Active Directory - Are your Passwords a Ticking Time Bomb?

  Рет қаралды 5,409

Andy Malone MVP

Andy Malone MVP

Күн бұрын

Пікірлер: 24
@1.618Golden
@1.618Golden 9 ай бұрын
I learned AD about 8 years ago. I work at a place that uses Entra/Azure AD now. Thank you for this. Security is always top of mind for our crew here. I shared this to our entire team.
@AndyMaloneMVP
@AndyMaloneMVP 9 ай бұрын
Thanks so much :-)
@Moralikov
@Moralikov 9 ай бұрын
I have been working with Active Directory for 20 years. I think it has been evolving nicely with every new release of Windows Server (WS). From WS 2003 significant improvements in Group Policy management over user and computer configurations within the network and also forest trust. Then WS 2008 introduced role-based authentication, providing administrators with more granular control over the assignments of rights and permissions and fine-grained password policies. Then WS 2012 with Dynamic Access Control, Recycle bin and Virtualization support. Then WS 2016 Privileged Access Management and Shielded Virtual machines. To WS 2019 Authentication Policy Silos, Enhanced Time Accuracy and Integration with Azure Active Directory. Havent played around with WS 2022 yet though.
@AndyMaloneMVP
@AndyMaloneMVP 9 ай бұрын
Great post thanks and absolutely I totally agree with you. These are some awesome features. However, you’ll notice that it still does not address fundamental issues regarding passwords. I do believe however the window server 2025 is going to rewrite active directory for the first time, removing its dependency on NTLM at last, so this is definitely worth looking forward to. Thanks again for the great response 👍
@it-candor
@it-candor 4 ай бұрын
Reach out if you want to have a deeper discussion more than happy to dive in a bit with you around some of these concepts and better security options and processes!
@scotteastin1433
@scotteastin1433 9 ай бұрын
This is a great video and I really enjoyed learning about Specops. Your point that 90% of businesses still run AD is spot on. My team is seeing a ton of AD security and hardening projects. Despite Microsoft's marketing, companies will remain hybrid longer than anyone expects. AD is the equivalent of the mainframe in the 90s. I wonder if we will have to recruit AD admins from retirement homes in 10 years 😀. Keep up the great work!
@AndyMaloneMVP
@AndyMaloneMVP 9 ай бұрын
Absolutely 100% key skill requirement.
@francescobedinijacobini
@francescobedinijacobini 9 ай бұрын
Great video as always! Since MS is appearing to move away from passwords (see Microsoft Account, or Microsoft 365, for example), I think MS should take a serious look to revamp the password policy and, most importantly, try to get rid of passwords in AD.
@Speed0a
@Speed0a 8 ай бұрын
I mean, yeah, fair point. We should enforce users to harden their passwords and stuff. And so they commit unrememberable passwords, with expiring policies enough for them to write down on a post-it or something, comprimising the password anyway.
@ivaylovalkov
@ivaylovalkov 9 ай бұрын
Very informative video Andy but I wonder how this SpecOps tools interacts with SSPR in Entra ID. Does it has similar "tips screen" as in Windows client or some other way to inform a user why the password is not accepted?
@AndyMaloneMVP
@AndyMaloneMVP 9 ай бұрын
I believe so, yes
@silvanabongiorno3292
@silvanabongiorno3292 9 ай бұрын
💻⌨📲🔍Thank you Andy, Excellent video presentation
@greendesigners3846
@greendesigners3846 8 ай бұрын
Andy I have been getting the run around from Microsoft Canada trying to get a client verification for ms edu. Any recommendations
@AndyMaloneMVP
@AndyMaloneMVP 8 ай бұрын
No idea I’m sorry.
@jstump1972
@jstump1972 9 ай бұрын
Use the AD administrative console and create a whole domain password policy there
@AndyMaloneMVP
@AndyMaloneMVP 9 ай бұрын
It still has limits. Characters, length etc
@12Burton24
@12Burton24 9 ай бұрын
Ahh thats a topic Im realy intressted in because Im in a ICT school currently learning how to do active directory. What are other options on a windows server to handle all the users, groups, rules?
@AndyMaloneMVP
@AndyMaloneMVP 9 ай бұрын
Watch the video, all will be revealed :-)
@ghasanazeza2936
@ghasanazeza2936 9 ай бұрын
You forgot to mention this video includes paid promotion!
@AndyMaloneMVP
@AndyMaloneMVP 9 ай бұрын
Not paid
@dennisbuswell
@dennisbuswell 9 ай бұрын
You forgot to mention this whole video is a promotion. There I fixed it. Thanks for putting out the work but I don't think this serves the community.
@krobotak
@krobotak 9 ай бұрын
@@dennisbuswell Promotion for what?
Group Policy 5 Nuggets Every Admin MUST Know!
26:14
Andy Malone MVP
Рет қаралды 10 М.
Cracking Active Directory Passwords & MFA Fatigue
17:31
John Hammond
Рет қаралды 73 М.
Tuna 🍣 ​⁠@patrickzeinali ​⁠@ChefRush
00:48
albert_cancook
Рет қаралды 104 МЛН
I thought one thing and the truth is something else 😂
00:34
عائلة ابو رعد Abo Raad family
Рет қаралды 23 МЛН
Что-что Мурсдей говорит? 💭 #симбочка #симба #мурсдей
00:19
Симбочка Пимпочка
Рет қаралды 4,6 МЛН
Secure Program Deployment and Maintenance
29:26
Superteam Germany
Рет қаралды 21
Entra ID Admin?  5 Mistakes That You Should NEVER Make!
22:17
Andy Malone MVP
Рет қаралды 7 М.
Entra ID NEW Guest & External Access Features YOU Need to Know!
29:21
Andy Malone MVP
Рет қаралды 16 М.
Phishing Resistant MFA How it Works!
15:26
Andy Malone MVP
Рет қаралды 15 М.
Learn Microsoft Group Policy the Easy Way!
23:58
Andy Malone MVP
Рет қаралды 154 М.
Windows Server 2025 Is Here - But Should You Upgrade?
15:55
This Week in IT
Рет қаралды 7 М.
5 Amazing FREE Security Tools That Every Admin Must Use!
21:54
Andy Malone MVP
Рет қаралды 17 М.
10 Mistakes that a Microsoft 365 Admin Must NEVER Make!
33:06
Andy Malone MVP
Рет қаралды 47 М.