Identity Security Blog

Expert insights on Active Directory and Azure security vulnerabilities, hardening guides, and remediation best practices.

123 articles
Active Directory Trust SID Filtering Selective Authentication Audit: Detection and Remediation
ADTrustsKerberos

Active Directory Trust SID Filtering Selective Authentication Audit: Detection and Remediation

A practical Active Directory trust SID filtering and selective authentication audit checklist: what to check, the event IDs and PowerShell that expose drift, and how to fix each finding.

Entra App Registration Credential Rotation Secrets: Detection and Remediation
AzureApplicationsMonitoring

Entra App Registration Credential Rotation Secrets: Detection and Remediation

Entra app registration credential rotation secrets get forgotten until a leaked secret or stale certificate becomes an attacker's way in. Learn how to detect and remediate long-lived secrets, multiple active credentials, and certificate-based auth persistence.

Entra ID Nested Privileged Groups, Role-Assignable Groups, and Guests in Security Groups
AzureGroupsPrivileged Access

Entra ID Nested Privileged Groups, Role-Assignable Groups, and Guests in Security Groups

Entra ID nested privileged groups, role-assignable groups, and guests riding into security groups form a silent escalation path most tenants never audit.

Active Directory Cleartext Password Reversible Encryption: The userPassword Trap Explained
ADPasswordConfig

Active Directory Cleartext Password Reversible Encryption: The userPassword Trap Explained

Two Active Directory settings can leave passwords recoverable in cleartext: the userPassword attribute and the reversible-encryption UAC flag. Here's how to detect and fix both.

Entra ID Logging: Retention, Diagnostic Settings, SIEM Export Gaps
AzureConfigMonitoring

Entra ID Logging: Retention, Diagnostic Settings, SIEM Export Gaps

Entra ID sign-in and audit logs expire in 7-30 days by default and nothing is exported unless you configure it. Learn how to check, detect, and fix the three gaps: retention, diagnostic settings, and SIEM export.

Active Directory Tiered Admin Model: Building Tiers That Hold Up (ESAE to RAMP)
ADPrivileged AccessConfig

Active Directory Tiered Admin Model: Building Tiers That Hold Up (ESAE to RAMP)

Most "tiered" Active Directory builds don't actually enforce the tier boundary. Here's how the model works in practice — OUs, PAWs, GPO scoping — plus detection and remediation.

ADCS ESC9, ESC10, ESC11: Certificate Escalation Paths Beyond ESC1-ESC8
ADADCSAttack Paths

ADCS ESC9, ESC10, ESC11: Certificate Escalation Paths Beyond ESC1-ESC8

ADCS ESC9, ESC10, ESC11 certificate escalation extends the original ESC1-ESC8 paths into template flags, DC-wide mapping downgrades, and RPC relay. Detection and remediation for each.

Azure AD Premium P2 Features: PIM, Identity Protection, and Access Reviews Nobody Turned On
AzureCompliancePrivileged Access

Azure AD Premium P2 Features: PIM, Identity Protection, and Access Reviews Nobody Turned On

Azure AD Premium P2 costs roughly $9/user/month and bundles Privileged Identity Management, Identity Protection, and Access Reviews — but the license being assigned doesn't mean any of the three is actually configured. Here's how to check, and how to close the gap.

GPO SYSVOL cPassword Secrets Active Directory: Why a 2014 Patch Didn't Fix It
ADGPOPassword

GPO SYSVOL cPassword Secrets Active Directory: Why a 2014 Patch Didn't Fix It

GPO Preferences cPassword entries in SYSVOL are still decryptable years after MS14-025 patched the editing tools, not the exposed data itself. Learn how to find, verify, and permanently remove them.

Zerologon CVE-2020-1472 Enforcement Active Directory: Why It's Still Missing on So Many DCs
ADGPOAttack Paths

Zerologon CVE-2020-1472 Enforcement Active Directory: Why It's Still Missing on So Many DCs

Zerologon (CVE-2020-1472) enforcement is still missing on domain controllers years after the patch. Learn why the gap persists, how to detect it, and how to close it.

Everyone, Authenticated Users, Privileged Groups, Active Directory: How Built-Ins Get Silently Over-Membered
ADGroupsPermissions

Everyone, Authenticated Users, Privileged Groups, Active Directory: How Built-Ins Get Silently Over-Membered

Everyone or Authenticated Users landing directly in a privileged domain-local group, or Schema Admins/DnsAdmins staying populated between changes, hands out Tier 0 access with no ACL trick required.

Active Directory Dangerous User Rights GPO SeDebug SeTcb: SeLoadDriver Privilege Escalation to SYSTEM
ADGPOPrivileged Access

Active Directory Dangerous User Rights GPO SeDebug SeTcb: SeLoadDriver Privilege Escalation to SYSTEM

GPOs that grant SeDebug, SeLoadDriver, or SeTcb to non-admins hand any domain account a direct path to SYSTEM. Here's how to find and fix it.