Pour bénéficier d’une expérience Web optimale, utilisez Internet Explorer 11 ou version ultérieure, Chrome, Firefox, ou Safari.

TEC Talk: Proper Password Protection within Active Directory and Azure Active Directory Environments

Proper Password Protection within Active Directory and Azure Active Directory Environments
a la demande
  • Date enregistrée:Nov. 14, 2023
  • Événement:a la demande
Proper Password Protection within Active Directory and Azure Active Directory Environments

Attacks against Active Directory have been steadily increasing in the last few years. This is because Active Directory holds all domain joined user and machine credentials and permissions, making it a prime target for attackers. Interestingly, a lot of these attacks start by initially compromising an account. In a lot of cases this account doesn’t have a lot of permissions (such as a standard user account), but does allow for thorough enumeration of the AD environment to find misconfigurations and elevate privileges. This brings me to the importance of managing passwords in an Active Directory/ Azure Active Directory environment. AD Passwords are used with computer accounts, user accounts, trusts, service accounts, and more. Microsoft has provided both guidance and technical capability to natively protect these passwords in various ways to shrink the attack surface of the environment. We will review the various situations where account credentials are commonly compromised, the native Microsoft solutions to mitigate the compromise, and when it is appropriate to use which mitigation.

Intervenants

Darryl Baker is an Army veteran of twelve years who specialized in weapons instruction before transitioning over to security. He has ten years of experience working in Windows domains in various roles and has spent the last two specializing in Microsoft security with a focus on Active Directory (AD). He has hosted AD CFPs online and at in-person conferences and has written multiple tools and scripts for both discovering Active Directory vulnerabilities and defending against attacks. 

Regarder votre webcast gratuit

Veuillez patienter...

triangle-down check
En téléchargeant, vous vous inscrivez pour recevoir des e-mails marketing de notre part. Pour vous désinscrire, veuillez suivre les instructions figurant dans notre politique de confidentialité.

Site protégé par reCAPTCHA. Consultez les conditions d’utilisation et la politique de confidentialité de Google.