Identity Security Blog

Expert insights on Active Directory and Azure security vulnerabilities, hardening guides, and remediation best practices.

123 articles
LDAP Signing Disabled: How Unsigned Binds Expose Active Directory
ADNetworkIdentity

LDAP Signing Disabled: How Unsigned Binds Expose Active Directory

LDAP signing disabled allows unsigned SASL binds and cleartext LDAP simple binds to reach domain controllers. Learn how to detect it, harden it, and avoid breaking legacy apps.

Passwords in AD Description Fields: Detection and Cleanup
ADPasswordAccounts

Passwords in AD Description Fields: Detection and Cleanup

AD description fields still leak temporary or legacy passwords in many environments. Learn how attackers find them and how to remove them safely.

AD Audit Tool Comparison: How to Compare PingCastle, Purple Knight, and Repeatable Audit Workflows
ADAzureIdentityMonitoring

AD Audit Tool Comparison: How to Compare PingCastle, Purple Knight, and Repeatable Audit Workflows

A criteria-first comparison of AD audit tools, from PingCastle and Purple Knight to repeatable workflows built for hybrid identity and remediation follow-up.

How to Audit Microsoft Entra ID Security (Azure AD): Practical Review Guide
AzureIdentityConditional Access

How to Audit Microsoft Entra ID Security (Azure AD): Practical Review Guide

Learn how to audit Microsoft Entra ID security, including Conditional Access, MFA, PIM, app permissions, guest access, and remediation priorities.

Audit Active Directory Security: What to Review First and How to Prove Remediation
ADIdentityPrivileged Access

Audit Active Directory Security: What to Review First and How to Prove Remediation

A technical guide to auditing Active Directory security, from Tier 0 exposure and ACL abuse to Kerberos, AD CS, logging, and remediation proof.

ACL Abuse and DCSync: The Silent Paths to Domain Admin
ADPermissionsAttack Paths

ACL Abuse and DCSync: The Silent Paths to Domain Admin

DCSync requires no exploit - just a misconfigured ACL. Learn how GenericAll and replication rights give attackers silent paths to dump every password hash in your domain.

GPO Misconfigurations: How Group Policy Becomes an Attack Vector
ADGPOAttack Paths

GPO Misconfigurations: How Group Policy Becomes an Attack Vector

Weak GPO permissions allow low-privileged users to modify policies applied to Domain Controllers, while missing LAPS enables domain-wide lateral movement from a single machine compromise.

Azure Guest Accounts: The Forgotten Attack Surface in Your Tenant
AzureGuest ExternalIdentity

Azure Guest Accounts: The Forgotten Attack Surface in Your Tenant

Forgotten guest accounts, unrestricted invitation rights, and no MFA for external users create a persistent and often unmonitored attack surface in Azure Entra ID.

Azure Privileged Access: Too Many Global Admins
AzurePrivileged AccessIdentity

Azure Privileged Access: Too Many Global Admins

Azure privileged access risk comes from standing Global Admins, weak admin authentication, unmanaged emergency accounts, and PIM gaps. Learn how to audit, reduce, monitor, and validate privileged access in Microsoft Entra ID.

Entra ID Conditional Access Gaps: What Misconfigurations Leave Real Exposure
AzureConditional AccessIdentity

Entra ID Conditional Access Gaps: What Misconfigurations Leave Real Exposure

A technical guide to reviewing Entra ID Conditional Access gaps across scope, exclusions, legacy authentication, workload identities, sign-in evidence, and remediation validation.

Azure App Registrations: Over-Privileged Tenant Apps
AzureApplicationsPermissions

Azure App Registrations: Over-Privileged Tenant Apps

Over-privileged app registrations with leaked client secrets give attackers full API access to mailboxes, files, and Azure resources. Learn how to audit and secure your app registrations.

Azure Identity Protection: Blocking Leaked Credentials
AzureRisk ProtectionIdentity

Azure Identity Protection: Blocking Leaked Credentials

Azure Identity Protection is useful only when risk detections trigger a response. Learn how sign-in risk, user risk, Conditional Access policies, remediation, and validation work in Microsoft Entra ID.