Hybrid Identity is Broken: Rethinking AD, Entra ID & the Bridge in Between

Hybrid Identity is Broken: Rethinking AD, Entra ID & the Bridge in Between

Welcome to another episode of Guardians of the Directory, where we pull back the curtain on the real-world challenges in securing and managing Active Directory and hybrid identity environments. In this episode, Craig Birch is joined by Sander Berkouwer, identity veteran, Microsoft MVP, and author of the Active Directory Administration Cookbook, to have a brutally honest conversation about hybrid identity – and why it's more than just "messy"... it's broken.

💡 Key Takeaways:

  • Why Hybrid AD isn't just two directories, and how the real architecture adds a third (and sometimes fourth) layer of identity confusion.

  • What’s really going wrong with Entra Connect Sync, delegated permissions, PowerShell lifecycle issues, and administrative sprawl.

  • ADFS: still lingering, or finally on its way out? Why some orgs are stuck with legacy federation even today.

  • The harsh truth about identity governance: the promise of Entra ID Governance, and the licensing challenges that come with it.

  • What’s actually working for organizations today — and why baby-stepping IAM might be your smartest move yet.

  • The real impact of role sprawl, just-in-time access challenges, and why elevated rights still haunt hybrid AD deployments.

  • Fix or Fail: Craig and Sander rapid-fire common hybrid identity practices and decide what stays and what needs to go.

  • The one thing Sander would fix today if he could: a surprising insight into replication and its ripple effect on the hybrid identity stack.

🔧 Whether you're wrestling with federation headaches, struggling to consolidate IAM platforms, or just trying to get a handle on delegation and privilege creep, this episode lays out the problems — and a few practical ways forward.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(18)

Blueprinting Zero Trust From: Strategy to Execution with Jerry Chapman

Blueprinting Zero Trust From: Strategy to Execution with Jerry Chapman

Welcome back to Guardians of the Directory! In this episode, Craig Birch is joined once again by Zero Trust expert Jerry Chapman for a deep dive into the Zero Trust Blueprint—a practical model to help...

26 Juni 202530min

AdminSDHolder in Active Directory: Hidden Risks and Persistent Threats

AdminSDHolder in Active Directory: Hidden Risks and Persistent Threats

In this episode of Directory Insights in 10 Minutes, Craig Birch breaks down the often-misunderstood AdminSDHolder object in Active Directory and why it's a high-value target for attackers. Learn how ...

1 Maj 20256min

Admin Accounts with SPNs — Hidden Risk Behind Kerberoasting

Admin Accounts with SPNs — Hidden Risk Behind Kerberoasting

🔍 Admin Accounts with SPNs — Hidden Risk Behind Kerberoasting | Directory Insights in 10 MinutesIn this episode, Craig Birch breaks down a major Active Directory security blind spot: Kerberoasting vi...

15 Apr 20255min

Kerberos Pre-Auth: Hidden AD Risk

Kerberos Pre-Auth: Hidden AD Risk

In this episode of Directory Insights in 10 Minutes, Craig Birch breaks down one of the most overlooked Active Directory misconfigurations: the "Do not require Kerberos pre-authentication" setting.🔍 ...

9 Apr 20257min

Directory Insights in 10 Minutes: Remediating DES Encryption in Active Directory

Directory Insights in 10 Minutes: Remediating DES Encryption in Active Directory

Welcome to another episode of Directory Insights in 10 Minutes, powered by Guardians of the Directory. In this quick-hitting session, host Craig Birch walks through the process of identifying and reme...

1 Apr 20254min

Directory Insights in 10 Minutes Reversible Password Encryption – A Hidden Risk

Directory Insights in 10 Minutes Reversible Password Encryption – A Hidden Risk

Summary:In this episode of Directory Insights in 10 Minutes, we dive into a critical yet often overlooked Active Directory misconfiguration—Allowing Password Storage with Reversible Encryption.This se...

18 Mars 20254min

Directory Insights in 10 minutes: Password Not Required - The Hidden Risk

Directory Insights in 10 minutes: Password Not Required - The Hidden Risk

Episode OverviewIn this episode of Directory Insights in 10 Minutes, we’re exposing a dangerous yet overlooked Active Directory misconfiguration—PasswordNotRequired.Most AD admins assume password poli...

11 Mars 20255min

Populärt inom Teknik

uppgang-och-fall
market-makers
skogsforum-podcast
rss-uppgang-och-fall
rss-laddstationen-med-elbilen-i-sverige
rss-elektrikerpodden
rss-en-ai-till-kaffet
natets-morka-sida
 och-bilen-gar-bra
bli-saker-podden
rss-veckans-ai
under-femton
hej-bruksbil
elbilsveckan
developers-mer-an-bara-kod
bosse-bildoktorn-och-hasse-p
rss-fabriken-2
garagehang
klocksnack-tillsammans-med-nymans-ur-1851
bilar-med-sladd