Active Directory Security Drift: How Identity Sprawl and Misconfiguration Create Invisible Risk

Active Directory Security Drift: How Identity Sprawl and Misconfiguration Create Invisible Risk

(00:00:00) Unconstrained Delegation and the Furnace
(00:00:03) The Unconstrained Delegation Furnace
(00:07:08) The Golden Ticket Attack
(00:09:04) Krbtgt Rotation Rituals
(00:13:07) The Backup Service Account Privilege
(00:20:21) Local Administrator Reuse
(00:27:19) SMB Signing and NTLM Relay
(00:41:31) Group Policy Preferences and Passwords
(00:48:15) Two-Way Forest Trust
(00:48:49) The Intruder's Journey

In Part 2 of this m365.fm series, Mirko Peters goes deeper into the gravitational pull of Active Directory and how unchecked identity sprawl, legacy design, and operational shortcuts quietly turn it into a black hole for security. Most organizations treat AD as stable infrastructure — accounts are created, groups are added, permissions are granted, and life moves on. But every exception, every “temporary” permission, and every legacy service account adds weight. This episode is about what happens when that weight turns into security drift: slow, invisible, and accelerating until something breaks in production or during an incident.

WHY IDENTITY SYSTEMS NATURALLY DRIFT TOWARD INSECURITY

The assumption in many enterprises is that if access is reviewed occasionally and audits pass, identity is under control. It is not. Identity systems like Active Directory are constantly changing: projects launch, teams reorganize, mergers happen, vendors come and go. Each change adds new groups, roles, and permissions that rarely get cleaned up. Over time, privilege creep turns once-reasonable access models into sprawling risk surfaces. Security does not usually fail in a single moment. It decays slowly as accumulated decisions, shortcuts, and exceptions widen the blast radius of every future compromise.

HOW SECURITY DRIFT ACCELERATES INSIDE ACTIVE DIRECTORY

This episode breaks down how security drift accelerates over time: from harmless-seeming group nesting to orphaned service accounts with excessive privileges, from one-off troubleshooting changes that never get rolled back to “temporary” access that quietly becomes permanent. Mirko walks through how misconfiguration at scale creates attack paths that defenders cannot see in traditional tools, why standard audits rarely catch identity-based exposure, and how lateral movement becomes easy once drift has taken hold. Instead of treating each issue as a one-off fix, identity security is reframed as a physics problem — governed by gravity, inertia, and entropy.

WHAT YOU WILL LEARN
  • Why identity systems like Active Directory naturally drift toward insecurity over time.
  • How permissions, groups, and service accounts silently accumulate risk as environments grow.
  • The real-world impact of misconfiguration at scale on incident response and breach paths.
  • How attack paths form and persist inside complex AD environments.
  • Why traditional audits and point-in-time reviews miss identity-based threats.
  • What it takes to reverse security drift instead of just slowing it down for the next audit cycle.
KEY THEMES AND TOPICS
  • Privilege creep, access entropy, and how “just this once” changes become permanent.
  • Service account abuse, automation risk, and hidden high-privilege identities.
  • Lateral movement through identity systems and the paths attackers actually use.
  • Delegation risks, inheritance failures, and the illusion of least privilege.
  • Detection gaps in identity security and why visibility is often an illusion.
  • How to think about Active Directory as critical infrastructure, not just directory plumbing.
WHO THIS EPISODE IS FOR
  • Blue Team and SOC analysts who need to understand identity-driven attack paths.
  • Identity and Access Management (IAM) engineers responsible for AD hygiene and design.
  • Active Directory administrators maintaining complex, multi-forest or legacy-heavy environments.
  • Security architects designing modern defenses on top of old identity foundations.
  • CISOs and risk leaders who need language to explain “invisible” identity risk to the business.
ABOUT THE HOST

Mirko Peters is a Microsoft 365 expert, architect, and host of m365.fm. He works with organizations from small businesses to large enterprises on Microsoft 365 architecture, security, AI integration, governance design, and system architecture. His work focuses on designing context-driven systems that reduce complexity, enable autonomous execution, and create scalable performance across modern enterprises.

Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(863)

The Copilot Credit Trap- Why Your AI Economy is Already Broken

The Copilot Credit Trap- Why Your AI Economy is Already Broken

For decades, enterprise software followed a predictable financial model. Organizations purchased licenses, assigned them to users, and budgeted annual IT spending with confidence. AI changes that comp...

26 Jul 0s

The End of AI Bloat: Why Modern Agents Need Skills

The End of AI Bloat: Why Modern Agents Need Skills

Many AI agents start out fast, responsive, and surprisingly intelligent. But after a few months of real-world use, something changes. Response times increase, costs rise, prompts become enormous, and ...

26 Jul 0s

THE DEATH OF THE PROXY: Architecting Dataverse for the Agent Fabric

THE DEATH OF THE PROXY: Architecting Dataverse for the Agent Fabric

For years, Microsoft's recommended architecture for connecting AI assistants like Claude Desktop to Dataverse relied on a local STDIO proxy. It was simple, easy to install, and perfectly suited for in...

26 Jul 0s

The Death of the Pipeline: Why AI Agents are Replacing Traditional

The Death of the Pipeline: Why AI Agents are Replacing Traditional

For more than two decades, CI/CD pipelines have been the backbone of modern software delivery. Developers commit code, automated builds run, tests execute, security scans complete, someone approves th...

25 Jul 0s

The Productivity Illusion: Why AI is Breaking Your Engineering KPIs

The Productivity Illusion: Why AI is Breaking Your Engineering KPIs

At first glance, the numbers look incredible. Deployment frequency is increasing, pull requests are being merged faster than ever, AI is generating more code, and engineering teams appear dramatically...

25 Jul 0s

The DevOps Tax: Why Your Platform is Failing

The DevOps Tax: Why Your Platform is Failing

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring The DevOps Tax—the hidden cost that silently reduces engineering productivity, increases cognitive overload, an...

25 Jul 0s

Microsoft Purview Insider Risk Management - Simply Explained

Microsoft Purview Insider Risk Management - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Purview Insider Risk Management, Microsoft's intelligent solution for identifying risky user behavior...

24 Jul 0s

Microsoft Purview Information Protection - Simply Explained

Microsoft Purview Information Protection - Simply Explained

Welcome to another episode of Knowledge Nuggets with Mirko Peters. Today we're exploring Microsoft Purview Information Protection, the foundation of Microsoft's data classification and protection stra...

24 Jul 0s

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
popradet
fotballpodden-2
stopp-verden
rss-gukild-johaug
aftenpodden-usa
hanna-de-heldige
dine-penger-pengeradet
rss-ness
aftenbla-bla
det-store-bildet
lydartikler-fra-aftenposten
nokon-ma-ga
unitedno
e24-podden
rss-penger-polser-og-politikk
bt-dokumentar-2
oppdatert