If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: adsecurity.org - Active Directory & Azure A.

site address: ADSecurity.org redirected to: adsecurity.org

site title: Active Directory & Azure AD/Entra ID Security Active Directory & Azure AD/Entra ID: Enterprise Security, Methods to Secure Active Directory, Attack Methods & Effective Defenses, PowerShell, Tech Notes, & Geek Trivia

Our opinion (on Thursday 27 August 2026 11:57:59 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

ad, fundamentals, group, security, domain, active, directory, permissions, root, windows, tip, managed, service, accounts, gmsas, recent, posts, policy, owner, rights, adminsdholder, dsheuristics, pre, 2000, compatible, controller, entra, id, categories, detecting, fake, password, changes, 16, mitigating, kerberoast, attacks, 15, 14, key, points, for, improve, more, quickly, services, popular, tags, comments, archives, meta, copyright, tier, supported, version,

Text of the page (most frequently used words):
the (69), security (65), this (42), #directory (41), #active (40), domain (37), and (30), fundamentals (27), group (21), password (21), permissions (20), that (20), windows (18), entra (15), for (14), posts (14), reading (13), powershell (13), 2015 (13), key (13), focuses (13), 2025 (12), activedirectorysecurity (12), may (12), root (12), post (12), need (12), are (11), technical (11), 2014 (11), 2016 (11), sean (11), metcalf (11), service (11), 2026 (10), dsheuristics (10), continue (10), gmsa (10), series (10), components (10), secured (10), order (10), ensure (10), leveled (10), rights (9), microsoft (9), have (9), accounts (9), focus (9), august (8), controllers (8), pre (8), access (8), tier (8), objects (8), any (7), reference (7), january (7), 2019 (7), securing (7), secure (7), improve (7), adminsdholder (7), policy (7), account (7), managed (7), change (7), with (6), provided (6), february (6), march (6), november (6), october (6), 2017 (6), controller (6), compatible (6), set (6), there (6), all (5), azure (5), activedirectory (5), kerberoasting (5), methods (5), server (5), how (5), user (5), msds (5), which (5), but (5), called (5), content (4), blog (4), its (4), they (4), only (4), views (4), not (4), article (4), system (4), mitigation (4), 2012 (4), july (4), june (4), september (4), december (4), 2018 (4), tip (4), recent (4), 2000 (4), owner (4), mimikatz (4), activedirectorysecuritytip (4), attack (4), their (4), should (4), talk (4), gmsas (4), changed (4), object (4), here (3), work (3), current (3), copyright (3), conference (3), presentation (3), realworld (3), april (3), 2020 (3), workstations (3), developing (3), baseline (3), admins (3), search (3), kerberoast (3), about (3), services (3), more (3), quickly (3), default (3), settings (3), configuration (3), bsides (3), from (3), attacker (3), computers (3), has (3), let (3), apply (3), two (3), last (3), changes (3), fake (3), when (3), ability (3), users (3), groups (3), disclaimer (2), contents (2), warranties (2), confer (2), script (2), samples (2), informational (2), purposes (2), guarantee (2), functionality (2), suitability (2), shared (2), reflect (2), those (2), authors (2), represent (2), companies (2), mentioned (2), comments (2), feed (2), vulnerability (2), thecloud (2), recommendation (2), video (2), network (2), malware (2), linux (2), unix (2), interview (2), hypervisor (2), hardware (2), hacking (2), exploit (2), entertainment (2), continuing (2), education (2), cloud (2), apple (2), categories (2), laps (2), krbtgt (2), kerberos (2), domaincontroller (2), dcsync (2), scanning (2), detection (2), detecting (2), passwords (2), admin (2), environment (2), privileged (2), applications (2), role (2), configurations (2), including (2), groupmanagedserviceaccount (2), compromises (2), request (2), compromised (2), computer (2), hosting (2), using (2), start (2), created (2), provide (2), automatically (2), means (2), delegated (2), like (2), other (2), where (2), look (2), many (2), attacks (2), pwdlastset (2), does (2), been (2), what (2), since (2), was (2), first (2), doesn (2), want (2), requires (2), attribute (2), provides (2), setting (2), next (2), logon (2), dcs (2), running (2), supported (2), versions (2), support (2), able (2), below (2), outside (2), forest (2), members (2), read (2), often (2), misunderstood (2), behavior (2), get (2), code (2), mostly (2), unknown (2), can (2), such (2), important (2), gpos (2), resources (2), enterprise (2), effective (2), defenses (2), tech (2), notes (2), geek (2), trivia (2), toggle (2), made, graphene, themes, ownership, posted, intellectual, under, law, poster, owns, terms, use, 2011, wordpress, org, entries, log, meta, 2013, archives, kurt, falde, oddvar, moe, oliver, gxxxx, windowsserver2012r2, windowsserver2012, windowsserver2008r2, windows10, tgt, tgs, spn, sneakyadpersistence, silverticket, powerview, powersploit, powershellv5, powershellhacking, powershellcode, passthehash, ms14068, microsoftwindows, microsoftemet, mcm, lsass, kerberoshacking, kdc, kb3011780, invoke, hyperv, goldenticket, adsecurity, adreading, tags, privileges, usage, exploitation, activity, finding, sysvol, exploiting, gaining, encoding, decoding, base64, features, popular, concerns, your, tenant, help, enterprises, posture, find, out, load, userdefaults, guestdefaults, entraidsecurity, entraid, checklist, connect, partner, conditional, policies, highly, assignable, membership, protection, roles, consent, guest, defaults, describes, northern, virginia, presented, captures, information, slides, nova, oct, principalsallowedtoretrievemanagedpassword, managedpasswordinterval, managedpasswordid, managedpassword, groupmsamembership, configure, allow, associated, points, used, rarely, better, approach, starting, timeframe, principals, explicitly, clear, text, much, areas, delegation, controls, determining, who, needs, carefully, considered, nov, adpermissions, week, configured, different, type, concerning, most, egregious, dec, mitigatekerberoastattack, identifying, targeted, harden, against, main, leveraged, adversaries, one, spraying, mitigating, jan, unicodepwd, fakepasswordchange, fakeadpasswordchange, activedirectoryreplicationmetadata, see, works, svc, agpm, lab, 20th, method, around, years, date, actual, call, appears, old, based, underlying, hasn, actually, spoke, times, someone, them, modify, check, uncheck, must, enabled, you, own, why, happen, charm, mar, domaincontrollersoftware, domaincontrollersecurity, domaincontrollerpermissions, dcsupportedwindows, dcsecurity, dcacls, item, ensuring, operating, point, least, preferably, 2022, shows, ended, mainstream, extended, until, 2029, version, maintained, servers, handle, authentication, authorization, organization, being, highest, nothing, manage, violation, principal, whether, management, inventory, virtualization, administration, prewindows200compatible, windows2000compatiblesecurity, windows2000compatiblegroup, windows2000, scoped, built, part, controlling, anonymous, original, intent, migration, path, thus, word, name, fldapblockanonops, fallowanonnspi, dwadminsdexmask, dsheuristicssecurity, exist, import, module, adobject, identity, adrootdse, configurationnamingcontext, properties, gets, value, registry, editor, changing, lightweight, aka, lds, component, domainrootpermissions, domainpermissions, adminsdholderpermissions, container, itself, similar, manner, makes, special, inherited, affect, etc, note, level, protected, grouppolicysecurity, grouppolicypermissions, grouppolicyowner, gposecurity, gpopermissions, gpoowner, application, install, run, powerful, tool, administrator, well, adversary, previous, top, spns, schema, presentations, defense, home, navigation, form,


Text of the page (random words):
st we focus on group policy objects gpos ad fundamentals domain root adminsdholder permissions this series of posts focuses on key active directory ad components that need to be secured in order to ensure ad security is leveled up this post focuses on permissions on two important objects in ad ad fundamentals dsheuristics this series of posts focuses on key active directory ad components that need to be secured in order to ensure ad security is leveled up in this post we focus on the mostly unknown ad ad fundamentals pre windows 2000 compatible group this series of posts focuses on key active directory ad components that need to be secured in order to ensure ad security is leveled up in this post we focus on the often misunderstood group called ad fundamentals domain controller security this series of posts focuses on key active directory ad components that need to be secured in order to ensure ad security is leveled up in this post we focus on domain controller configuration tier previous next may 19 2026 ad fundamentals group policy permissions owner rights by sean metcalf in activedirectorysecurity ad fundamentals this series of posts focuses on key active directory ad components that need to be secured in order to ensure ad security is leveled up in this post we focus on group policy objects gpos and their permissions group policy provides the ability to change application settings security settings install and run code and more as such it s a powerful tool for the administrator as well as the attacker adversary continue reading gpoowner gpopermissions gposecurity grouppolicyowner grouppolicypermissions grouppolicysecurity may 13 2026 ad fundamentals domain root adminsdholder permissions by sean metcalf in activedirectorysecurity ad fundamentals technical reference this series of posts focuses on key active directory ad components that need to be secured in order to ensure ad security is leveled up this post focuses on permissions on two important objects in ad the domain root and the adminsdholder object domain root let s start with the domain root the domain is the container for all domain objects and on the domain object itself there are permissions in a similar manner to any object in active directory what makes the domain root object special is that any permissions set here are inherited by default on objects below it which means that permissions here can affect all domain objects users computers groups etc note that permissions set at the domain level do not apply to adminsdholder protected objects such as domain admins and da members but can apply to domain controllers and read only domain controllers continue reading adminsdholder adminsdholderpermissions domainpermissions domainrootpermissions may 12 2026 ad fundamentals dsheuristics by sean metcalf in activedirectorysecurity ad fundamentals this series of posts focuses on key active directory ad components that need to be secured in order to ensure ad security is leveled up in this post we focus on the mostly unknown ad component called dsheuristics dsheuristics is like a registry editor for changing behavior in the active directory forest and ad lightweight directory service aka lds this powershell code gets the current dsheuristics value import module activedirectory ds get adobject identity cn directory service cn windows nt cn services get adrootdse configurationnamingcontext properties dsheuristics ds dsheuristics by default the attribute doesn t exist if it is set to 0 there s no change to behavior continue reading dsheuristics dsheuristicssecurity dwadminsdexmask fallowanonnspi fldapblockanonops may 06 2026 ad fundamentals pre windows 2000 compatible group by sean metcalf in activedirectorysecurity ad fundamentals microsoft security technical reference this series of posts focuses on key active directory ad components that need to be secured in order to ensure ad security is leveled up in this post we focus on the often misunderstood group called pre windows compatible this domain scoped group is created automatically in the built in root ou and is part of any active directory forest controlling anonymous access to ad its original intent was to provide a migration path from using a windows nt domain to active directory thus the compatible word in the name members of this group have read access to all users and groups in the domain continue reading pre windows2000 pre windows2000compatiblegroup pre windows2000compatiblesecurity prewindows200compatible may 05 2026 ad fundamentals domain controller security by sean metcalf in activedirectorysecurity ad fundamentals technical reference this series of posts focuses on key active directory ad components that need to be secured in order to ensure ad security is leveled up in this post we focus on domain controller configuration tier 0 domain controllers need to be managed and maintained as tier 0 servers since they handle authentication and authorization for the organization tier 0 being the highest tier that requires nothing outside of this be in the tier including users groups and computers only ad admins as tier 0 accounts should be able to manage domain controllers any system outside of this is in violation of the tier 0 principal whether it be management inventory security or virtualization administration supported windows version the first key item is ensuring that all domain controllers dcs are running on supported microsoft windows operating system versions at this point dcs should be running at least windows server 2019 preferably windows server 2022 or 2025 the t able below shows that windows server 2016 2019 have ended mainstream support windows server 2019 has extended support until january 2029 continue reading dcacls dcsecurity dcsupportedwindows domaincontroller domaincontrollerpermissions domaincontrollersecurity domaincontrollersoftware mar 02 2026 detecting fake active directory password changes by sean metcalf in activedirectorysecurity microsoft security mitigation powershell in active directory there has been a method that s been around for many years which changes the password last set date but not the actual password this is what i call a fake password change since the account appears to have a recent password when scanning for old passwords based on password last set but the underlying password hasn t actually changed i spoke about this in my 2015 bsides charm talk which was my first conference talk why does this happen there are times where service account or admin accounts need to have password changes but someone doesn t want to do the work to change them the ability to fake a password change requires modify rights on the pwdlastset attribute which provides the ability to check uncheck the setting user must change password at next logon this setting is enabled when you want the user to change their own password when they logon how does this work to see how this works we ll focus on the service account svc agpm in my lab this account last changed its password on august 20th in 2025 continue reading activedirectory activedirectoryreplicationmetadata fakeadpasswordchange fakepasswordchange powershell pwdlastset unicodepwd jan 20 2026 active directory security tip 16 mitigating kerberoast attacks by sean metcalf in activedirectorysecurity microsoft security mitigation powershell realworld there are two main password attacks leveraged by adversaries one is called password spraying and the other is called kerberoasting this post focuses on identifying accounts that may be targeted for kerberoasting and how to harden the environment against kerberoasting continue reading activedirectory activedirectorysecuritytip kerberoast kerberoasting mitigatekerberoastattack powershell dec 02 2025 active directory security tip 15 active directory domain root permissions by sean metcalf in activedirectorysecurity microsoft security powershell this week let s look at active directory domain permissions which are configured on the domain root and apply to the domain there are many different type of concerning permissions but let s look at the most egregious continue reading activedirectory activedirectorysecuritytip adpermissions domain root permissions nov 04 2025 active directory security tip 14 group managed service accounts gmsas by sean metcalf in activedirectorysecurity microsoft security powershell technical reference group managed service accounts gmsas user accounts created to be used as service accounts rarely have their password changed group managed service accounts gmsas provide a better approach starting in the windows 2012 timeframe the password is managed by ad and automatically changed this means that the gmsa has to have security principals explicitly delegated to have access to the clear text password much like with other areas where delegation controls access laps determining who should have be delegated access needs to be be carefully considered key points for group managed service accounts gmsas the gmsa password is managed by ad computers hosting gmsa service account s request the current password from active directory to start the associated service configure the gmsa to allow computer account s access to the gmsa password if an attacker compromises any computer hosting services using the gmsa the gmsa is compromised if attacker compromises an account with rights to request the gmsa password the gmsa is compromised continue reading activedirectorysecuritytip gmsa groupmanagedserviceaccount msds groupmanagedserviceaccount msds groupmsamembership msds managedpassword msds managedpasswordid msds managedpasswordinterval principalsallowedtoretrievemanagedpassword oct 19 2025 improve entra id security more quickly by sean metcalf in entra id security microsoft security technical reference at bsides northern virginia bsides nova in october 2025 i presented a talk on how to improve entra id security quickly this post captures the key information from my talk slides this article describes the entra id settings and configuration that should be set to improve security including user default configurations guest defaults user applications consent and permissions secure entra id roles privileged role membership protection role assignable group configurations highly privileged applications conditional access policies partner access securing entra connect secure entra id quickly checklist continue reading entraid entraidsecurity guestdefaults userdefaults 1 2 3 28 load more recent posts ad fundamentals group policy permissions owner rights ad fundamentals domain root adminsdholder permissions ad fundamentals dsheuristics ad fundamentals pre windows 2000 compatible group ad fundamentals domain controller security active directory entra id security services have concerns about your active directory environment and or entra id tenant we help enterprises improve their security posture find out how popular posts ad reading windows server 2019 active directory features powershell encoding decoding base64 attack methods for gaining domain admin rights in kerberos krbtgt active directory s finding passwords in sysvol exploiting group securing windows workstations developing a secure baseline securing domain controllers to improve active detecting kerberoasting activity mimikatz dcsync usage exploitation and detection scanning for active directory privileges categories activedirectorysecurity ad fundamentals apple security cloud security continuing education entertainment entra id security exploit hacking hardware security hypervisor security interview linux unix security malware microsoft security mitigation network system security powershell realworld security security conference presentation video security recommendation technical article technical reading technical reference thecloud vulnerability tags activedirectory active directory activedirectorysecurity active directory security activedirectorysecuritytip adreading adsecurity ad security azure dcsync domaincontroller goldenticket hyperv invoke mimikatz kb3011780 kdc kerberoast kerberos kerberoshacking krbtgt laps lsass mcm microsoftemet microsoftwindows mimikatz ms14068 passthehash powershell powershellcode powershellhacking powershellv5 powersploit powerview presentation security silverticket sneakyadpersistence spn tgs tgt windows10 windowsserver2008r2 windowsserver2012 windowsserver2012r2 search for recent posts ad fundamentals group policy permissions owner rights ad fundamentals domain root adminsdholder permissions ad fundamentals dsheuristics ad fundamentals pre windows 2000 compatible group ad fundamentals domain controller security recent comments gxxxx on active directory security tip 1 active directory admins sean metcalf on securing domain controllers to improve active directory security oliver on securing domain controllers to improve active directory security oddvar moe on securing windows workstations developing a secure baseline kurt falde on securing windows workstations developing a secure baseline archives may 2026 march 2026 january 2026 december 2025 november 2025 october 2025 september 2025 august 2025 december 2020 may 2020 january 2020 august 2019 march 2019 february 2019 october 2018 august 2018 may 2018 january 2018 november 2017 august 2017 june 2017 may 2017 february 2017 january 2017 november 2016 october 2016 september 2016 august 2016 july 2016 june 2016 april 2016 march 2016 february 2016 january 2016 december 2015 november 2015 october 2015 september 2015 august 2015 july 2015 june 2015 may 2015 april 2015 march 2015 february 2015 january 2015 december 2014 november 2014 october 2014 september 2014 august 2014 july 2014 june 2014 may 2014 april 2014 march 2014 february 2014 july 2013 november 2012 march 2012 february 2012 categories activedirectorysecurity ad fundamentals apple security cloud security continuing education entertainment entra id security exploit hacking hardware security hypervisor security interview linux unix security malware microsoft security mitigation network system security powershell realworld security security conference presentation video security recommendation technical article technical reading technical reference thecloud vulnerability meta log in entries feed comments feed wordpress org copyright content disclaimer this blog and its contents are provided as is with no warranties and they confer no rights script samples are provided for informational purposes only and no guarantee is provided as to functionality or suitability the views shared on this blog reflect those of the authors and do not represent the views of any companies mentioned content ownership all content posted here is intellectual work and under the current law the poster owns the copyright of the article terms of use copyright 2011 2025 content disclaimer this blog and its contents are provided as is with no warranties and they confer no rights script samples are provided for informational purposes only ...
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • Active Directory & Azure ...
  • web analytics

Verified site has: 219 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
101-105 106-110 111-115 116-120 121-125 126-130 131-135 136-140 141-145 146-150
151-155 156-160 161-165 166-170 171-175 176-180 181-185 186-190 191-195 196-200
201-205 206-210 211-215 216-219


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Content-Type text/html; charset=UTF-8
Transfer-Encoding chunked
Connection close
X-WS-Origin available
X-WS-RateLimit-Limit 1000
X-WS-RateLimit-Remaining 999
Date Thu, 27 Aug 2026 11:57:57 GMT
Server Apache
X-Redirect-By WordPress
Location htt????/adsecurity.org/
HTTP/2 200
content-type text/html; charset=UTF-8
x-ws-origin available
x-ws-ratelimit-limit 1000
x-ws-ratelimit-remaining 998
date Thu, 27 Aug 2026 11:57:58 GMT
server Apache
x-powered-by PHP/8.3.33
permissions-policy private-state-token-redemption=(self htt????/www.google.com htt????/www.gstatic.com htt????/recaptcha.net htt????/challenges.cloudflare.com htt????/hcaptcha.com ), private-state-token-issuance=(self htt????/www.google.com htt????/www.gstatic.com htt????/recaptcha.net htt????/challenges.cloudflare.com htt????/hcaptcha.com )
link <htt????/adsecurity.org/index.php?rest_route=/>; rel= htt????/api.w.org/
content-encoding gzip

Meta Tags

title="Active Directory & Azure AD/Entra ID Security Active Directory & Azure AD/Entra ID: Enterprise Security, Methods to Secure Active Directory, Attack Methods & Effective Defenses, PowerShell, Tech Notes, & Geek Trivia"
charset="UTF-8"
http-equiv="X-UA-Compatible" content="IE=edge"
name="viewport" content="width=device-width, initial-scale=1"
name="robots" content="max-image-preview:large"
name="generator" content="WordPress 7.1"

Load Info

page size21790
load time (s)1.932233
redirect count1
speed download11278
server IP 74.208.236.132
* all occurrences of the string "http://" have been changed to "htt???/"