Active Directory

Active Directory Password Policy

Password Policy

Unfortunately, setting a good password policy for Active Directory is difficult. This is also because there are several best practices that sometimes contradict each other. In this post, I will try to address the various best practices and give my own recommendation.

Built-in Misconfigurations - Pre-Windows 2000 Compatible Access

Old Computer

This is the first part of a series in which we look into default insecure configurations in Active Directory. This part covers the Pre-Windows 2000 Compatible Access group. What is it? What are the risks? And what can we do about it?

Active Directory and EntraID Penetration Testing and Auditing

Tier Model

Ransomware attacks are on the rise, and the ones with the highest impact take over the whole Active Directory or EntraID. We must secure these systems to minimize the risk of having our data encrypted and put up for sale on the internet!

Internal Infrastructure Penetration Testing

Internal Infrastructure Pentest

What if one of your employees clicks on the wrong email attachment? Will you be able to stop the attack, or will the attackers be able to move laterally from there and take over all your systems? This is why you should conduct an internal infrastructure penetration test. The internal system is just one wrong click away from being “public”.