NTLMv1 Single Sign On Gets Blocked by Default in October 2026: How to Audit BlockNtlmv1SSO Now Microsoft has said that in October 2026 the default for a new NTLM setting flips from “audit only” to “block”.... Sep 26, 2026 6 min read Active Directory
BadSuccessor After the Patch: What Windows Server 2025 dMSA Privilege Escalation Still Gets You BadSuccessor, the delegated Managed Service Account (dMSA) privilege escalation technique in Windows Server 2025 Active Directory, is often still described... Sep 25, 2026 6 min read Active Directory
September 2026 Patch Tuesday: What Windows Server, Active Directory, and Exchange Admins Need to Patch Right Now Microsoft’s September 2026 Patch Tuesday is the largest release in the program’s history: 974 CVEs addressed in a single month,... Sep 15, 2026 6 min read Active Directory / Exchange / Security
Tracing a Domain Compromise: Key Active Directory Logs and Indicators of Compromise to Check First Golden Ticket and DCSync indicators, GPO tampering, AdminSDHolder ACL abuse, SID History injection, and domain controller logon anomalies to check first when AD itself is suspected of compromise. Sep 6, 2026 4 min read Active Directory / Security