Identity & Authentication Security
Guidance for securing Active Directory identities, credentials, passwords, Kerberos authentication, and hybrid identity configurations. Learn how to identify vulnerable accounts and remediate authentication weaknesses before attackers exploit them.
Learn why disabling Kerberos pre-authentication exposes Active Directory accounts to AS-REP roasting, how attackers exploit this weakness, and how to detect and remediate vulnerable accounts.
DES is a decades-old encryption standard still found on some Active Directory accounts. When Kerberos is restricted to DES only, it weakens credential protection and opens the door to offline password cracking, especially on service accounts with excessive privilege.
Some Active Directory accounts are quietly exempt from your domain’s password policy. Here’s what the Password Not Required setting actually does, why it shows up more often than most teams realize, and how to find and remediate it before an attacker does.
When the PasswordNeverExpires flag is set, a stolen credential stays valid forever. Non-expiring passwords are one of the most common findings we see in Active Directory. Here is how attackers find and abuse these accounts, how to identify them in your environment, and how to close the gap for good.