Skip to content
EN

Back to the catalog

adsecurity.org
rss2American English

Comments for Active Directory & Azure AD/Entra ID Security

adsecurity.org · American English

Active Directory & Azure AD/Entra ID: Enterprise Security, Methods to Secure Active Directory, Attack Methods & Effective Defenses, PowerShell, Tech Notes, & Geek Trivia...

rss2 wordpress content atom dc sy

Open the feed

https://adsecurity.org/?feed=comments-rss2

Last post
Sep 14, 2025
Posts in 24 h · 7 days · 30 days
0 · 0 · 0
Our last check
Answering
Served from
United States
Site title
Active Directory & Azure AD/Entra ID Security – Active Directory & Azure AD/Entra ID: Enterprise Security, Methods to Secure Active Directory, Attack Methods & Effective Defenses, PowerShell, Tech Not
Text score at discovery
281
Format
rss2
Features in the feed
content, atom, dc, sy
Community
wordpress

Posts

What our queue read from this feed. Open one to read it here, or go to the site that published it.

  1. Comment on Active Directory Security Tip #1: Active Directory Admins by Gxxxx
    Sep 14, 2025 · original
    Thanks for this . Great compliment to my OSCP journey . Keep up the great work
  2. Comment on Securing Domain Controllers to Improve Active Directory Security by Sean Metcalf
    Nov 4, 2016 · original
    In reply to Oliver . Thanks! Configuring Active Directory communications through a firewall is challenging since most of RPC occurs on random high-level ports. This is what I use as a reference: https://technet.microsoft.com/en-us/library/dd772723(v=ws.10).aspx
  3. Comment on Securing Domain Controllers to Improve Active Directory Security by Oliver
    Nov 4, 2016 · original
    Excellent article, I will definitely be referencing this for quite some time. I have had some trouble negotiating DC communications through a corporate firewall that I do not control, but this was due to blocked ports related to replication. Are you aware of any changes in required ports if enforcing NTLMv2? What confuses me is the reference to secure RPC, which I cannot find info on elsewhere. Actually after rereading post-coffee I think you answered this already, saying it does not modify the way the authentication sequence works, but I just want to be sure. This could have actually been a terribly stupid question, sorry.
  4. Comment on Securing Windows Workstations: Developing a Secure Baseline by Oddvar Moe
    Oct 25, 2016 · original
    One of the best blogposts I have seen in a long time. Great work. Also I suggest to remove the possibility to run .hta extensions. It is no problem wrapping vb scripts inside a HTA.
  5. Comment on Securing Windows Workstations: Developing a Secure Baseline by Kurt Falde
    Oct 24, 2016 · original
    Great write-up nice good list of findings that are over and above what STIG/CIS currently dictates.
  6. Comment on Securing Windows Workstations: Developing a Secure Baseline by F
    Oct 24, 2016 · original
    Very nice comprehensive list – thanks!
  7. Comment on Securing Windows Workstations: Developing a Secure Baseline by Ned Pyle
    Oct 21, 2016 · original
    You can also remove SMB1 from Windows 8.1. And I sure wish you would. 🙂 Excellent article, as always, Sean.
  8. Comment on Securing Windows Workstations: Developing a Secure Baseline by Bobby
    Oct 21, 2016 · original
    Excellent write-up! Thanks for publishing this.
  9. Comment on Microsoft LAPS Security & Active Directory LAPS Configuration Recon by Sean Metcalf
    Aug 17, 2016 · original
    In reply to Ryan . I agree that it would be better if the password was encrypted and note as much in my earlier post on LAPS ( https://adsecurity.org/?p=1790 ). Since the password is stored in a confidential attribute which only Domain Admins have access to by default (not including custom delegation), the password data is appropriately secured. IF the issue is the difference between changing local admin passwords versus not, the answer is simple, use LAPS (or another password management solution).
  10. Comment on Microsoft LAPS Security & Active Directory LAPS Configuration Recon by Ryan
    Aug 16, 2016 · original
    I would be interested to know your thoughts on the password stored in clear text? Our security team are not happy to approve LAPS as they see that as a security risk and want the password encrypted. my initial thoughts are that the password is stored on a confidential attribute so you would need to compromise AD and the ACLs to get access which at that point does it really matter where your passwords are stored..don’t you have bigger issues?

Discovered by the rss-feed-index crawler, which checks each feed at most once a month.

Same record as JSON: https://api.agentalog.com/api/feeds/fd_adsecurity_org_e1f8d05d4abe57c5. More from this site: adsecurity.org in the Feeds tab.