Identity Security Blog

Expert insights on Active Directory and Azure security vulnerabilities, hardening guides, and remediation best practices.

123 articles
Entra Guest Admin Role Cross Tenant B2B Trust: How External Users Reach Global Administrator
AzureGuest ExternalPrivileged Access

Entra Guest Admin Role Cross Tenant B2B Trust: How External Users Reach Global Administrator

An external guest holding an Entra directory role, combined with wide-open cross-tenant B2B trust settings, is a governance gap most tenants never audit.

Entra ID SSPR Registered Methods Only November 2026: What Breaks and How to Fix It
AzureIdentityPassword

Entra ID SSPR Registered Methods Only November 2026: What Breaks and How to Fix It

Starting November 9, 2026, Entra ID SSPR stops accepting unregistered directory phone/email as fallback verification. Here's what changes, how to find exposed users, and how to fix it.

Active Directory Monitoring Blind Spots: Display Specifiers, RODC, Default Domain Policy Tampering, and PAM Shadow Principals
ADAdvancedComputers

Active Directory Monitoring Blind Spots: Display Specifiers, RODC, Default Domain Policy Tampering, and PAM Shadow Principals

Four Active Directory objects most monitoring programs never watch: display specifiers, Default Domain Policy edits, PAM shadow principals, and RODC credential caching. Context, detection, and fixes.

Entra App Registration Dangerous Graph API Permissions: Detection and Remediation
AzureApplicationsPermissions

Entra App Registration Dangerous Graph API Permissions: Detection and Remediation

Directory.ReadWrite.All, Mail.ReadWrite, Files.ReadWrite.All, and RoleManagement.ReadWrite.Directory can turn a leaked app credential into full Global Administrator control. Here's how the escalation works, how to detect the grants, and how to remediate them.

Domain Controller LDAPS Weak TLS, Print Spooler, Time Sync Audit: A Network Hygiene Checklist
ADNetworkMonitoring

Domain Controller LDAPS Weak TLS, Print Spooler, Time Sync Audit: A Network Hygiene Checklist

Weak TLS on LDAPS, a Print Spooler nobody disabled, and clock drift past the Kerberos tolerance: three DC network settings that skip most AD reviews. Here's how to audit and fix all three.

Exchange Privilege Escalation WriteDacl Domain Active Directory: How a Decade-Old Install Still Hands Out Domain Admin
ADAttack PathsPermissions

Exchange Privilege Escalation WriteDacl Domain Active Directory: How a Decade-Old Install Still Hands Out Domain Admin

On-prem Exchange still grants WriteDacl on the AD domain object by default in many environments — a quiet path to DCSync and Domain Admin that outlives the 2019 disclosure that made it famous.

Entra ID Custom Controls Retirement External Authentication Methods: Migration Guide Before September 2026
AzureConditional AccessIdentity

Entra ID Custom Controls Retirement External Authentication Methods: Migration Guide Before September 2026

Microsoft is deprecating Custom Controls in Entra Conditional Access, with edits blocked from September 2026 and full retirement by May 2027 — here's how to detect affected policies and migrate to External MFA.

RODC Privileged Credential Caching: Read-Only Domain Controller Holds Domain Admin Hashes
ADComputersPrivileged Access

RODC Privileged Credential Caching: Read-Only Domain Controller Holds Domain Admin Hashes

A misconfigured Password Replication Policy can let an RODC cache Domain Admin credentials — turning physical compromise into full domain compromise.

August 2026 Patch Tuesday Active Directory Domain Controller RCE: 3 Flaws You Can't Defer
ADADCSNetwork

August 2026 Patch Tuesday Active Directory Domain Controller RCE: 3 Flaws You Can't Defer

August 2026 Patch Tuesday shipped three domain-controller-critical RCEs — Windows DNS Server, AD CS, and AD DS. What's confirmed, what to watch for, and what to patch first.

Entra Provisioning Service Vulnerability CVE-2026-59115: Two Critical SyncFabric EoP Flaws
AzureIdentityPrivileged Access

Entra Provisioning Service Vulnerability CVE-2026-59115: Two Critical SyncFabric EoP Flaws

Two Critical EoP CVEs, CVE-2026-59115 and CVE-2026-57100, hit Microsoft Entra Provisioning Service (SyncFabric). What's confirmed and what to do.

Active Directory ACL DPAPI Tombstone Schema Permissions Audit: 3 Rights Nobody Checks
ADPermissionsMonitoring

Active Directory ACL DPAPI Tombstone Schema Permissions Audit: 3 Rights Nobody Checks

Every active directory ACL audit checks GenericAll and DCSync. Three other high-impact rights — DPAPI master key access, tombstone reanimation, and schema permissions — almost never get reviewed.

PowerShell Script Block Logging Active Directory GPO: What You're Missing
ADGPOMonitoring

PowerShell Script Block Logging Active Directory GPO: What You're Missing

Most Active Directory environments still leave PowerShell script block, module, and transcription logging off by default — the three GPO settings that make fileless PowerShell tradecraft visible instead of invisible.