By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
IndebtaIndebta
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
9
Notification Show More
News
China snaps up mines around the world in rush to secure resources
58 minutes ago
News
Mining boss calls for price support to challenge China’s critical minerals dominance
2 hours ago
News
Big Food’s snack binge unravels as Americans ditch sweet treats
3 hours ago
News
It pays to be vulnerable — but please pick your moments
4 hours ago
News
Musk launches US political party to fight ‘one-party system’
5 hours ago
News
PwC lines up UK managing partner as new Middle East head
6 hours ago
News
Retail investors reap big gains from ‘buying the dip’ in US stocks
7 hours ago
Videos
How to pay off your student loans, (yes, you can do it)
10 hours ago
Videos
What Will Life On Mars Be Like?
11 hours ago
Aa
IndebtaIndebta
Aa
  • Banking
  • Credit Cards
  • Loans
  • Dept Management
  • Mortgage
  • Markets
  • Investing
  • Small Business
  • Videos
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
Follow US
Indebta > Small Business > Why AD Modernization Is Critical To Your Organization’s Cybersecurity
Small Business

Why AD Modernization Is Critical To Your Organization’s Cybersecurity

News Room
Last updated: 2023/10/20 at 9:40 AM
By News Room
Share
7 Min Read
SHARE

Co-founder of Semperis. Leads the company’s overall strategic vision and implementation.

Contents
AD Complexity Increases The Attack SurfaceThe Case For ModernizationAD Security And Migration ComplexitySteps To A Successful And Secure MigrationThe Time Is Now

In the highly distributed, cloud-based computing environments that are increasingly common today, threat actors primarily target identities to gain access to organizational resources. As such, Active Directory (AD) and Azure AD (now Entra ID) identity systems, used in more than 90% of enterprises worldwide, have become a major target for bad actors.

As the directory service for network users and resources, AD is tightly integrated into most organizations and is essential to all operations. A survey from my company reveals that 77% of business leaders (download required) and their security and IT ops teams would experience a severe or catastrophic impact if AD was down. Unfortunately, the original AD architecture in most organizations wasn’t built to handle cloud and modern infrastructures. As a leader in offering AD migration solutions, and considering AD’s position as a prime target for attackers, I’d like to share why AD modernization is critical to ensuring security in the modern enterprise.

AD Complexity Increases The Attack Surface

With the proliferation of cloud systems, the traditional idea of a network perimeter has effectively vanished. Most attack strategies focus on compromising identities via phishing and other means. Accordingly, security strategies increasingly focus on identity management and control.

Yet many of AD’s original security and architecture recommendations are inadequate to meet the needs of the modern enterprise. When AD was introduced with Windows Server 2000 at the tail end of the last millennium, networks were a different environment. The design of AD domains was heavily influenced by bandwidth limitations and NT replication concerns.

These constraints, combined with object limits and migration challenges from legacy Windows NT 4 domains, resulted in the adoption of multiple AD domains within the forest structure. These complicated designs, along with decades of configuration drift, have created complexities and misconfigurations that increase the AD attack surface.

The Case For Modernization

Modernizing AD can enable organizations to resolve decades’ worth of technical debt accrued by multi-forest environments and years of ineffective or outdated security practices. Modernization can enable teams to implement robust authorization controls for identity management and fully centralize control over their networks.

Modernization also reduces overall management costs by simplifying the environment and supporting compliance and regulatory demands.

AD Security And Migration Complexity

Despite the many advantages that modernization brings, organizations need to plan carefully when setting out to modify AD. The process can be a big effort with many challenges.

Users, groups, applications and computers must all be migrated into a new domain or forest. And any undetected vulnerabilities that exist in the old environment can be carried forward. The migration process can also introduce new vulnerabilities that might not be detected unless continuous monitoring and assessment are in place during the process.

It’s unlikely that everything will be moved at once. Migrating resources such as applications, file servers and databases is more complex than moving users and groups and so might temporarily stay behind in the old environment. Attackers love to take advantage of unsettled environments, so ensuring security during the transition period is paramount.

Steps To A Successful And Secure Migration

To manage an AD migration with minimal disruption, organizations need to take a security-first approach. That starts with a detailed migration plan that ensures that the destination domain is designed with security best practices in mind.

Best practices include assessing the environment before the migration, to identify gaps such as compromised accounts and vulnerable system misconfigurations, and creating a test environment that mirrors the production AD to test the migration process. You also must be sure that user permissions and access rights are moved in line with the overall policy, that passwords are synchronized, and that accounts, authentication protocols and encryption algorithms are compatible with the new environment.

Likewise, organizations need to apply the same precautions to the more complex tasks of migrating applications, resources and multitier architectures, which often require special configurations. And be sure to update hard-coded usernames, distinguished names and server names. If the destination AD environment uses different user or server names, users might not be authenticated or resources might be inaccessible.

Before activating the destination AD environment, it’s essential to test and validate to be sure the environment is working properly. Continuous monitoring—for unauthorized access, permission changes and anomalous behavior—is also vital once the migration is complete. Administrators should also conduct regular security audits and penetration testing.

Finally, implement training for end users, IT staff and management. And thoroughly document the new domain structure, user and group procedures, and all security policies.

The Time Is Now

Some organizations might balk at the complexity of modernizing AD, preferring to rely on existing security measures and AD’s own security features. However, those approaches are insufficient protection against current threats, which focus on compromising identities and exploiting the type of vulnerabilities that develop in AD over time. Securing AD via a thoroughly planned, well-executed modernization is essential to keeping both critical systems and their users secure in today’s environment.

Forbes Business Council is the foremost growth and networking organization for business owners and leaders. Do I qualify?

Read the full article here

News Room October 20, 2023 October 20, 2023
Share this Article
Facebook Twitter Copy Link Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Finance Weekly Newsletter

Join now for the latest news, tips, and analysis about personal finance, credit cards, dept management, and many more from our experts.
Join Now
China snaps up mines around the world in rush to secure resources

Stay informed with free updatesSimply sign up to the Mining myFT Digest…

Mining boss calls for price support to challenge China’s critical minerals dominance

Stay informed with free updatesSimply sign up to the Mining myFT Digest…

Big Food’s snack binge unravels as Americans ditch sweet treats

Big Food’s bet on America’s appetite for snacks is turning sour. Cookies, chocolate…

It pays to be vulnerable — but please pick your moments

Unlock the Editor’s Digest for freeRoula Khalaf, Editor of the FT, selects…

Musk launches US political party to fight ‘one-party system’

Unlock the White House Watch newsletter for freeYour guide to what Trump’s…

- Advertisement -
Ad imageAd image

You Might Also Like

Small Business

Brilliant Or Lucky? 4 Key Insights For Ventures & Angels

By News Room
Small Business

A Conversation With Agile Expert Harry Narang

By News Room
Small Business

College enrollment is down, Gen Z losing faith in a degree. Here is a better option.

By News Room
Small Business

The Digital Cyrano De Bergerac Of Modern Business

By News Room
Small Business

Why Do We Stay In A Job When We Are Not Happy? Insights To Help You Get The Career You Deserve

By News Room
Small Business

Making A Large Language Model Transparent, Compliant And Reliable

By News Room
Small Business

The Important Initiative For Real Digital Marketing Results

By News Room
Small Business

The Future Of Real Estate

By News Room
Facebook Twitter Pinterest Youtube Instagram
Company
  • Privacy Policy
  • Terms & Conditions
  • Press Release
  • Contact
  • Advertisement
More Info
  • Newsletter
  • Market Data
  • Credit Cards
  • Videos

Sign Up For Free

Subscribe to our newsletter and don't miss out on our programs, webinars and trainings.

I have read and agree to the terms & conditions
Join Community

2023 © Indepta.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?