Identity Security Blog

Expert insights on Active Directory and Azure security vulnerabilities, hardening guides, and remediation best practices.

133 articles
DCShadow Attack Rogue Domain Controller Registration: How It Bypasses AD Change Auditing
ADAdvancedPermissions

DCShadow Attack Rogue Domain Controller Registration: How It Bypasses AD Change Auditing

DCShadow forges a rogue domain controller to push Active Directory changes via replication rather than a write API, bypassing the audit trail Domain Admin abuse normally leaves.

Active Directory Audit Policy Configuration Gaps: The Categories Nobody Enables Before They Need the Logs
ADMonitoringAdvanced

Active Directory Audit Policy Configuration Gaps: The Categories Nobody Enables Before They Need the Logs

Most Active Directory environments leave Account Logon, Account Management, and Policy Change auditing off or half-configured. Here's why the gap exists, how to check for it, and how to close it.

CVE-2025-55241: Entra ID Actor Token Impersonation Could Compromise Any Global Admin
AzureIdentityPrivileged Access

CVE-2025-55241: Entra ID Actor Token Impersonation Could Compromise Any Global Admin

CVE-2025-55241 let an undocumented Actor token bypass MFA and Conditional Access to impersonate any Global Admin across Entra ID tenants. How it worked, and what to fix.

Entra ID MemberOf Dynamic Group Rule Operator Retirement: What Breaks on November 3
AzureGroupsIdentity

Entra ID MemberOf Dynamic Group Rule Operator Retirement: What Breaks on November 3

Microsoft is retiring the preview memberOf dynamic-group rule operator in Entra ID on November 3, 2026 — here's what breaks, how to find every affected rule, and how to migrate first.

Active Directory Privileged Accounts: Protected Users, Delegation, and Service Account Gaps
ADAccountsPrivileged Access

Active Directory Privileged Accounts: Protected Users, Delegation, and Service Account Gaps

Domain Admins left out of Protected Users, delegation flags never set, and service accounts sitting in privileged groups are three separate, additive gaps that widen credential-theft blast radius. Here's how to find and close them.

CVE-2026-56155 ADFS Elevation of Privilege: The Actively Exploited Flaw Sysadmins Still Haven't Patched
ADPermissionsPrivileged Access

CVE-2026-56155 ADFS Elevation of Privilege: The Actively Exploited Flaw Sysadmins Still Haven't Patched

CVE-2026-56155 lets a low-privileged local user escalate to admin via AD FS's DKM container ACLs. Actively exploited pre-patch — what to detect and fix.

Entra ID AiTM Token Replay, Impossible Travel Detection, and MFA Push Fatigue
AzureRisk ProtectionIdentity

Entra ID AiTM Token Replay, Impossible Travel Detection, and MFA Push Fatigue

Entra ID's sign-in risk detections catch AiTM token replay, impossible travel, and MFA push abuse — but only if you know which signal to read. Here is what to watch and how to respond.

Entra ID SMS MFA Retirement Passkeys: The Migration Timeline
AzureIdentityConditional Access

Entra ID SMS MFA Retirement Passkeys: The Migration Timeline

Microsoft is retiring Microsoft-provided SMS and voice MFA in Entra ID by February 1, 2027, auto-enrolling remaining users into passkeys starting September 1, 2026. Here is the exact timeline, how to find who is exposed, and how to migrate before the blocking prompt hits.

Entra SAML Signing Certificate Expired: Why Federated Sign-In Breaks
AzureApplicationsMonitoring

Entra SAML Signing Certificate Expired: Why Federated Sign-In Breaks

An expired SAML signing certificate doesn't just weaken security — it breaks federated sign-in tenant-wide. Learn how Entra certificate rotation works, how to detect expiring or long-lived certs, and how to renew without downtime.

Active Directory Computer Objects Attack Surface: The Machine Identity Risk Nobody Audits
ADComputersAttack Paths

Active Directory Computer Objects Attack Surface: The Machine Identity Risk Nobody Audits

The Active Directory computer objects attack surface — unconstrained delegation, RBCD abuse, DCSync rights on machine accounts, computers in admin groups, and obsolete OS — covers the attack, detection, and remediation for each.

BadSuccessor dMSA Privilege Escalation: How Low-Privilege Users Become Domain Admin
ADAdvancedAttack Paths

BadSuccessor dMSA Privilege Escalation: How Low-Privilege Users Become Domain Admin

BadSuccessor dMSA privilege escalation lets a low-privileged user with just CreateChild on an OU impersonate any account in the domain, up to Domain Admin. How it works, the August 2025 patch (CVE-2025-53779), detection, and remediation.

Certighost CVE-2026-54121 AD CS: Low-Privileged Users Can Impersonate a Domain Controller
ADADCSMonitoring

Certighost CVE-2026-54121 AD CS: Low-Privileged Users Can Impersonate a Domain Controller

Certighost (CVE-2026-54121) is a critical AD CS flaw that lets a low-privileged domain user impersonate a Domain Controller. Patched July 14, 2026, PoC public since July 24 — what's confirmed, how to detect it, and how to patch.