value does not exist until you create it.

Entra Conditional Access Licensing Overage Warning: What the New Banner Actually Means
AzureConditional AccessIdentity

Entra Conditional Access Licensing Overage Warning: What the New Banner Actually Means

Entra now warns that your Conditional Access policies protect more users than your licences allow. The banner is informational — but the count it uses understates your real P1 exposure.

Active Directory Duplicate SPN, WriteSPN Abuse, Kerberos Downgrade: Inside CVE-2026-25177 (KerberLoss)
ADKerberosPermissions

Active Directory Duplicate SPN, WriteSPN Abuse, Kerberos Downgrade: Inside CVE-2026-25177 (KerberLoss)

CVE-2026-25177 (KerberLoss) let any WriteSPN holder plant an invisible-Unicode duplicate SPN, break Kerberos forest-wide, and force clients onto NTLM.

CVE-2026-50481 Azure Active Directory Elevation of Privilege: The CVSS 9.9 You Cannot Patch
AzurePrivileged AccessIdentity

CVE-2026-50481 Azure Active Directory Elevation of Privilege: The CVSS 9.9 You Cannot Patch

Microsoft rated CVE-2026-50481 a CVSS 9.9 Azure Active Directory privilege escalation, then shipped no patch — the fix was server-side. Here is what you can still verify in your own tenant.

ResetNightmare CVE-2026-27912, Kerberos Change Password, Active Directory: Writing Your Own userPrincipalName Is Enough to Reset a Domain Admin
ADKerberosPassword

ResetNightmare CVE-2026-27912, Kerberos Change Password, Active Directory: Writing Your Own userPrincipalName Is Enough to Reset a Domain Admin

CVE-2026-27912 lets an attacker who can write the userPrincipalName of any account reset a Domain Admin password over the Kerberos change password protocol, because that flow never performs a TGS-REQ.

Windows Hello for Business Standalone MFA Factor Entra October 2026: The Second Passkey Requirement Disappears
AzureConditional AccessIdentity

Windows Hello for Business Standalone MFA Factor Entra October 2026: The Second Passkey Requirement Disappears

From early October 2026, Entra treats Windows Hello for Business and macOS Platform SSO as standalone MFA factors. No config change is required — which is exactly the problem.

Kerberos Armoring (FAST): Active Directory Flexible Authentication Secure Tunneling Is Off by Default
ADKerberosGPO

Kerberos Armoring (FAST): Active Directory Flexible Authentication Secure Tunneling Is Off by Default

Kerberos armoring (FAST) protects AD pre-authentication data, but both Group Policy settings that enable it ship Not Configured. Detection and staged rollout.

Entra Service Principal Sign-In Anomaly Detection: Workload Identity Blind Spots
AzureApplicationsMonitoring

Entra Service Principal Sign-In Anomaly Detection: Workload Identity Blind Spots

Service principals cannot perform MFA, are missed by ordinary Conditional Access, and their sign-ins live in a separate log stream. Learn to baseline and detect anomalies on the identities holding your widest Graph permissions.