February 15, 2024
- First, we start by taking a view of how large systems have evolved. Larger systems tend to have two or more identity processes, and Active Directory from Microsoft has a 90% share of that overall market.
- Secondly, some identity systems can use outdated Identification Access Management systems.
- Thirdly, we have employees and contractors who enter and leave systems. This can produce confusion in de-provisioning access.
"Active Directory is the core identity store for 90% of organizations worldwide"
Jimmy McNary, Semperis Tweet
Semperis uses Active Directory as the starting point to orchestrate identification. They can stop malicious actors before they attack, during the attack, and help post-attack.
In a poignant example, Jimmy McNary relates the story that some organizations spend significant amounts of money on backups, including immutable backups. Unfortunately, they forget about backing up Active Directory. We know that it is likely the attack vector included Active Directory, but it is not protected.
This is a scenario where the system is restored, and the malicious actor has retained credentials to allow him back into the system.
Jimmy McNary provides practical tips to avoid these frustrating situations.
If you are interested in security from an Active Directory perspective, then you may want to read a recent blog from Semperis titled, NSA Top Ten Cybersecurity Misconfigurations: An Active Directory Perspective
Federal Tech Podcast covers many topics. You may want to listen to Episode 125 The Secure Hybrid Edge with AWS

Leave a Reply