<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Bob&#039;s Identity &#38; Access Blog</title>
	<atom:link href="http://www.bobbobel.com/feed" rel="self" type="application/rss+xml" />
	<link>http://www.bobbobel.com</link>
	<description>The Active Directory Identity Management Blog</description>
	<lastBuildDate>Mon, 10 Jun 2013 17:59:16 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Dell Competes Head-to-Head with Microsoft</title>
		<link>http://www.bobbobel.com/dell-head-to-head-with-microsoft</link>
		<comments>http://www.bobbobel.com/dell-head-to-head-with-microsoft#comments</comments>
		<pubDate>Mon, 10 Jun 2013 17:58:15 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Data Classification]]></category>
		<category><![CDATA[Microsoft Dell Compete]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1701</guid>
		<description><![CDATA[Dell added Data classification for unstructured data to Quest One. This is the same feature Microsoft added to Windows Server 2012 last year &#8211; that takes guts or stupidity. I&#8217;m guessing the later. http://www.net-security.org/secworld.php?id=15027 &#160;]]></description>
				<content:encoded><![CDATA[<p>Dell added Data classification for unstructured data to Quest One. This is the same feature Microsoft added to Windows Server 2012 last year &#8211; that takes guts or stupidity. I&#8217;m guessing the later.</p>
<p>http://www.net-security.org/secworld.php?id=15027</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/dell-head-to-head-with-microsoft/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Best Practice for a Migration after APT</title>
		<link>http://www.bobbobel.com/microsoft-best-practice-for-a-migration-after-apt</link>
		<comments>http://www.bobbobel.com/microsoft-best-practice-for-a-migration-after-apt#comments</comments>
		<pubDate>Wed, 05 Jun 2013 16:35:19 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[AD Compromised]]></category>
		<category><![CDATA[AD Experts Help]]></category>
		<category><![CDATA[AD HACK]]></category>
		<category><![CDATA[Advanced Persistant Threat]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1696</guid>
		<description><![CDATA[In my May 2012 post, Your AD was compromised, now what? I first described using a pre-staged migration as the only viable method of recovery from an Advanced Persistent threat compromise. I was thrilled to see that Microsoft has followed this approach and released a best practices guide detailing how to recover from APT using a my “lifeboat” migration scenario. &#8230; <a class="rm" href="http://www.bobbobel.com/microsoft-best-practice-for-a-migration-after-apt">Rm </a>]]></description>
				<content:encoded><![CDATA[<p>In my May 2012 post, <a href="http://www.bobbobel.com/active-directory-was-compromised-now-what">Your AD was compromised, now what?</a> I first described using a pre-staged migration as the only viable method of recovery from an Advanced Persistent threat compromise.</p>
<p>I was thrilled to see that Microsoft has followed this approach and released a best practices guide detailing how to recover from APT using a my “lifeboat” migration scenario.</p>
<p>This is a <a href="http://blogs.technet.com/b/security/archive/2013/06/03/microsoft-releases-new-mitigation-guidance-for-active-directory.aspx">This Microsoft Best Practice is a MUST READ FOR EVERY AD OWNER</a> I consider this the only ture insurance policy against a deep AD compromise.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/microsoft-best-practice-for-a-migration-after-apt/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows Credential Editor</title>
		<link>http://www.bobbobel.com/windows-credential-editor</link>
		<comments>http://www.bobbobel.com/windows-credential-editor#comments</comments>
		<pubDate>Mon, 20 May 2013 02:05:53 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Access]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Active Directory Security]]></category>
		<category><![CDATA[Free AD Tools]]></category>
		<category><![CDATA[Windows Admin Password]]></category>
		<category><![CDATA[Windows Credential Editor]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1675</guid>
		<description><![CDATA[This topic of the Windows Credential Editor came up again recently  The use of Windows Credential Editor an attack that compromised a fairly large Active Directory deployment resulting in me writing the whitepaper entitled  &#8221;Active Directory was compromised, now what?&#8221; whitepaper. I ask that you register on my blog, but it is worth it. This makes a good argument for Kerberos over NTLM &#8230; <a class="rm" href="http://www.bobbobel.com/windows-credential-editor">Rm </a>]]></description>
				<content:encoded><![CDATA[<p>This topic of the Windows Credential Editor came up again recently  The use of Windows Credential Editor an attack that compromised a fairly large Active Directory deployment resulting in me writing the whitepaper entitled  &#8221;<a href="http://www.bobbobel.com/active-directory-was-compromised-now-what">Active Directory was compromised, now what?</a>&#8221; whitepaper. I ask that you register on my blog, but it is worth it.</p>
<p>This makes a good argument for Kerberos over NTLM for Windows Networks. If you don&#8217;t <a href="http://en.wikipedia.org/wiki/Pass_the_hash" target="_blank">Windows Credential Editor</a> may make you wish you had turned NTLM off.</p>
<p>Microsoft provides some security guidance on the subject in kb article <a href="http://support.microsoft.com/kb/2793313" target="_blank">2793313</a>.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/windows-credential-editor/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Everything Active Directory page</title>
		<link>http://www.bobbobel.com/the-everything-active-directory-page</link>
		<comments>http://www.bobbobel.com/the-everything-active-directory-page#comments</comments>
		<pubDate>Thu, 16 May 2013 15:24:40 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1671</guid>
		<description><![CDATA[If you need a list of what to know about getting started with Active Directory then this is a page for you. It isn&#8217;t new, but it has a lot of really excellent content. Read the Microsoft Technet blog article here. &#160; &#160;]]></description>
				<content:encoded><![CDATA[<p>If you need a list of what to know about getting started with Active Directory then this is a page for you. It isn&#8217;t new, but it has a lot of really excellent content.</p>
<p><a href="http://blogs.technet.com/b/ashleymcglone/archive/2012/01/03/everything-you-need-to-get-started-with-active-directory.aspx" target="_blank">Read the Microsoft Technet blog article here.</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/the-everything-active-directory-page/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Create an Active Directory Test Lab and Development Environment</title>
		<link>http://www.bobbobel.com/creating-an-active-directory-test-and-development-environment</link>
		<comments>http://www.bobbobel.com/creating-an-active-directory-test-and-development-environment#comments</comments>
		<pubDate>Sun, 17 Feb 2013 18:39:14 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Active Directory Help]]></category>
		<category><![CDATA[Active Directory test lab]]></category>
		<category><![CDATA[Active Directory Testing]]></category>
		<category><![CDATA[Active Directory Tools]]></category>
		<category><![CDATA[Clone Active Directory]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1595</guid>
		<description><![CDATA[There are two primary methods used by administrators to implement Dev/Test environments to protect Active Directory from errors while they try out administrative changes. There are numerous options for creating an Active Directory test lab. The first method is to clone the directory and the second is to recreate the directory. Each has benefits and drawbacks that should be considered &#8230; <a class="rm" href="http://www.bobbobel.com/creating-an-active-directory-test-and-development-environment">Rm </a>]]></description>
				<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://www.bobbobel.com/white-papers"><img class="alignnone size-medium wp-image-1630" alt="Download whitepaper" src="http://www.bobbobel.com/wp-content/uploads/2013/02/Download-whitepaper-300x80.png" width="300" height="80" /></a></p>
<p>There are two primary methods used by administrators to implement Dev/Test environments to protect Active Directory from errors while they try out administrative changes. There are numerous options for creating an Active Directory test lab. The first method is to <b>clone</b> the directory and the second is to <b>recreate</b> the directory. Each has benefits and drawbacks that should be considered before choosing the method that meets your organizations requirements. Cloning keeps all object Security IDs (SIDs) identical to the production while Recreating will new SIDs for the objects. Both methods should keep the object names the same and that is typically the important part. Cloning may be seen by some as a security problem as well since you end up with a duplicate Active Directory with password hashes intact. I prefer Recreation of the directory because it is simpler, safer, more secure and can be extended to pull additional changes from production into test.</p>
<p><span style="color: #000080;"><strong>Cloning</strong></span></p>
<p>Cloning is more accurate yet the more difficult of the two methods. Cloning is a one-time event the result of which must forever be disconnected from you production environment so that there is no chance of improper replication. There are two general ways people clone Active Directory. Both methods will require you implement changes to Active Directory such as seizing FISMO roles and potentially re-implementing services such as DNS, but with a lot of work it can be done. The result of cloning is that you very accurate clone of AD at that moment in time.</p>
<p style="padding-left: 30px;"><span style="color: #000080;">Option 1</span>: Create a backup of an active directory domain controller then restore that backup new computer (VM or Physical Host) on a disconnected or sandboxed network. This method can get messy because of the restored OS will detect the hardware changed and you will need to repair the OS. In addition to fixing the OS you will need to update AD by seizing the FISMO roles with NTDSUTIL as well as configure a new DNS to work with this new environment.</p>
<p style="padding-left: 30px;"><span style="color: #000080;">Option 2:</span> Create a computer on the production network (VM or Physical Host) and promote it to a domain controller. After it fully replicates, move the domain controller to a completely isolated network so that it has no chance of replicating with the source directory.</p>
<p><strong><span style="color: #000080;">Recreation</span></strong></p>
<p>Recreating is less accurate it is vastly simpler and safer. Recreated directories are usually&#8230; just as useful as a cloned directory and there is no fear of accidental replication back into production.</p>
<p style="padding-left: 30px;"><span style="color: #000080;">Option 1:</span> Setup a new Windows Server (VM or physical host) and install DNS and Active Directory; this will be the home of your dev/test directory. When you configure AD choose a domain name that is similar, but not the same as your production domain. For example, if my domain name is bobbobel.com, make the test environment domain name bobbobel.devtest. On a domain controller your existing production directory use either the LDIFDE or CSVDE utilities to export the data in Active Directory. (<a href="http://technet.microsoft.com/en-us/library/cc787549(v=ws.10).aspx" target="_blank">Technet article on using CSVDE</a>) I prefer CSVDE because the resulting file can be opened and modified in Microsoft Excel allowing you to find/replace names. Using LDIFDE or CSVDE import the file into your new domain.</p>
<p style="padding-left: 30px;"><span style="color: #000080;">Option 2:</span> Writing a PowerShell script that copies the most important objects from production to a dev/test environment is actually very simple. In this case you create a new host with a new dev/test domain as you would with option 1, but instead of using LDIFDE or CSVDE you write a PowerShell script that will copy the OU structure, user objects, group objects, group memberships etc… until you have enough detail to meet your  requirements. I like this approach, because the scripting that is required is typically one or two lines per object type and examples are easily found on the Internet. I also like this option because you get ultimate control over what you copy into dev/test and you delete your dev/test objects and re-run the scripts to get an up-to-date picture of your current production environment.</p>
<p>Having used both cloning and recreating, I have rarely run into a situation where re-creating the directory did not meet my requirements. For dev/test I almost never need the SIDs or passwords to be identical to production and I never enjoy dealing with FISMO role transfers or repairing the OS. So in my mind I would always choose re-creating the directory using PowerShell until I ran into some situation that would force me to consider cloning.</p>
<p style="text-align: center;"><img class="aligncenter" alt="Download whitepaper" src="http://www.bobbobel.com/wp-content/uploads/2013/02/Download-whitepaper-300x80.png" width="300" height="80" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/creating-an-active-directory-test-and-development-environment/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why join my site?</title>
		<link>http://www.bobbobel.com/why-join-now</link>
		<comments>http://www.bobbobel.com/why-join-now#comments</comments>
		<pubDate>Wed, 30 Jan 2013 02:50:43 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Bob Bobel]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1509</guid>
		<description><![CDATA[There are a lot of reasons to join my site. Over the next several weeks I will be presenting more content and give you valuable information on Identity &#38; Access Management. Join now and you will get several free benefits. » Email Updates » Free content » Suggestions for webinars &#38; events you may be interested in attending » Show your &#8230; <a class="rm" href="http://www.bobbobel.com/why-join-now">Rm </a>]]></description>
				<content:encoded><![CDATA[<p>There are a lot of reasons to join my site. Over the next several weeks I will be presenting more content and give you valuable information on Identity &amp; Access Management. Join now and you will get several free benefits.</p>
<p>» Email Updates<br />
» Free content<br />
» Suggestions for webinars &amp; events you may be interested in attending<br />
» Show your icon and a user name when you comment</p>
<p><strong>Join now &#8211; it only takes a few moments!</strong></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/why-join-now/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>TechRepublic Interview GRC &amp; S</title>
		<link>http://www.bobbobel.com/techrepublic-interview-grc-s</link>
		<comments>http://www.bobbobel.com/techrepublic-interview-grc-s#comments</comments>
		<pubDate>Tue, 15 Jan 2013 10:34:21 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Bobel]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1440</guid>
		<description><![CDATA[I had the opportunity to speak with Dominic Vogel at TechRepublic a week or so ago. The conversation was about the work we are doing at NetWrix and how change and configuration auditing can have a huge impact on GRC &#38; S (Governance, Risk, Compliance &#38; Security). http://www.techrepublic.com/blog/security/governance-risk-and-compliance-change-auditing-and-security/8865]]></description>
				<content:encoded><![CDATA[<p>I had the opportunity to speak with Dominic Vogel at TechRepublic a week or so ago. The conversation was about the work we are doing at NetWrix and how change and configuration auditing can have a huge impact on GRC &amp; S (Governance, Risk, Compliance &amp; Security).</p>
<p>http://www.techrepublic.com/blog/security/governance-risk-and-compliance-change-auditing-and-security/8865</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/techrepublic-interview-grc-s/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BeyondTrust buys Blackbird Group</title>
		<link>http://www.bobbobel.com/1432</link>
		<comments>http://www.bobbobel.com/1432#comments</comments>
		<pubDate>Tue, 15 Jan 2013 10:25:21 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[BeyondTrust buys Blackbird Group]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1432</guid>
		<description><![CDATA[The BeyondTrust stable of products is starting to look a lot like those offered by the Windows Group at Quest Software (now Dell). On December 12th, BeyondTrust announced they  acquisition of BlackBird Group a German owned Auditing and Compliance company. The move to assemble these types of Infrastructure products is very smart because as it begins to align BeyondTrust with their &#8230; <a class="rm" href="http://www.bobbobel.com/1432">Rm </a>]]></description>
				<content:encoded><![CDATA[<p>The BeyondTrust stable of products is starting to look a lot like those offered by the Windows Group at Quest Software (now Dell). On December 12th, BeyondTrust announced they  acquisition of BlackBird Group a German owned Auditing and Compliance company. The move to assemble these types of Infrastructure products is very smart because as it begins to align BeyondTrust with their partners for replacing the Quest Tools with which the partners now compete.</p>
<p>This acquisition certainly helps the breadth of their offering, it will be interesting to see if they keep all of the Blackbird products. (For more information see <a href="http://www.beyondtrust.com/bb_acquisition/" target="_blank">http://www.beyondtrust.com/bb_acquisition/</a>)</p>
<p><a href="http://www.bobbobel.com/wp-content/uploads/2013/01/BeyondTrust_Buys_Blackbird-300x112.png"><img class="alignleft size-full wp-image-1438" title="BeyondTrust_Buys_Blackbird-300x112" src="http://www.bobbobel.com/wp-content/uploads/2013/01/BeyondTrust_Buys_Blackbird-300x112.png" alt="" width="300" height="112" /></a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/1432/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NetWrix WINS 6 Awards from Windows IT Pro Magazine</title>
		<link>http://www.bobbobel.com/netwrix-wins-6-awards-from-windows-it-pro-magazine</link>
		<comments>http://www.bobbobel.com/netwrix-wins-6-awards-from-windows-it-pro-magazine#comments</comments>
		<pubDate>Fri, 30 Nov 2012 22:51:32 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Bobel]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1283</guid>
		<description><![CDATA[http://blog.netwrix.com/2012/11/23/netwrix-wins-six-2012-community-choice-and-editors-best-awards-from-windows-it-pro-magazine/]]></description>
				<content:encoded><![CDATA[<p><a href="http://blog.netwrix.com/2012/11/23/netwrix-wins-six-2012-community-choice-and-editors-best-awards-from-windows-it-pro-magazine/">http://blog.netwrix.com/2012/11/23/netwrix-wins-six-2012-community-choice-and-editors-best-awards-from-windows-it-pro-magazine/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/netwrix-wins-6-awards-from-windows-it-pro-magazine/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NetWrix Group Policy Change Reporter #1 according to WindowsSecurity.com</title>
		<link>http://www.bobbobel.com/netwrix-group-policy-change-reporter-1-according-to-windowssecurity-com</link>
		<comments>http://www.bobbobel.com/netwrix-group-policy-change-reporter-1-according-to-windowssecurity-com#comments</comments>
		<pubDate>Thu, 26 Jul 2012 19:54:01 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Group Policy Change Reporting]]></category>
		<category><![CDATA[NetWrix beats EmpowerID]]></category>
		<category><![CDATA[NetWrix Beats SpecOps]]></category>
		<category><![CDATA[NetWrix Group Policy Change Reporter]]></category>
		<category><![CDATA[WindowsSecurity.com Reader's Choice Award Winner; Active Directory Help]]></category>

		<guid isPermaLink="false">http://www.bobbobel.com/?p=1227</guid>
		<description><![CDATA[NetWrix Group Policy Change Reporter was selected the winner in the Group Policy Management category of the WindowSecurity.com Readers&#8217; Choice Awards. NetWrix Group Policy Change Reporter is built on the NetWrix next generation auditing platform. Congratulations NetWrix. Anyone who is interested, there is a Free Trial that will let you check out the technology. Congratulations also to my friends at &#8230; <a class="rm" href="http://www.bobbobel.com/netwrix-group-policy-change-reporter-1-according-to-windowssecurity-com">Rm </a>]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.netwrix.com/group_policy_auditing_change_reporting_freeware.html" target="_blank">NetWrix Group Policy Change Reporter </a>was selected the winner in the Group Policy Management category of the <a href="http://blog.netwrix.com/2012/07/27/netwrix-wins-windowssecurity-com-readers-choice-award/" target="_blank">WindowSecurity.com Readers&#8217; Choice Awards</a>. NetWrix Group Policy Change Reporter is built on the NetWrix next generation auditing platform. Congratulations NetWrix. Anyone who is interested, there is a <a href="http://www.netwrix.com/sign_in.html?rf=requeste.html&amp;product=gpcr" target="_blank">Free Trial </a>that will let you check out the technology.</p>
<p><a href="http://www.bobbobel.com/wp-content/uploads/2012/07/WS_ReadersChoice_Winner_88x511188464514860.gif"><img class="aligncenter size-full wp-image-1230" title="WindowsSecurity.com Readers Choice Winner NetWrix" src="http://www.bobbobel.com/wp-content/uploads/2012/07/WS_ReadersChoice_Winner_88x511188464514860.gif" alt="" width="88" height="51" /></a></p>
<p>Congratulations also to my friends at The Dot Net Factory, Dell and Specops for a good showing. (Hey SpecOps is your tool really called &#8220;AD Janitor&#8221;?)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bobbobel.com/netwrix-group-policy-change-reporter-1-according-to-windowssecurity-com/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
