Identity Security Blog

Expert insights on Active Directory and Azure security vulnerabilities, hardening guides, and remediation best practices.

123 articles
Active Directory Disabled Expired Locked Accounts Privileged Groups: Why Admin Rights Persist
ADAccountsPrivileged Access

Active Directory Disabled Expired Locked Accounts Privileged Groups: Why Admin Rights Persist

A disabled admin account is a missed offboarding step. A locked one can mean an active password-spray attack. Here's how to find both, plus the orphaned adminCount residue between them.

Group Managed Service Account (GMSA) Password Exposure Active Directory: When Auto-Rotation Isn't a Security Boundary
ADGroupsPassword

Group Managed Service Account (GMSA) Password Exposure Active Directory: When Auto-Rotation Isn't a Security Boundary

gMSA passwords auto-rotate so no human ever has to know them — but the msDS-GroupMSAMembership attribute that gates who can read that password is routinely left too broad, handing attackers a clean impersonation path.

Entra PIM Activation Approval MFA Justification Misconfiguration
AzurePrivileged AccessIdentity

Entra PIM Activation Approval MFA Justification Misconfiguration

Enabling Microsoft Entra PIM doesn't harden anything by itself. If role activation skips approval, MFA, and justification, and allows 8+ hour windows, PIM becomes a formality attackers walk straight through.

Entra Self-Service Password Reset (SSPR) Security Gaps: Not Enabled, Not Required for Admins, Weak Reset Methods
AzureIdentityPassword

Entra Self-Service Password Reset (SSPR) Security Gaps: Not Enabled, Not Required for Admins, Weak Reset Methods

SSPR is usually deployed to cut helpdesk tickets, not as a security control — which is how it ends up disabled, skipped for admins, or backed by guessable security questions. Detection and remediation for all three gaps.

Active Directory Machine Account Quota (ms-DS-MachineAccountQuota): The Default That Lets Any User Add a Computer
ADComputersConfig

Active Directory Machine Account Quota (ms-DS-MachineAccountQuota): The Default That Lets Any User Add a Computer

By default, ms-DS-MachineAccountQuota lets any Active Directory user join 10 computers to the domain — the quiet root cause behind RBCD and NTLM relay escalation chains.

Anonymous LDAP Access dsHeuristics Active Directory Enumeration: How One Weak Attribute Exposes Your Whole Domain
ADAdvancedConfig

Anonymous LDAP Access dsHeuristics Active Directory Enumeration: How One Weak Attribute Exposes Your Whole Domain

A single character in dsHeuristics can silently re-enable anonymous LDAP binds, letting attackers with zero credentials enumerate your entire Active Directory domain.

Entra Service Principal Admin Role Over-Privileged: How to Detect and Fix It
AzurePrivileged AccessApplications

Entra Service Principal Admin Role Over-Privileged: How to Detect and Fix It

Over-privileged, ownerless, disabled-but-permissioned, and external-org service principals holding Entra admin roles are a standing, MFA-proof admin surface. Detection queries and remediation steps.

Conditional Access Baseline Policy Coverage Gaps, Entra ID: No Policy for Admins, All Users, or All Apps
AzureConditional AccessIdentity

Conditional Access Baseline Policy Coverage Gaps, Entra ID: No Policy for Admins, All Users, or All Apps

Conditional access baseline policy coverage gaps in Entra ID aren't a misconfigured policy — they're the complete absence of one covering admin roles, all users, all cloud apps, or device compliance.

AdminSDHolder SDProp Backdoor Active Directory Persistence: The Hourly Process for Permanent Privileged Access
ADPermissionsAdvanced

AdminSDHolder SDProp Backdoor Active Directory Persistence: The Hourly Process for Permanent Privileged Access

AdminSDHolder SDProp backdoor active directory persistence lets attackers plant permanent privileged access that survives password resets and group changes.

Active Directory Backup Operators, Print Operators, Server Operators Privilege Escalation: The Groups Nobody Audits
ADAccountsGroups

Active Directory Backup Operators, Print Operators, Server Operators Privilege Escalation: The Groups Nobody Audits

Backup Operators, Print Operators, Server Operators, and Account Operators sit outside Domain Admins but each holds a built-in path to full domain controller compromise.

Conditional Access Register Security Information Windows Hello macOS Platform SSO Scope Change (July 13, 2026)
AzureConditional AccessIdentity

Conditional Access Register Security Information Windows Hello macOS Platform SSO Scope Change (July 13, 2026)

From July 13, 2026, Conditional Access scoped to 'Register security information' also governs Windows Hello for Business and macOS Platform SSO registration.

Active Directory DNS Zone Transfer Insecure Dynamic Update Security: Detection and Remediation
ADNetworkConfig

Active Directory DNS Zone Transfer Insecure Dynamic Update Security: Detection and Remediation

Active Directory DNS zone transfer, insecure dynamic update, and a default ACL that lets Authenticated Users write records: three chainable AD-integrated DNS gaps attackers use for recon and MITM.