Identity Security Blog

Expert insights on Active Directory and Azure security vulnerabilities, hardening guides, and remediation best practices.

123 articles
Entra Connect Sync Mandatory Upgrade September 2026: Why 2.5.79.0 Is the Wrong Target
ADAzureIdentityConfig

Entra Connect Sync Mandatory Upgrade September 2026: Why 2.5.79.0 Is the Wrong Target

The Entra Connect Sync mandatory upgrade September 2026 deadline stops all synchronization on servers below version 2.5.79.0 - and 2.5.79.0 itself falls out of support 23 days later. What the deadline really says, how to check your servers, and which build to actually target.

Entra ID Tenant Default User Settings Restrict App Registration, Group Creation, and Admin Center Access
AzureApplicationsConfig

Entra ID Tenant Default User Settings Restrict App Registration, Group Creation, and Admin Center Access

Entra ID tenant default user settings restrict app registration and group creation only once an admin changes them. Until then, every user can. Here are the four switches that close the gap.

Windows Server 2016 End of Support: Active Directory Domain Controller Upgrade Before January 12, 2027
ADComputersCompliance

Windows Server 2016 End of Support: Active Directory Domain Controller Upgrade Before January 12, 2027

Windows Server 2016 extended support ends January 12, 2027. The hard part is not the domain controllers — it is the handful of legacy hosts that hold your whole domain at their security level.

krbtgt Password Rotation, Trust Account, Domain Controller Machine Password: The Three AD Secrets That Never Rotate Themselves
ADKerberosPassword

krbtgt Password Rotation, Trust Account, Domain Controller Machine Password: The Three AD Secrets That Never Rotate Themselves

Two of Active Directory's three long-lived secrets rotate themselves only while nothing is broken, and the third never rotates at all. How to check and fix all three.

Entra ID Risk Protection: Leaked Credentials, Risky Users Not Remediated
AzureRisk ProtectionIdentity

Entra ID Risk Protection: Leaked Credentials, Risky Users Not Remediated

Entra ID Risk Protection detects leaked credentials natively — the real gap is response. Learn why risky users stay at risk for months, and how to measure and drain the backlog with KQL and Graph.

Active Directory Dangerous ACE Orphaned SID Cross Domain Permissions Audit: The ACL Abuse Most Tools Can't Even Resolve
ADPermissionsAttack Paths

Active Directory Dangerous ACE Orphaned SID Cross Domain Permissions Audit: The ACL Abuse Most Tools Can't Even Resolve

Some Active Directory ACEs grant full control to a SID that resolves to no principal at all. Most ACL reviews skip them silently. Here is how to find and fix them.

Active Directory AS-REP Roasting Privileged Service Accounts: The Accounts Pre-Auth Was Supposed to Protect
ADKerberosAccounts

Active Directory AS-REP Roasting Privileged Service Accounts: The Accounts Pre-Auth Was Supposed to Protect

Privileged accounts and service accounts with Kerberos pre-auth disabled turn AS-REP roasting into a fast, quiet path to Domain Admin — here's how to detect and fix it.

CVE-2026-62869 Entra ID Spoofing Vulnerability: What It Means for Identity Trust
AzureIdentityConditional Access

CVE-2026-62869 Entra ID Spoofing Vulnerability: What It Means for Identity Trust

CVE-2026-62869 let an authenticated attacker spoof identity-related data in Entra ID over the network. Already patched — what CWE-345 means for detection and hardening.

Active Directory Domain Controller Computer Object Hygiene LAPS Schema: Six Gaps a Live Audit Keeps Finding
ADComputersMonitoring

Active Directory Domain Controller Computer Object Hygiene LAPS Schema: Six Gaps a Live Audit Keeps Finding

Active Directory domain controller computer object hygiene laps schema gaps most audits miss: an unextended LAPS schema, misplaced DCs, stale computers, and machine passwords that stopped rotating.

Conditional Access Report-Only Mode, Stale Exclusions: Policies That Aren't Really Enforced
AzureConditional AccessIdentity

Conditional Access Report-Only Mode, Stale Exclusions: Policies That Aren't Really Enforced

A Conditional Access policy can exist, look correctly configured, and still block nothing — because it never left report-only mode, or because its exclusion list quietly grew past its original intent.

SIDHistory Injection: Well-Known SID Privilege Escalation to Domain Admin
ADAccountsAdvanced

SIDHistory Injection: Well-Known SID Privilege Escalation to Domain Admin

SIDHistory injection lets an attacker write a well-known Domain Admins SID into a low-privilege account's sIDHistory, granting silent domain-dominance access invisible to group membership audits.

Entra Hybrid Identity Sync Cloud Only Privileged Orphaned Accounts: The Hybrid Audit Blind Spot
AzureIdentityPrivileged Access

Entra Hybrid Identity Sync Cloud Only Privileged Orphaned Accounts: The Hybrid Audit Blind Spot

Two hybrid identity sync blind spots: cloud-only privileged Entra roles that skip Tier 0 governance, and orphaned synced users that outlive deleted AD accounts.