NTLMv1 Single Sign On Gets Blocked by Default in October 2026: How to Audit BlockNtlmv1SSO Now Microsoft has said that in October 2026 the default for a new NTLM setting flips from “audit only” to “block”.... Sep 26, 2026 6 min read Active Directory
BadSuccessor After the Patch: What Windows Server 2025 dMSA Privilege Escalation Still Gets You BadSuccessor, the delegated Managed Service Account (dMSA) privilege escalation technique in Windows Server 2025 Active Directory, is often still described... Sep 25, 2026 6 min read Active Directory
CVE-2026-72982: Critical Unauthenticated Netlogon RCE Puts Every Unpatched Domain Controller at Risk CVE-2026-72982, patched in Microsoft’s September 2026 security release, is a critical, unauthenticated remote code execution flaw in the Windows Netlogon... Sep 24, 2026 5 min read Active Directory / Security
Certighost (CVE-2026-54121): A Public Exploit Now Exists for This AD CS Domain Controller Impersonation Flaw A public proof-of-concept exploit is now available for CVE-2026-54121, nicknamed “Certighost,” a critical Active Directory Certificate Services vulnerability that lets... Sep 23, 2026 5 min read Active Directory / Security
Kerberoasting in 2026: What CVE-2026-20833 and RC4 Disablement Actually Change for Active Directory If any service accounts in your Active Directory environment are still relying on RC4 for Kerberos ticket encryption, Microsoft’s phased... Sep 18, 2026 5 min read Active Directory / Security
Microsoft Entra Conditional Access Custom Controls Are Retiring: Migrating to External MFA Before September 30, 2026 Microsoft is retiring Custom Controls in Microsoft Entra Conditional Access. Creating new Custom Controls or editing existing ones stops working... Sep 16, 2026 5 min read Active Directory / Azure / Security
September 2026 Patch Tuesday: What Windows Server, Active Directory, and Exchange Admins Need to Patch Right Now Microsoft’s September 2026 Patch Tuesday is the largest release in the program’s history: 974 CVEs addressed in a single month,... Sep 15, 2026 6 min read Active Directory / Exchange / Security
Tracing a Domain Compromise: Key Active Directory Logs and Indicators of Compromise to Check First Golden Ticket and DCSync indicators, GPO tampering, AdminSDHolder ACL abuse, SID History injection, and domain controller logon anomalies to check first when AD itself is suspected of compromise. Sep 6, 2026 4 min read Active Directory / Security
Migrating Microsoft AD Users Between different Domains with Minimal Data Loss Microsoft’s primary native tool for migrating Active Directory (AD) users between domains remains the Active Directory Migration Tool (ADMT) version... Dec 14, 2025 3 min read Active Directory / Microsoft / Windows Server
Entra ID Connect Health and Troubleshooting Synchronization Error Synchronization is the backbone of any hybrid identity environment. When your on-premises Active Directory (AD) data isn’t flowing correctly to... Dec 14, 2025 7 min read Active Directory / Microsoft / Windows Server