Today Active Directory Security is mission-critical to organizational security worldwide and thus mission-critical to Cyber Security worldwide. On this blog, former Microsoft Program Manager for Active Directory Security, and today, CEO of Paramount Defenses, shares valuable technical insights on Active Directory Security.


Monday, July 15, 2013

The Active Directory Security Resource Center

Folks,

I hope this finds you all doing well. As you may know, the Cyber Security temperature around the world continues to rise, and as it does, it potentially threatens organizational Active Directory deployments worldwide.

In an effort to help organizations worldwide adequately secure and defend their Active Directory deployments from compromise, I recently commissioned the development of an Active Directory Security Resource Center.

Active Directory Security


The intention was to help organizations better understand the risks to which their Active Directory deployments may be exposed, as well as to help them determine how to assess and mitigate risks to their Active Directory deployments, measurably, efficiently and reliably.

It thus provides valuable information on numerous aspects of Active Directory such, including the Top Security Risks to Active Directory, as well as a set of adequate risk mitigation measures that can be enacted to protect Active Directory from these risks.

It thus touches upon numerous aspects of Active Directory Security, including Domain Controller Security, Administrative Account Reduction, Active Directory Audit, Active Directory Auditing, Active Directory Security Tools, Active Directory Checklists, as well as other Active Directory Resources.

One of the main reasons for commissioning it was that, based on what we're seeing, most organizations around the world, are substantially deficient in their ability to successfully thwart potential cyber security attacks aimed  at Active Directory deployments. The only part more worrisome is that most of these organizations don't actually even realize the ramifications of an Active Directory compromise. That's a worrisome situation, and one that we intend to help improve to the extent we can.

The Active Directory Security Resource Center is thus one of many ways in which we intend to help organizations.

Its over at -  http://www.paramountdefenses.com/active-directory-security

Kindly note that it is not intended to be a comprehensive source of information, as we expect Microsoft Corporation to be that source. It is however, intended to provide highly actionable and valuable guidance, as well as pointers to other resources, so organizations can better understand the threats to Active Directory, as well as determine how to mitigate those threats in a timely manner.

In days to come, we will also declassify the #1 cyber security risk to Active Directory deployments today. Before we do so, we will also share valuable additional information on this vital subject, so that organizations can better understand how to protect their Active Directory deployments from harm.

Best wishes,
Sanjay.

Wednesday, May 29, 2013

Active Directory Security - A Top Cyber Security Priority Today

Folks,

As you may know, today Active Directory is at the very foundation of enterprise security and cyber security worldwide.



Given Active Directory's foundational role in enterprise security worldwide, based on the principle of adequate protection, it is only logical that the security of the Active Directory itself is paramount to organizational security worldwide.

As logical as it may sound, based on what we have seen in our vast experience over the last decade, we are deeply concerned to see that most organizations today across the world do NOT yet realize just how important Active Directory security really is.

I suppose the only thing more concerning is that not only do so many organizations not realize this yet, they also do not seem to possess the level of technical skill-set and expertise that is required to adequately protect their underbelly.

(You'd be surprised if we told you just how many government agencies are still looking for mere account lockout status tools.)

In addition, so many organizations believe that the presence of an Active Directory auditing solution is generally sufficient to provide adequate security for Active Directory because it can help them audit the enactment of a malicious task.

Little do they realize that auditing is merely a reactive security measure, that at best, aids in potentially detecting the occurrence of a malicious action and determining the identity of the perpetrator. The key word here is REACTIVE. The fact that the occurrence of a malicious task showed up in an audit log indicates that the malicious task has already been performed.

The keyword here is ALREADY. In such a situation, although auditing could potentially help identify the perpetrator, depending on the perpetrator's skill, the opportunity to enact a single malicious task could be (/have been) sufficient to inflict substantial, and often irreversibly damage to not just the Active Directory, but the entire Windows Server based IT infrastructure. (The first thing a smart perpetrator would do is disable all the admin accounts so no one can even login to try and stop him/her.)

The point is that the presence of any one single security measure such as reactionary auditing, is hardly sufficient to provide adequate security for an Active Directory deployment. Providing adequate security for Active Directory requires and involves the presence of numerous procedural, policy and technical security controls, that work together to provide adequate protection.

So many organizations today seem to be substantially deficient in providing adequate protection for their Active Directory deployments, and the #1 reason for this is that Active Directory security does not appear to be a high enough priority for them.

Thus, in the best interest of all organizations, we've put together a simple succinct document that unequivocally communicates the importance of protecting foundational Active Directory deployments. You can download it by clicking the image below, or clicking here.
 

The Importance of Active Directory Security
 
We do hope that this simple document helps organizations unequivocally understand just how important the security of their foundational Active Directory is to their security, and in their own best interest, ensure its adequate protection at all times.

As the very foundation of enterprise security worldwide, Active Directory security is not just important, it is paramount.

What else could be more important?

Best wishes,
Sanjay

Tuesday, May 21, 2013

Active Directory Security Checklist

Folks,

As you may know, today Active Directory is at the very foundation of enterprise security and cyber security, worldwide.




At Paramount Defenses, we go to great lengths to provide thought leadership in this vital area of cyber security, by not only delivering the world's most valuable Active Directory security solutions that today help secure and defend the world's most respected organizations , but also by responsibly sharing valuable subject matter expertise with 1000s of organizations across 100+ countries worldwide.

In days to come, we will be declassifying arguably the #1 Active Directory security risk that organizations face today.

Before we did so, we felt it necessary to share a simple yet effective Active Directory Security Checklist designed to help organizations assess and mitigate risks to their foundational Active Directory deployments. (One of the reasons for doing so is that the #1 security risk to Active Directory deployments can be easily mitigated by ensuring that one of the items on this checklist is adequately fulfilled.)

You can download this Active Directory Security Checklist by clicking here or on the image below.







This checklist is intended to be a succinct, prioritized high-level check-list and is designed to help IT personnel assess the security afforded to their Active Directory deployments.

We humbly advise all organizations to take the security of their foundational Active Directory deployments seriously because a Microsoft Windows Server based IT infrastructure, and the entirety of IT resources stored and protected by it, are arguably only as secure as is its underlying Active Directory.

Kindest regards,
Sanjay

Tuesday, February 26, 2013

Active Directory Security - Breaking the Silence

Folks,

As you may know, today cyber security has become mission-critical to global security, and at the very foundation of cyber security in over 85% of all organizations worldwide lies a single technology - Active Directory.

Active Directory Security

For over 7 years we have known about the most serious of all security risks to Active Directory, and for 7 years, we have kept silent about it, because we know that disclosing any information about such risks without there being adequate solutions to help organizations mitigate these risks would have been irresponsible.

Today, with the availability of security solutions that can adequately and swiftly mitigate these risks, we will break the silence and let the world know about arguably the most serious security risk to their foundational Active Directory deployments, so they can adequately secure and defend their mission-critical Active Directory deployments from the risk of swift and systemic compromise.

We would ideally not have liked to share this information at all, but we have reason to believe that certain advanced persistent threats, such as specific hostile governments and organized crime syndicates, may already have gotten a drift of these critical security risks and may possibly even be working on exploits to inflict the foundational cyber security defenses of organizations worldwide.

Thus, on September 12, 2013 we will finally break the silence on this blog, and share with you information about the most serious of all risks to foundational Active Directory deployments worldwide. (The days of "security by obscurity" are going to be over.)


Note: As some of you may know, we were initially going to declassify this on September 02, 2013. However, in light of recent cyber security attacks by the Syrian Electronic Army, we were requested to postpone this. Out of an abundance of caution, we have decided to postpone it by 9 days. We will NOT postpone it again, come rain, wind, war or shine.


[September 12, 2013 Update:] Here is the link to the declassified risk - http://www.active-directory-security.com/2013/09/Active-Directory-Privilege-Escalation-Top-Cyber-Security-Risk.html

Thanks,
Sanjay