<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1685828484927720237</id><updated>2011-11-03T23:36:02.691-07:00</updated><category term='Active Directory Security'/><category term='Active Directory Security Professionals'/><title type='text'>The Active Directory Security Blog</title><subtitle type='html'>Former Microsoft Active Directory Security Program Manager's blog on Active Directory Security</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.active-directory-security.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1685828484927720237/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://www.active-directory-security.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Webmaster</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1685828484927720237.post-1349010791711399640</id><published>2011-06-20T01:02:00.000-07:00</published><updated>2011-07-07T14:43:41.163-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory Security Professionals'/><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory Security'/><title type='text'>The Active Directory Security Professionals Group on LinkedIn</title><content type='html'>Folks,&lt;br /&gt;&lt;br /&gt;If you're interested in the important area of Active Directory Security, you may wish to consider joining the &lt;a href="http://www.linkedin.com/groups?gid=2006946"&gt;Active Directory Security Professionals Group&lt;/a&gt; on LinkedIn.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.linkedin.com/groups?gid=2006946"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-6VW2HHHwH9Q/Tf7-AIq-WzI/AAAAAAAAAD0/wgJqS1D1ti4/s1600/AdSecPro.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;Today, its 400+ members include highly proficient IT personnel all of whom have a keen interest in this exiiting area of Windows and IT security, and many of whom are highly experienced IT administrators and security architects at some of the most prominent organizations in the world.&lt;br /&gt;&lt;br /&gt;Some of the organizations represented include Microsoft, Hewlett Packard, Siemens, Paramount Defenses, the U.S. Department of Homeland Security and others. &lt;br /&gt;&lt;br /&gt;Membership is free, and you're welcome to join&amp;nbsp;and learn from other esteemed colleagues.&lt;br /&gt;&lt;br /&gt;Best wishes,&lt;br /&gt;Sanjay&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1685828484927720237-1349010791711399640?l=www.active-directory-security.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.active-directory-security.com/feeds/1349010791711399640/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1685828484927720237&amp;postID=1349010791711399640&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1685828484927720237/posts/default/1349010791711399640'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1685828484927720237/posts/default/1349010791711399640'/><link rel='alternate' type='text/html' href='http://www.active-directory-security.com/2011/06/active-directory-security-professionals.html' title='The Active Directory Security Professionals Group on LinkedIn'/><author><name>Sanjay</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-6VW2HHHwH9Q/Tf7-AIq-WzI/AAAAAAAAAD0/wgJqS1D1ti4/s72-c/AdSecPro.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1685828484927720237.post-1055865176985673287</id><published>2011-06-19T12:38:00.000-07:00</published><updated>2011-06-20T00:20:23.614-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory Security'/><title type='text'>Active Directory Security - The Final Frontier</title><content type='html'>Folks, &lt;br /&gt;&lt;br /&gt;In my humble opinion, Active Directory Security is the &lt;em&gt;Final Frontier &lt;/em&gt;of Security*&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-fdAdO7XBKC8/Tf5Ln47ZPHI/AAAAAAAAADI/3jJPc6hE8ZM/s1600/USS_Enterprise_NCC-1701-A.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="156" src="http://3.bp.blogspot.com/-fdAdO7XBKC8/Tf5Ln47ZPHI/AAAAAAAAADI/3jJPc6hE8ZM/s400/USS_Enterprise_NCC-1701-A.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;(*Nothing's final, but its vital enough to be deemed almost final for the next few years.)&lt;br /&gt;&lt;br /&gt;I say so because, after all, from the U.S. White House to the Fortune 1000, at the very security foundation of virtually every organization in the world lies the Active Directory. &lt;br /&gt;&lt;br /&gt;It is the very foundation of security because the very building blocks of security - accounts, passwords, groups, security policies etc. are all stored, managed and protected, in Active Directory.&lt;br /&gt;&lt;br /&gt;Should someone be able to compromise an organization's Active Directory, the entirety of all other security protection controls in place, from VPNs to firewalls and from anti-virus protection to auditing systems, could be rendered moot, useless and worthless. &lt;br /&gt;&lt;br /&gt;Ove the coming weeks, via this &lt;a href="http://www.active-directory-security.com/"&gt;blog&lt;/a&gt;, and &lt;a href="http://www.identitysecurityandaccessblog.com/"&gt;other avenues&lt;/a&gt;, I'll share helpful thoughts on this vital subject. Also, because this is a public blog, no sensitive information will be shared on this blog.&lt;br /&gt;&lt;br /&gt;Sensitive information will only be shared with folks whose identity has been authenticated, via the &lt;a href="http://www.paramountdefenses.com/newsletter.html"&gt;Vantage Point&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Thanks, and stay tuned.&lt;br /&gt;&lt;br /&gt;Best wishes,&lt;br /&gt;Sanjay&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1685828484927720237-1055865176985673287?l=www.active-directory-security.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.active-directory-security.com/feeds/1055865176985673287/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1685828484927720237&amp;postID=1055865176985673287&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1685828484927720237/posts/default/1055865176985673287'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1685828484927720237/posts/default/1055865176985673287'/><link rel='alternate' type='text/html' href='http://www.active-directory-security.com/2011/06/active-directory-security-final.html' title='Active Directory Security - The Final Frontier'/><author><name>Sanjay</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-fdAdO7XBKC8/Tf5Ln47ZPHI/AAAAAAAAADI/3jJPc6hE8ZM/s72-c/USS_Enterprise_NCC-1701-A.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1685828484927720237.post-5837516572844631407</id><published>2011-06-18T02:42:00.000-07:00</published><updated>2011-06-18T03:48:54.423-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Active Directory Security'/><title type='text'>A Blog on Active Directory Security</title><content type='html'>Folks, &lt;br /&gt;&lt;br /&gt;I'm &lt;a href="http://www.sanjaytandon.com/"&gt;Sanjay&lt;/a&gt;, former Microsoft Program Manager for &lt;a href="http://www.activedirsec.org/"&gt;Active Directory Security&lt;/a&gt;, and now CEO of &lt;a href="http://www.paramountdefenses.com/"&gt;Paramount Defenses&lt;/a&gt;, a valued Microsoft partner.&lt;br /&gt;&lt;br /&gt;If you've ever delegated authority or provisioned access in Active Directory, or read Microsoft's &lt;a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=631747a3-79e1-48fa-9730-dae7c0a1d6d3"&gt;official whitepaper&lt;/a&gt; on delegation or its &lt;a href="http://www.microsoft.com/download/en/details.aspx?id=16755"&gt;official&lt;/a&gt; Active Directory Security whitepaper, of if you've used &lt;a href="http://technet.microsoft.com/en-us/library/cc770394(v=ws.10).aspx"&gt;fine-grained password policies&lt;/a&gt; in Windows Server 2008, or used &lt;a href="http://www.microsoft.com/download/en/details.aspx?displaylang=en&amp;amp;id=19288"&gt;dsrevoke&lt;/a&gt; (... the list is long), you've come across my work. &lt;br /&gt;&lt;br /&gt;For five years, I worked for Microsoft, first as Program Manger for Active Directory Security on the Windows Server Development Team, and then as a Risk Assessor on the Threat and Risk Assessment Team with Microsoft IT. Before leaving Microsoft, I also performed an &lt;a href="http://www.paramountdefenses.com/services_security_assessments.html"&gt;Active Directory Risk Assessment&lt;/a&gt; of Microsoft's global Active Directory deployment.&lt;br /&gt;&lt;br /&gt;After moving on from Microsoft in 2005, I established Paramount Defenses Inc, a valued Microsoft partner, where I architected &lt;a href="http://www.paramountdefenses.com/goldfinger.html"&gt;Gold Finger&lt;/a&gt;, the world's first and only accurate &lt;a href="http://www.paramountdefenses.com/goldfinger_accuracy.html"&gt;Active Directory resultant-access assessment&lt;/a&gt; solution.&lt;br /&gt;&lt;br /&gt;Today the &lt;a href="http://www.paramountdefenses.com/goldfinger_overview_endorsement.html"&gt;Microsoft-endorsed&lt;/a&gt; Gold Finger, powered by patent-pending technology is deployed at over 4000 organizations in 70 countries. Perhaps that's because Gold Finger uniquely addresses arguably the most serious of &lt;a href="http://www.paramountdefenses.com/goldfinger_risk_mitigation.html"&gt;Active Directory security risks&lt;/a&gt;, i.e. the exploitation of unauthorized access in Active Directory.&lt;br /&gt;&lt;br /&gt;Over the years, I've had the opportunity to work with some of the &lt;a href="http://www.microsoft.com/presspass/exec/charney/"&gt;brightest minds&lt;/a&gt; in the industry, and to have interacted with 1000s of IT administrators from around the world. I've also spoken at &lt;a href="http://findarticles.com/p/articles/mi_pwwi/is_200412/ai_n8562248/"&gt;various conferences&lt;/a&gt; (e.g. Microsoft TechEd) and reviewed several products from numerous vendors in this space. &lt;br /&gt;&lt;br /&gt;I generally share my perspectives over at the &lt;a href="http://www.identitysecurityandaccessblog.com/"&gt;Identity, Security and Access Blog&lt;/a&gt;, and via &lt;a href="http://www.paramountdefenses.com/newsletter.html"&gt;Vantage Point&lt;/a&gt;, PD's newsletter, but they're not very technical in nature as they're not for a 100% technical audience. However, after repeated requests from many of our customers, I've established this blog to share some technical stuff on Active Directory Security.&lt;br /&gt;&lt;br /&gt;Via this blog, I intend to shed light on the most vital aspects of Active Directory. As PD's CEO, time is my most valuable resource, so while I certainly will not be blogging regularly, when I do, I'll try to make each entry be as valuable as possible. &lt;br /&gt;&lt;br /&gt;You're welcome to tune in.&lt;br /&gt;Best wishes,&lt;br /&gt;Sanjay&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1685828484927720237-5837516572844631407?l=www.active-directory-security.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.active-directory-security.com/feeds/5837516572844631407/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1685828484927720237&amp;postID=5837516572844631407&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1685828484927720237/posts/default/5837516572844631407'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1685828484927720237/posts/default/5837516572844631407'/><link rel='alternate' type='text/html' href='http://www.active-directory-security.com/2011/06/blog-on-active-directory-security.html' title='A Blog on Active Directory Security'/><author><name>Sanjay</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
