Bob's Identity & Access Blog

The Active Directory Identity Management Blog

ADLab Learn more

Create an Active Directory Test Lab

There are two primary methods used by administrators to implement Dev/Test environments to protect Active Directory from errors while they try out administrative changes. There are numerous options for creating an Active Directory test lab. The first method is to clone the directory and the second is to recreate the directory. Each has benefits and drawbacks that should be considered … Rm

BobBobel.Photo3 Learn more

Why join my site?

There are a lot of reasons to join my site. Over the next several weeks I will be presenting more content and give you valuable information on Identity & Access Management. Join now and you will get several free benefits. » Email Updates » Free content » Suggestions for webinars & events you may be interested in attending » Show your … Rm

Directions Learn more

Active Directory compromised?

Now What????    Whitepaper: Re-constituting Active Directory after a critical compromise or detection of an Advanced Persistent Threat  Microsoft’s Active Directory (AD) provides a secure and stable directory service on which many organizations depend to provide user authentication and authorization.  Because AD represents the preverbal keys to the kingdom it typically receives the appropriate level of care and feeding required maintaining … Rm

By BoLOHLONE payday loans

Blog

Dell added Data classification for unstructured data to Quest One. This is the same feature Microsoft added to Windows Server 2012 last year – that takes guts or stupidity. I’m guessing the later. http://www.net-security.org/secworld.php?id=15027  

In my May 2012 post, Your AD was compromised, now what? I first described using a pre-staged migration as the only viable method of recovery from an Advanced Persistent threat compromise. I was thrilled to see that Microsoft has followed this approach and released a best practices guide detailing how to recover from APT using a my “lifeboat” migration scenario. … Rm

This topic of the Windows Credential Editor came up again recently  The use of Windows Credential Editor an attack that compromised a fairly large Active Directory deployment resulting in me writing the whitepaper entitled  ”Active Directory was compromised, now what?” whitepaper. I ask that you register on my blog, but it is worth it. This makes a good argument for Kerberos over NTLM … Rm

If you need a list of what to know about getting started with Active Directory then this is a page for you. It isn’t new, but it has a lot of really excellent content. Read the Microsoft Technet blog article here.    

I had the opportunity to speak with Dominic Vogel at TechRepublic a week or so ago. The conversation was about the work we are doing at NetWrix and how change and configuration auditing can have a huge impact on GRC & S (Governance, Risk, Compliance & Security). http://www.techrepublic.com/blog/security/governance-risk-and-compliance-change-auditing-and-security/8865

The BeyondTrust stable of products is starting to look a lot like those offered by the Windows Group at Quest Software (now Dell). On December 12th, BeyondTrust announced they  acquisition of BlackBird Group a German owned Auditing and Compliance company. The move to assemble these types of Infrastructure products is very smart because as it begins to align BeyondTrust with their … Rm

http://blog.netwrix.com/2012/11/23/netwrix-wins-six-2012-community-choice-and-editors-best-awards-from-windows-it-pro-magazine/

NetWrix Group Policy Change Reporter was selected the winner in the Group Policy Management category of the WindowSecurity.com Readers’ Choice Awards. NetWrix Group Policy Change Reporter is built on the NetWrix next generation auditing platform. Congratulations NetWrix. Anyone who is interested, there is a Free Trial that will let you check out the technology. Congratulations also to my friends at … Rm

I ran across an interesting scenario the other day at work. I was going through the AD event log for some details on a change that I made to the security settings for a group hoping to find the value before I made the change. I thought the improved AD Domain Services logging would help me by showing the before … Rm

Microsoft has announced the timing of the Windows Server 2012 now set to release in September. http://blogs.technet.com/b/windowsserver/archive/2012/07/09/windows-server-2012-final-release-timing.aspx

News

Free Techincal Briefs

document_downWhen you join you can are able to browse and download tech briefs about Active Directory and related topics. These white papers are efficiently written and get to the point so you don’t waste time on marketing pitches or non-essential material.

Events

News & Events

2013 – Febuary, Interview with Help Net Security: IT complexity and change auditing
http://www.net-security.org/article.php?id=1811

2013 – January, Interview with TechRepublic on GRC: Change Auditing & Security
http://www.techrepublic.com/blog/security/governance-risk-and-compliance-change-auditing-and-security/8865

2011 – August, Presentation U.S. Airforce Security Conference HSPD-12 and the impact on logical access control. http://www.bobbobel.com/smart-card-presentation-at-the-afitc/

2010 – January, Interview with Enterprise Systems Journal about Attestation http://esj.com/articles/2010/01/19/attestation.aspx

2010 – January 27th, 11am (EST). Achieve Access Accountability and Sustained Compliance with ActiveRoles Server Sign up at http://www.quest.com/events/ListDetails.aspx?ContentID=10866

2009 – October, Northeastern ActiveRoles Server User Group, Boston

2009 – September 16th, EMEA ActiveRoles Server User Group, Berlin Hilton http://www.bobbobel.com/sign-up-now-for-the-activeroles-server-user-group-at-tec-berlin/

2009 – August, Randy Franklin Smith Webcast:Using Active Directory’s Delegation of Control and Auditing to Streamline Security Administration http://www.ultimatewindowssecurity.com/webinars/register.aspx?id=65&source=quest

2009 – May, Randy Franklin Smith Webcast: Access and Provisioning Challenges – Addressing the 8 Worst Areas for Risk and Cost During this webcast, Randy will discuss and demonstrates challenges that threaten AD efficiency and security and then Bob demonstrated how these could be resolved using ActiveRoles Server. http://www.quest.com/events/ListDetails.aspx?ContentID=9676

2009 – May, PowerScripting Podcast with Bob http://powerscripting.wordpress.com/2009/04/20/episode-67-bob-bobel-from-quest-software/

2009 – May, Provisioning Web Cast http://www.quest.com/events/listdetails.aspx?contentid=9514&searchoff=true&technology=&prod=183&prodfamily=&loc=

2009 – Feb, My interview in Enterprise Systems Journal http://esj.com/articles/2009/02/10/qa-best-practices-for-access-management.aspx

http://www.softwaremag.com/focus-areas/business-of-it/product-coverage/quests-activeroles-server-enhanced-with-workflow-access-accountability/

2007 – Whitepaper, Change Management: Path to a Secure, Efficient and Risk-Free Active Directory http://www.quest.com/documents/landing.aspx?id=6175&technology=5&prod=&prodfamily=&loc=

Join

Why Join

Free AccountA free account includes:

» Email Updates
» Free content
» Download white papers and case studies
» Suggestions for webinars & events you may be interested in attending
» Show your icon and a user name when you comment

Join now – it only takes a few moments!