Identity Security Blog

Expert insights on Active Directory and Azure security vulnerabilities, hardening guides, and remediation best practices.

138 articles
Active Directory Backup Operators, Print Operators, Server Operators Privilege Escalation: The Groups Nobody Audits
ADAccountsGroups

Active Directory Backup Operators, Print Operators, Server Operators Privilege Escalation: The Groups Nobody Audits

Backup Operators, Print Operators, Server Operators, and Account Operators sit outside Domain Admins but each holds a built-in path to full domain controller compromise.

Conditional Access Register Security Information Windows Hello macOS Platform SSO Scope Change (July 13, 2026)
AzureConditional AccessIdentity

Conditional Access Register Security Information Windows Hello macOS Platform SSO Scope Change (July 13, 2026)

From July 13, 2026, Conditional Access scoped to 'Register security information' also governs Windows Hello for Business and macOS Platform SSO registration.

Active Directory DNS Zone Transfer Insecure Dynamic Update Security: Detection and Remediation
ADNetworkConfig

Active Directory DNS Zone Transfer Insecure Dynamic Update Security: Detection and Remediation

Active Directory DNS zone transfer, insecure dynamic update, and a default ACL that lets Authenticated Users write records: three chainable AD-integrated DNS gaps attackers use for recon and MITM.

Entra Guest Admin Role Cross Tenant B2B Trust: How External Users Reach Global Administrator
AzureGuest ExternalPrivileged Access

Entra Guest Admin Role Cross Tenant B2B Trust: How External Users Reach Global Administrator

An external guest holding an Entra directory role, combined with wide-open cross-tenant B2B trust settings, is a governance gap most tenants never audit.

Entra ID SSPR Registered Methods Only November 2026: What Breaks and How to Fix It
AzureIdentityPassword

Entra ID SSPR Registered Methods Only November 2026: What Breaks and How to Fix It

Starting November 9, 2026, Entra ID SSPR stops accepting unregistered directory phone/email as fallback verification. Here's what changes, how to find exposed users, and how to fix it.

Active Directory Monitoring Blind Spots: Display Specifiers, RODC, Default Domain Policy Tampering, and PAM Shadow Principals
ADAdvancedComputers

Active Directory Monitoring Blind Spots: Display Specifiers, RODC, Default Domain Policy Tampering, and PAM Shadow Principals

Four Active Directory objects most monitoring programs never watch: display specifiers, Default Domain Policy edits, PAM shadow principals, and RODC credential caching. Context, detection, and fixes.

Entra App Registration Dangerous Graph API Permissions: Detection and Remediation
AzureApplicationsPermissions

Entra App Registration Dangerous Graph API Permissions: Detection and Remediation

Directory.ReadWrite.All, Mail.ReadWrite, Files.ReadWrite.All, and RoleManagement.ReadWrite.Directory can turn a leaked app credential into full Global Administrator control. Here's how the escalation works, how to detect the grants, and how to remediate them.

Domain Controller LDAPS Weak TLS, Print Spooler, Time Sync Audit: A Network Hygiene Checklist
ADNetworkMonitoring

Domain Controller LDAPS Weak TLS, Print Spooler, Time Sync Audit: A Network Hygiene Checklist

Weak TLS on LDAPS, a Print Spooler nobody disabled, and clock drift past the Kerberos tolerance: three DC network settings that skip most AD reviews. Here's how to audit and fix all three.

Exchange Privilege Escalation WriteDacl Domain Active Directory: How a Decade-Old Install Still Hands Out Domain Admin
ADAttack PathsPermissions

Exchange Privilege Escalation WriteDacl Domain Active Directory: How a Decade-Old Install Still Hands Out Domain Admin

On-prem Exchange still grants WriteDacl on the AD domain object by default in many environments — a quiet path to DCSync and Domain Admin that outlives the 2019 disclosure that made it famous.

Entra ID Custom Controls Retirement External Authentication Methods: Migration Guide Before September 2026
AzureConditional AccessIdentity

Entra ID Custom Controls Retirement External Authentication Methods: Migration Guide Before September 2026

Microsoft is deprecating Custom Controls in Entra Conditional Access, with edits blocked from September 2026 and full retirement by May 2027 — here's how to detect affected policies and migrate to External MFA.

RODC Privileged Credential Caching: Read-Only Domain Controller Holds Domain Admin Hashes
ADComputersPrivileged Access

RODC Privileged Credential Caching: Read-Only Domain Controller Holds Domain Admin Hashes

A misconfigured Password Replication Policy can let an RODC cache Domain Admin credentials — turning physical compromise into full domain compromise.

August 2026 Patch Tuesday Active Directory Domain Controller RCE: 3 Flaws You Can't Defer
ADADCSNetwork

August 2026 Patch Tuesday Active Directory Domain Controller RCE: 3 Flaws You Can't Defer

August 2026 Patch Tuesday shipped three domain-controller-critical RCEs — Windows DNS Server, AD CS, and AD DS. What's confirmed, what to watch for, and what to patch first.