Skip to content
EN

Back to the catalog

adsecurity.org
rss2American English

Active Directory & Azure AD/Entra ID Security

adsecurity.org · American English

Active Directory & Azure AD/Entra ID: Enterprise Security, Methods to Secure Active Directory, Attack Methods & Effective Defenses, PowerShell, Tech Notes, & Geek Trivia...

rss2 wordpress atom dc sy

Open the feed

https://adsecurity.org/?feed=rss2

Last post
May 20, 2026
Posts in 24 h · 7 days · 30 days
0 · 0 · 0
Our last check
Answering
Served from
United States
Site title
Active Directory & Azure AD/Entra ID Security – Active Directory & Azure AD/Entra ID: Enterprise Security, Methods to Secure Active Directory, Attack Methods & Effective Defenses, PowerShell, Tech Not
Text score at discovery
441
Format
rss2
Features in the feed
atom, dc, sy
Community
wordpress

Posts

What our queue read from this feed. Open one to read it here, or go to the site that published it.

  1. AD Fundamentals: Group Policy Permissions & Owner Rights
    May 20, 2026 · original
    This series of posts focuses on key Active Directory (AD) components that need to be secured in order to ensure AD security is leveled up. In this post, we focus on Group Policy Objects (GPOs) and their permissions. Group Policy provides the ability to change application settings, security settings, install and run code, and more! … Continue reading
  2. AD Fundamentals: Domain Root & AdminSDHolder Permissions
    May 14, 2026 · original
    This series of posts focuses on key Active Directory (AD) components that need to be secured in order to ensure AD security is leveled up. this post focuses on permissions on two important objects in AD: the Domain root and the AdminSDHolder object. Domain Root Let’s start with the domain root. The domain is the container … Continue reading
  3. AD Fundamentals: DSHeuristics
    May 13, 2026 · original
    This series of posts focuses on key Active Directory (AD) components that need to be secured in order to ensure AD security is leveled up. In this post, we focus on the mostly unknown AD component called DSHeuristics DSHeuristics is like a registry editor for changing behavior in the Active Directory forest (and AD Lightweight … Continue reading
  4. AD Fundamentals: Pre-Windows 2000 Compatible Group
    May 7, 2026 · original
    This series of posts focuses on key Active Directory (AD) components that need to be secured in order to ensure AD security is leveled up. In this post, we focus on the often-misunderstood group called “Pre-Windows Compatible”. This domain-scoped group is created automatically in the Built-in root OU and is part of any Active Directory … Continue reading
  5. AD Fundamentals: Domain Controller Security
    May 6, 2026 · original
    This series of posts focuses on key Active Directory (AD) components that need to be secured in order to ensure AD security is leveled up. In this post, we focus on Domain Controller configuration. Tier 0 Domain Controllers need to be managed and maintained as Tier 0 servers since they handle authentication and authorization for … Continue reading
  6. Detecting Fake Active Directory Password Changes
    Mar 3, 2026 · original
    In Active Directory, there has been a method that’s been around for many years which changes the password last set date but not the actual password. This is what I call a “fake password change” since the account appears to have a recent password when scanning for old passwords based on password last set, but … Continue reading
  7. Active Directory Security Tip #16: Mitigating Kerberoast Attacks
    Jan 21, 2026 · original
    There are two main password attacks leveraged by adversaries; one is called Password Spraying and the other is called Kerberoasting. This post focuses on identifying accounts that may be targeted for Kerberoasting and how to harden the environment against Kerberoasting. Password spraying involves the attacker using a list of passwords and for each password attempts … Continue reading
  8. Active Directory Security Tip #15: Active Directory Domain Root Permissions
    Dec 3, 2025 · original
    This week let’s look at Active Directory domain permissions which are configured on the domain root and apply to the domain. There are many different type of concerning permissions, but let’s look at the most egregious. I wrote a PowerShell script leveraging the Active Directory PowerShell module that can help identify these permissions on the … Continue reading
  9. Active Directory Security Tip #14: Group Managed Service Accounts (GMSAs)
    Nov 5, 2025 · original
    Group Managed Service Accounts (GMSAs) User accounts created to be used as service accounts rarely have their password changed. Group Managed Service Accounts (GMSAs) provide a better approach (starting in the Windows 2012 timeframe). The password is managed by AD and automatically changed. This means that the GMSA has to have security principals explicitly delegated … Continue reading
  10. Improve Entra ID Security More Quickly
    Oct 20, 2025 · original
    At BSides Northern Virginia (BSides NoVa) in October 2025, I presented a talk on how to improve Entra ID security quickly. This post captures the key information from my talk slides. This article describes the Entra ID settings and configuration that should be set to improve security including: User Default Configurations Users are able to … Continue reading

Discovered by the rss-feed-index crawler, which checks each feed at most once a month.

Same record as JSON: https://api.agentalog.com/api/feeds/fd_adsecurity_org_2036e0182d69bff4. More from this site: adsecurity.org in the Feeds tab.