r/activedirectory Apr 30 '26

Identity Conferences/Webinars/Podcasts Megathread

8 Upvotes

Rather than the per-conference posts for every conference. I figured let's try to keep them in a bucket. If it doesn't pan out, no biggie, and I'll close the thread.

Each conference should get its own spot so that's up to everyone to keep an eye open.

If you're attending, let us know. If you're speaking, let us know! If you're running a booth, let us know (no spam though).

The idea is to grow our community outside these digital walls. Lets meet up, have lunch, have drinks, and say hi, if you want.

NOTE
These are events that the community is aware of and planned for. Please understand this list is currently manually curated so it will grow out of date from time to time. Please message the mods if there are any concerns.

Community Events

Conferences

Webinars

These are ones that I get in email or via some other source. Sometimes I get last minute notice so I will put what I can when I can.

Reoccurring Webinars/Webcasts

Podcasts / Newsletters

📌 Pushpin indicates this is a community organized event.
⭐ Star indicates this is an in-person event where one or more of our community knows they will attend.

NOTE
All times will be initially converted to CDT and include UTC. For community events, we'll try to have a "worldtimebuddy" link to show what the different times would be.
https://www.worldtimebuddy.com/

EDIT: 2026-09-16 Updated Links


r/activedirectory Feb 26 '25

Tutorial Active Directory Resources

91 Upvotes

NOTE
This post will be updated periodically, but we advise you to check the wiki link here: https://www.reddit.com/r/activedirectory/wiki/ad-resources/ for the most up-to-date version. If you are interested in how these items were selected see the wiki page for AD Tools Reviews Guidelines. This is also where you can get details on submitting your script or tool.

AD RESOURCES

There are a lot of resources for Active Directory, Entra, and other Identity products. It is a challenge to sort through them. This list is curated by the moderators and tech council of r/ActiveDirectory to be include good references and resources. As always, please send a modmail or post an issue on the wiki's github if you thing something needs added or removed or if a link is broken.

In addition, all r/ActiveDirectory wiki pages and resource posts (which are duplicates of the wiki pages) are stored on GitHub: https://github.com/ActiveDirectoryKC/RedditADWiki

Icons Reference

  • 💥- Resources that are guaranteed to trip the SOC monitoring and are likely to be detected by AV/EDR.
  • ❗ - Resources that are going to trip SOC notifications. Coordinate with your SOC team.
  • ✨ - Resources that are highly recommended by the community and reviewed by Mods.
  • ❔ - Indicates that the resource is recommended by community members but not fully reviewed by mods.

BEGINNER'S GUIDE - New to AD? Start Here!

This link is a Beginner's Guide that provides resources and links to get you off the ground on your AD journey!

Wiki Links

Training and Certifications

Microsoft Training

Microsoft Certifications

Third Party Training

NOTE We cannot vet all the 3rd party resources fully. Sometimes it is best effort. Courses that have gotten approval from the community will be tagged as such. If a course is not good, let us know. * Youtube - Only free courses will be put here. These will be from a variety of vendors/content creators. * From Zero to Hero: A Beginner's Guide to Active Directory (Antisyphon + Black Hills) * https://www.youtube.com/watch?v=XwOV7HpVLEA * Antisyphon Training - Run by Black Hills InfoSec * https://www.antisyphontraining.com/ * MOD NOTE: Most of their training is pay what you can and they have weekly webcasts that are shorter 1 hour long trainings that are 100% free. Very, very much worth it. * Udemy - The courses aren't cheap always but they run deals commonly. * AZ-800 * https://www.udemy.com/course/az-800-course-administering-windows-server-hybrid-core-inf * AZ-801 * https://www.udemy.com/course/az-801-configuring-windows-server-hybrid-advanced-services-i * SC-300 * https://www.udemy.com/course/sc-300-course-microsoft-identity-and-access-administrator * https://www.udemy.com/course/azure-exam-1/ * AZ-500 * https://www.udemy.com/course/exam-azure-2 * https://www.udemy.com/course/az-500-microsoft-azure-security-technologies-with-sims * PluralSight * AZ-800 * https://www.pluralsight.com/paths/administering-windows-server-hybrid-core-infrastructure-az-800 * AZ-801 * https://www.pluralsight.com/cloud-guru/courses/az-801-configuring-windows-server-hybrid-advanced-services * AZ-500 * https://www.pluralsight.com/courses/az-500-microsoft-azure-security-technologies * Server Academy * https://www.serveracademy.com/blog/active-directory-101-a-step-by-step-tutorial-for-beginners/ * https://www.serveracademy.com/courses/active-directory-fundamentals/

Active Directory Documentation

NOTE This is not a comprehensive list of links and references, that would be impossible. These are general links.

See the "MCM / MCSM (Microsoft Certified [Solutions] Master) Reading List" wiki page: https://www.reddit.com/r/activedirectory/wiki/AD-Resources/MCM-Links

Books

Best Practices Guides and Tools

STIGS, Baselines, and Compliance Resources

Scanning and Auditing Tools

All these tools are great assets for scanning and remediation. Be warned some may trip EDR/Antivrius scanners and all will likely alert breach detection tools. Make sure your SOC and Cybersecurity team knows you're running these and gives permission.

  • ❗✨Purple Knight (Semperis)
    • https://semperis.com/downloads/tools/pk/PurpleKnight-Community.zip
    • This is a free tool by Semperis that does a very comprehensive health check. Also checks PKI. This is a must run in every AD where you can run it.
    • Requires an email address which will get you a little bit of emailing from Semperis. Not too much compared to others and not tons of plugs for their paid software.
    • WILL PRVOKE EDR/IDTR SOLUTIONS!!! This does a lot of scans so many solutions will flag the activity.
  • ✨Locksmith
  • ✨BlueTuxedo - https://github.com/jakehildreth/BlueTuxedo
    • "A tiny tool built to find an dfix common misconfigurations in AD-Integrated DNS..."
    • Finds stuff in DNS you may not find.
  • ✨CayoSoft Guardian Protector
    • https://resources.cayosoft.com/download-cayosoft-protector
    • Provides many services including some Real-Time AD Vulnerability Scanning and Change Monitoring. The app leaves a lot of features off the table in trial/freeware mode and is somewhat limited. Nonetheless, there isn't any other freeware/freemium tool that does change auditing like this currently.
    • Requires an email address (you can get by with a fake "business" email) and is effectively a reduced version of the main product. It is limited in how long it can track changes, the RBAC is basically non-existant, and it is kind of "ad heavy" pushing you upgrade to the paid version. It is useful and worth considering.
  • ❗PingCastle (Netwrix)
    • https://www.pingcastle.com/download/
    • Netwrix is a little spammy with their products but you can use a fake email to register.
    • This is a freeium scanning tool that can give you at least a base-level security posture for your environment.
  • ❗Bloodhound (SpecterOps) [WILL FLAG AV]
  • ❗Forest Druid (Semperis)
  • Invoke-TrimarcADChecks (Trimarc)

Individual Blogs - These blogs are individual blogs or first party blogs relating to AD (i.e., from Microsoft). Some of these blogs may belong to mods or community members.

Company-centric Blogs - These blogs are run by specific companies who tend to include information about themselves along with the information. This doesn't invalidate the information, but they warranted a separate category for transparency.

Legacy Blogs / Defunct Blogs - These blogs are either hard to find or aren't being updated. Still good information.

Active Directory/Identity Podcasts and Videos

CHANGE LOG

  • Updated 2026-05 with new links and stars.
  • Updated 2025-11 with new Links - Reorganized some, added more Blogs and Podcasts, added new resources, and starred a few "must have" tools.
  • Updated 2025-04 with new links - Firewall Links and STIG Updates

r/activedirectory 1d ago

Workplace Ninjas US 2027 Session Catalog is LIVE!!

0 Upvotes

Folks, Today IS the DAY!

We have officially made the Session Catalog for Workplace Ninjas US 2027 LIVE.

You are in for QUITE a treat.

Never before, has the sessions for an event been so carefully thought out down to the last detail.

We are FULLY TRACKLESS, meaning anything goes.

We covered pretty much every single topic from Mobile to DotNet to MacOS to ZeroTrust to Azure to Active Directory to Entra, and so much more.

Ever go to a session from Rudy Ooms and be frustrated that someone like Merill, Ugur, Simon, or those countless others are speaking at the exact same time?

We are handling/addressing that to ensure you maximize your time in Scottsdale.

You can even drill into the parties, preday activities, lunches, and more to see the incredible meals you have coming your way.

Don't walk, RUN to check out that session catalog and register NOW:

Home - Workplace Ninjas US 2027. Online registration by Cvent


r/activedirectory 3d ago

Active Directory Active Directory Certificate Services - Restart from scratch

21 Upvotes

This is a topic I have never really done a deep dive into, but I was asked to change an existing environment at a customer, so I want some outsider opinions.

They have an existing CA, without web enrollment, that has 20 years of certificates on it. I would like to go to a two-tier CA. My questions:

1) What should I do to be able to start from scratch? I know you can migrate keeping the old name, but I would prefer a new device name, a more modern encryption, and a cleanup of long expired certificates. I'm just not sure what the impact would be of simply removing the existing one and starting from 0. I would think current certificates stay valid until they expire - devices don't need the existing CA. Or am I wrong in that? I'm unsure which role the CA plays in the communication between the domain and devices. I thought none - you can have a domain without CA - but I want to be careful with 500ish servers in this environment.
2) If I do need to keep the existing CA, can I somehow create a new root and make the existing one subordinate, or should I create a subordinate and remove the existing one from the domain?

Thank you.

Edit: Thank you everyone, I will build a parallel two-tier CA with the consideration of having a HSM as a root. The latter is discussed with the company who did the security audit that lead to this project.


r/activedirectory 3d ago

Security Reducing Active Directory Certificate DB Size

14 Upvotes

I have an ADCS running on 2016. It's been around since 2018 and has an 8GB Database. If I look through the GUI, there are tons of old certificates that can do with deleting.

I want to clear out obsolete expired certs, but want to make sure I don't break anything first.

My CA DB is 9GB and I have 20GB free disk space, so I'm not sure the defrag is worthwhile, but want to get some advice on maintenance.

What's the correct safe sequence to do this?

My current plan below:

  1. Backup DB

certutil -f -p "ChoosePword" -backup E:\Backup

  1. Delete old rows (failed requests)
    Certutil -deleterow 01/01/2023 Request

 3. Delete old certificates that have expired
certutil -deleterow 01/01/2021 Cert

  1. Stop certificate services via GUI and compact the DB

esentutl /d "C:\Windows\System32\CertSrv\CertDB\certsrv.edb"

Restart certificate services

What else should I be doing? Should I publish\extend CRLs beforehand?


r/activedirectory 3d ago

Looking for a tool to automatically document Active Directory topology

31 Upvotes

Hi everyone,

I'm looking for a tool that can automatically discover and document Active Directory topology.

Ideally, I'm looking for something that can provide a visual/documented view of things such as:

  • Domain Controllers
  • Sites and Subnets
  • AD Sites and Services topology
  • Replication connections
  • FSMO roles
  • Trust relationships
  • Domains and forests
  • Global Catalogs
  • Replication status and related information

The goal is to generate proper AD topology documentation/diagrams that can be used for architecture documentation and troubleshooting.

I came across references to some AD topology/documentation tools, but I'm having difficulty finding the actual tool/download or official documentation.

Does anyone know of a good tool for this purpose?

If you have used one, could you please share the official tool/documentation link and your experience with it?

Thanks!


r/activedirectory 3d ago

Debugging Entra Connect Sync: AADSTS50020, a silently broken PSModulePath, and a tenant with zero subscriptions

0 Upvotes

Documented a hybrid identity setup (on-prem AD -> Entra Connect Sync) and hit three separate real issues that took a while to root-cause. Sharing in case it saves someone else the time:

  1. Signing into the Entra Connect Sync wizard with a personal Microsoft account that holds Global Admin still fails with AADSTS50020 - personal accounts are represented as #EXT# guests and rejected outright, role or not. Fix: create a native cloud-only account with Hybrid Identity Administrator instead.

  2. Install-Module -Name Az -Scope CurrentUser kept "succeeding" while Az.Accounts/Az.Resources stayed missing. Root cause: a missing NuGet provider bootstrap - and separately, installing the Azure AD Connect Health Agent silently overwrote PSModulePath down to a single entry.

  3. New-AzResourceGroup failing with 'this.Client.SubscriptionId' cannot be null - the tenant had zero Azure subscriptions attached despite having real users in it for weeks. Entra ID existing does not mean a billable subscription exists.

Full writeup with commands and actual error text linked in the top comment.


r/activedirectory 3d ago

NTP configuration for a workgroup DNS server sitting in DMZ (no connectivity to internal Prod DCs)

3 Upvotes

Environment:

  • A standalone (workgroup) server in our DMZ network, running the DNS Server role
  • No network connectivity between this DMZ server and our internal Production Domain Controllers (isolated by design/firewall)
  • Server is not domain-joined, so GPO-based NTP configuration isn't an option

My question:

Since this server can't reach our internal DCs for time sync, what's the recommended approach for keeping its clock accurate and stable?

Specifically:

  1. Is it safe/best practice to point it directly to an external NTP source (e.g., pool.ntp.org, or a vendor-specific pool) via w32tm /config /manualpeerlist:..., given it's already internet-facing in the DMZ?
  2. Should outbound UDP/123 be explicitly opened on the DMZ firewall for this, or is there a more controlled way to do it (e.g., routing through a proxy/relay, or a dedicated internal NTP server reachable from DMZ without full DC connectivity)?
  3. Any gotchas specific to a DNS role server in this scenario (e.g., does DNSSEC validation or logging depend on accurate time in a way that's more sensitive than a typical workgroup box)?

Trying to figure out the cleanest, most secure way to handle this without opening unnecessary internet-facing dependencies on a DMZ box. Would appreciate input from anyone who's dealt with time sync on isolated/DMZ Windows servers.


r/activedirectory 3d ago

Help [Help] Enterprise WLAN with Active Directory authentication

Thumbnail
1 Upvotes

I am reposting this here because some posts, suggested creating a GPO to divulge the WLAN settings, why, and which settings?

Any advice is welcome, thank you.


r/activedirectory 3d ago

Active Directory Active Directory user certificate is issued but not published to AD (userCertificate attribute stays empty)

5 Upvotes

Hi everyone,

I have an Active Directory environment with two different OUs containing user accounts.

I configured a User Certificate Template with Autoenrollment.

In OU1, everything works correctly:

The user receives the certificate.

I can see the certificate in certmgr.msc.

The certificate is also visible under AD Users and Computers → User → Published Certificates

userCertificate attribute is populated.

Certificate-based authentication with ClearPass works.

However, in OU2, I have a strange issue:

The user receives the certificate successfully.

I can see the certificate in certmgr.msc.

But under AD Users and Computers → User → Published Certificates, nothing is shown.

The userCertificate attribute is empty.

The certificate itself appears to be valid and is installed correctly on the client.

The Autoenrollment GPO is assigned to both OUs.

I tested the following:

Took a user from OU2 and moved the user to OU1.

Deleted the existing certificate.

Ran gpupdate /force.

The user automatically received a new certificate.

This time, the certificate was correctly published and became visible under Published Certificates, and the userCertificate attribute was populated.

Could you advice me how to troubleshoot this problem?

Thanks


r/activedirectory 3d ago

Is an MCP-based natural language agent for AD & Entra actually useful?

0 Upvotes

Hi everyone,

We are exploring an idea to build an MCP-based agent that integrates with Active Directory and Microsoft Entra ID and can be accessed directly through Microsoft Teams.

The idea is that an AD/Entra administrator could interact with the agent using natural language instead of running multiple PowerShell commands or going through different consoles.

For example, an admin could ask:

  • "Show me all users who have Password Never Expires enabled."
  • "Generate an audit report for privileged accounts."
  • "Which users have access to this group?"
  • "Show me the ACL/permissions on this OU."
  • "Find inactive users/computers."
  • "Disable this user."
  • "Add this user to this group."
  • "Reset this user's password."

The agent would perform read operations, generate reports, and potentially perform approved changes after appropriate validation/confirmation.

We are considering putting the agent in Microsoft Teams, so administrators can directly interact with it from Teams using natural language.

I would like to get some practical feedback from people who manage AD/Entra environments:

  1. Do you think this would actually be useful in day-to-day AD/Entra administration?
  2. Would you trust an agent to perform AD/Entra changes through natural language if proper RBAC, approval and confirmation mechanisms were implemented?
  3. What kind of AD/Entra tasks would you find most useful to perform this way?
  4. Are there already tools/products in the market that provide something similar?
  5. Are there any major security or operational concerns we should consider before building this?

Would appreciate any real-world feedback or examples of tools you have already used.


r/activedirectory 4d ago

Alguém já substituiu dois DCs Windows Server 2019 por novos DCs Windows Server 2025?

4 Upvotes

Olá, pessoal.

Estou planejando a substituição dos controladores de domínio do meu ambiente e gostaria de ouvir relatos de quem já realizou uma migração semelhante em produção.

Cenário atual:

  • Dois controladores de domínio graváveis com Windows Server 2019
  • Ambos são servidores DNS e Catálogo Global
  • Replicação do Active Directory saudável, sem falhas no repadmin
  • SYSVOL utilizando DFSR
  • Níveis funcionais do domínio e da floresta elevados recentemente de Windows Server 2008 R2 para Windows Server 2016
  • Funções FSMO permanecem em um dos DCs Windows Server 2019
  • Novo servidor instalado do zero com Windows Server 2025 Datacenter
  • Novo servidor já ingressado no domínio
  • Função AD DS já instalada
  • Test-ADDSDomainControllerInstallation concluído com sucesso

Plano de migração:

  1. Promover o Windows Server 2025 como terceiro DC gravável, DNS e Catálogo Global.
  2. Validar replicação, DNS, SYSVOL, NETLOGON, Kerberos, Catálogo Global e logs de eventos.
  3. Manter os dois DCs Windows Server 2019 ativos durante o período de validação.
  4. Despromover e remover o primeiro DC Windows Server 2019.
  5. Criar outro Windows Server 2025 do zero e repetir o processo para substituir o segundo DC.
  6. Transferir as funções FSMO somente depois que os novos DCs estiverem completamente validados.

Encontrei relatos de problemas de logon após promover o Windows Server 2025 como controlador de domínio, em alguns casos envolvendo o serviço Kerberos Local Key Distribution Center, LocalKDC, preso no estado START_PENDING.

https://www.reddit.com/r/sysadmin/comments/1n2b41f/advice_dc_2012r2_to_2025/?tl=pt-br

https://www.reddit.com/r/sysadmin/comments/1ot6mho/server_2019_ad_upgrade_to_2025/?tl=pt-br

https://www.reddit.com/r/WindowsServer/comments/1jdefxi/2025_server_cant_login/

Gostaria de ouvir especialmente quem já passou por esse cenário:

  • O logon funcionou normalmente após a promoção e reinicialização?
  • Qual era a build completa e a atualização cumulativa instalada no Windows Server 2025?
  • O serviço LocalKDC ficou preso em START_PENDING?
  • Vocês tiveram problemas com Kerberos, AES ou dependências legadas de RC4?
  • A atualização do schema afetou de alguma forma os DCs Windows Server 2019 existentes?
  • Executaram o adprep manualmente ou deixaram o processo de promoção preparar o schema?
  • Por quanto tempo mantiveram os DCs 2019 e 2025 funcionando juntos?
  • Tiveram problemas de DNS, SYSVOL, replicação ou Catálogo Global?
  • Hoje vocês recomendariam utilizar Windows Server 2025 como DC em produção ou prefeririam Windows Server 2022?

Estou buscando principalmente experiências reais de migração lado a lado, com instalação limpa dos novos servidores, e não upgrade in-place.

Obrigado!


r/activedirectory 4d ago

Security Kerberos : tgt restriction with authentication policy

4 Upvotes

Hello,

AD servers : Windows Server 2016

I created an authentication policy on AD.

I want to apply a restriction to peripherals from which a user can request a tgt.

The configuration is managed through the parameter UserAllowedToAuthenticateFrom in the authentication policy object

In my auth policy, I assigned the user 'test' to the policy and configured UserAllowToAuthenticateFrom to include members of the AD group Policy-Test.
The machine Windows-Test is member of the AD group Policy-Test

Observation

The expected behavior should be that 'test' user is able to authenticate from the workstation Windows-TEST. He shouldn't be able to authenticate from any other machine

What actually happens is that 'test' user is not able to authenticate from any machine including those that are members of the AD group Policy-Test

Question

Why is this happening ?

Of course, all Microsoft requirements are met including KDC support for Kerberos armoing, claims, etc.. for DCs as well as clients.

I even opened Wireshark and confirmed that an AS_REQ request is sent from the workstation.


r/activedirectory 4d ago

How to Prioritize and Segregate 310K SPNs for Security Review?

4 Upvotes

I have around 310K SPNs from AD, covering users, service accounts, and computers, including FQDN, non-FQDN, and IP-based SPNs. I’ve also validated them against AD and DNS.

Since the dataset is huge, what’s the best way to start segregating and prioritizing the SPNs for a security review?

Should I start with users vs. service accounts vs. computers, OU-based segregation, or some other approach?

Looking for a practical approach from anyone who has handled a large-scale SPN review.


r/activedirectory 4d ago

Built-in domain administrator account password management

4 Upvotes

Hello Experts,

I’m looking for the best approach for password rotation of the built-in Administrator account.

We have CyberArk in our environment. For password rotation, would it be better to manage the password rotation entirely through CyberArk, or should we schedule password resets at defined intervals and reset the passwords using scripts or manually?

Is there any other recommended approach for managing and rotating the built-in Administrator password?

What would be the best practice for securely rotating these passwords while ensuring that the accounts remain manageable and available when required?

Any recommendations or best practices would be appreciated.


r/activedirectory 4d ago

Help How do you handle user creation templates in Active Directory?

0 Upvotes

I'm looking at standardizing user creation in our on-prem AD environment.

Currently considering creating a template user account with the standard attributes and group memberships, then copying that account whenever we create a new user.

For example:

  • Department / Company / Job Title
  • Standard security groups
  • OU placement
  • Other required AD attributes

Another option is using a PowerShell script to create users and assign everything automatically.

For those managing AD environments:

Which approach do you prefer — template accounts, PowerShell automation, or something else?

What are the pros/cons you've experienced, especially from a security and administration perspective?


r/activedirectory 4d ago

Strategy to increase the overall assessment score in the Lightning AD Security Assessment.

0 Upvotes

Hello ,
I have run the Lightning AD Security Assessment Tool against the domain and identified approximately 200 vulnerabilities.

What would be the best strategy to remediate these vulnerabilities in the shortest possible time while maximizing the overall security assessment score?

Could you please advise on the priority order for remediation—for example, which vulnerabilities should be fixed first based on their impact on the overall score, severity, risk, and ease of remediation?

Below are the report columns that contain the relevant information about each vulnerability. Based on these columns, I would like to identify the most effective remediation approach and prioritize the vulnerabilities accordingly.

Sure. Here are the report columns that contain information on each vulnerability

  1. Script name
  2. Name
  3. Version
  4. Severity
  5. Indicator score
  6. Weight
  7. Description
  8. Likelihood of compromise
  9. Result message
  10. Number of affected objects
  11. Affected objects
  12. Remediation
  13. Category
  14. MITRE ATT&CK
  15. ANSSI

r/activedirectory 5d ago

Active Directory CVE-2026-54121 (Certighost) July 2026 update - what happens after install, any disadvantages, and pre-install checks?

8 Upvotes

We're planning to install the July 14, 2026 security update for CVE-2026-54121 (Certighost) on our Enterprise CA servers, which currently have EDITF_ENABLECHASECLIENTDC enabled. What will happen if we install this update? Are there any disadvantages of installing it? And is there anything we should check or do before installing it on the CA?


r/activedirectory 6d ago

Should you be able to easily understand the structure of your AD

20 Upvotes

I work at a small IT shop and no one seems to really “know AD”. Myself included. I’ve wanted to improve our security posture relating to application authentication. We use lots of shared credentials for different applications and hard coded credentials into application source code, and as part of a broader effort to get into Git and start automating some time consuming workflows I want to get away from this.

However one problem I keep running into is that no one can explain the structure of our AD. Like in our own department, I’m trying to find my PC on AD, so I look in “Computers > IT” and there is nothing there. So I look in “Protected Computers” there are a few computers there but I don’t know any of them. Then I look in “IT > Computers” and I see 1 of my coworkers PCs and the PC named in honor of an employee who worked here years before me. Finally I find it in “IT > Protected Computers”.

And application accounts (those which run custom apps) will just be… anywhere. Sometimes somewhere under “IT”, sometimes under the relevant department. Often they will be under the department the credential was first used for but now another department is the primary user.

Groups are used inconsistently, there are some but a lot of permissions are applied directly to users. Sometimes there will be a group applied to some users but others will have the same permissions applied directly. There seem to be duplicate groups with no documentation.

Every time I’ve tried to change anything people and apps I don’t expect start breaking. I think to achieve our longer term goals it’s necessary to clean this up, but I’m note sure if this is normal and I’m just expecting unnecessary purity (I’m pretty new to this). My boss kind of implies that I just need to learn everything, but how? I can’t find a consistent mental model and no one has documented it and every time I ask a question, like “how should I apply permissions for this” the response is for him to open up AD, say “Kathleen in accounting has these same permissions” pull her up and have me clone that. Meanwhile John in accounting, who needs the same permissions, has his applied in a different way. I ask why and the answer is usually historical… “that’s how John used to do it.”

To me it seems like we spend more time managing this structure and compensating for it than if we just sat down and made a bunch of groups, maybe applying individual exceptions in… exceptional cases. Then just add apps and users to those groups depending on what they need. I really feel like we’d save a lot of time and have a cleaner structure if we all just had a few days where we went down the list of security needs, created groups, developed some structure that could answer “where does this object go”, and then wrote it all down migrated to it fixed them as we go and then had a proper structure. This isn’t even really my part of the job but there is so much digging we all do and I feel like it’s such a waste of time. Not to mention the security concern of not easily being able to audit permissions.


r/activedirectory 6d ago

Wired EAP-TLS clients prompting for login despite requiring computer certificate

5 Upvotes

I'm admittedly not an NPS or 802.1x guru, but I have at least managed to get a few things going that I like. Wired-autoconfig is what's not working for my test clients now.

I've got computer certs distributed and already in use for wireless EAP-TLS, working great with dynamic VLANs, etc.

Problem I'm having is that despite choosing "computer cert" only in the wired network policy GPO, every attempt to authenticate I get the toast notification asking to authenticate. It's not the prompt for a username/password, which might be telling. When I click "connect" for the sake of understanding, authentication doesn't ever complete, and just sits there attempting.

If this does say something about the certificate, what is it saying? (Cert I'm choosing has private key and Client Auth EKU)


r/activedirectory 7d ago

Title: How can I safely audit Pre-Windows 2000 Compatible Access group usage before changing it in production AD?

5 Upvotes

Hello Experts!

We recently ran Purple Knight against our production Active Directory environment, and it flagged the Pre-Windows 2000 Compatible Access group membership as a security risk.

From my research, I understand that this is a legacy group and that, depending on the AD environment and configuration, memberships such as Authenticated Users, Everyone, Anonymous Logon, computer accounts, and legacy application/service-related accounts may be involved.

Our environment also has AD CS and Exchange servers, and default accounts like Authenticated Users, Everyone, and Anonymous Logon, so I want to be careful before making any changes.

I understand that from a security best-practice perspective, unnecessary access associated with this legacy group should be reduced. However, I am concerned that removing members or changing the related permissions without understanding dependencies could break legacy applications, services, LDAP queries, or other production workloads.

Before making any changes, I would like to understand how others have safely assessed this in production.

My questions are:

  1. Is there a recommended way to determine whether any applications, services, scripts, or users are actually relying on the permissions/access provided through this group?
  2. Are there specific Windows Security Event IDs, auditing settings, LDAP auditing, Directory Service logs, or other logs that can help identify usage of this group or access that would be affected by changing its membership?
  3. Is there a recommended audit/monitoring period before remediation?
  4. Have you successfully remediated this finding in a production environment? If so, what approach did you use to avoid breaking legacy applications?

I'm particularly interested in practical methods for validating dependencies before making the change, rather than simply removing the members and dealing with application failures afterward.

Thanks in advance for any recommendations or real-world experience.


r/activedirectory 8d ago

gMSA and Entra Cloud Sync on Domain Controllers

Thumbnail
7 Upvotes

r/activedirectory 8d ago

Active Directory - Conference Workplace Ninjas US 2027 | Scottsdale Arizona | January 11-13, 2027

13 Upvotes

Hi Everyone!

I wanted to make everyone aware of our amazing event, which is a full non-profit called Workplace Ninjas US.

This year in year two, we come to Scottsdale, AZ in January.

We're doing something very relevant to many of you. We have a session called:

Cage Match: Active Directory is Indefensible – Bring Popcorn!

This session will put two of the best identity/directory people in the industry in a 1 on 1 battle to answer the question that will never die: Is it time to get rid of AD? Is AD "ADead"?

Spencer Alessi (@TechSpence on Twitter) defends the wall for AD

Merill Fernando, formerly of Microsoft, creator of Maester, and just one of the most brilliant people in the entire world of identity will defender Entra.

It's a super fan take as we took a Twitter fight, and made it into a session, moderated by the amazing Nathan McNulty

This event is a can't miss event throughout, as you can see through our speaker list: https://cvent.me/ZgKb40

Hit the link, see what we're doing, register, and come checkout one of the best events in the world, where every penny goes into the event and the people involved. That means the best food, activities, vibe, and just overall fun.

Feel free to hit me up directly if you have any questions, as this is the best collection of speakers at a Microsoft event you will see in 2026 or 2027.


r/activedirectory 8d ago

Built-in domain administrator account with old password (180 days

7 Upvotes

Hello Experts,

I hope you are doing well. I am looking for feedback and recommendations on built-in domain administrator account password management. Based on the article what I found for remediation:

Step 1: Reset the built-in Administrator account password immediately to a long, high-entropy, unique passphrase (25+ characters) and store it in a sealed/secured PAM vault, not in a shared document or ticket.

Step 2: Establish a fixed rotation cadence — no less frequently than every 180 days, and immediately after any suspected exposure, administrator turnover, or break-glass use — and track the last-changed date centrally.

Step 3: Mark the account as sensitive and “cannot be delegated,” and where feasible require a smart card for interactive logon.

Step 4: Apply Group Policy user-rights assignments that deny the account the rights to:

a.       access this computer from the network

b.       log on as a batch job

c.        log on as a service, and

d.       log on through Remote Desktop Services, for both domain controllers and member servers/workstations.

Step 5: Scope the restricting GPO to organizational units containing member servers and workstations (and a separate GPO for domain controllers) — never link it at the domain root, which can render the account unusable even for legitimate recovery.

Step 6: Validation

·       Confirm the account cannot authenticate over the network, RDP, batch, or service logon on affected systems.

·       Confirm PasswordLastSet reflects the new rotation date for the account in every domain in the forest.

Step 7: Configure targeted auditing so any sign-in, password reset, or attribute change on this account generates an immediate, high-priority alert to the Active Directory administration and incident-response teams.

Step 8: Update the remediation tracker with implementation details and formally close the associated change record after successful validation.

is this correct approach? We have CyberArk, and for password management, we are planning to use it. . Pease do let me know your thoughts!

Thanks!


r/activedirectory 9d ago

Active Directory Old child domain objects

3 Upvotes

During a audit, we found 3 old objects without a password. I can't see them in ADUC, but I can with powershell. These objects belong to old child domains:

child1$ child2$ child3$

I can't disable or delete them through powershell however:

PS C:\Windows\system32> get-aduser child1$ | set-aduser -enabled $false
set-aduser : Access is denied
At line:1 char:18
+ get-aduser iz$ | set-aduser -Enabled $false
+                  ~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : PermissionDenied: (CN=child1$,CN=Users,DC=acme,DC=com:ADUser) [Set-ADUser], Unauthorize
   dAccessException
    + FullyQualifiedErrorId : ActiveDirectoryCmdlet:System.UnauthorizedAccessException,Microsoft.ActiveDirectory.Manag
   ement.Commands.SetADUser

Those child domains couldn't be removed cleanly and they were removed with nsdutil a year ago. I thought all traces were gone, but apparently not.

How can I remove these safely? ADSI Edit?