Cyber resilience isn’t a single team’s job anymore. Learn about the roles a resilient organization actually needs assembled, long before the next crisis forces the point—and make your case for sending more than one person to the 2026 Hybrid Identity Protection Conference.
AI has changed the face of the attack surface. It has changed how attackers advance and how we defend systems. And it changes the way that Boards must think about the intersection of AI adoption, identity security, and recovery.
Resilience means you can recover your identity system in a trustworthy way to a level that restores critical business functions. When evaluating any identity resilience solution, demand that your vendor meet this list of non-negotiable requirements—and prove it.
There are plenty of questions on the internet regarding which software should be installed on a domain controller (DC). Which roles should be deployed? Which applications are required? To answer these questions, you must consider what a DC should do in the first place. Which Windows Server roles should you…
Cyber resilience isn’t a single team’s job anymore. Learn about the roles a resilient organization actually needs assembled, long before the next crisis forces the point—and make your case for sending more than one person to the 2026 Hybrid Identity Protection Conference.
AI has changed the face of the attack surface. It has changed how attackers advance and how we defend systems. And it changes the way that Boards must think about the intersection of AI adoption, identity security, and recovery.
Account Operators is an AD group that many people underestimate because it doesn’t contain the word “admins.” The problem is that it gives broad control over identities across the domain—and in Active Directory, identities are privilege. See how attackers use this group to move from “not quite privileged” to “I…
One of the most common misconfigurations I encounter in Active Directory environments is a LAN Manager authentication level set to 2 on domain controllers (DCs). If your reason for staying at level 2 is legacy application compatibility, you can move to level 3 today without breaking those applications.
Active Directory remains a critical infrastructure component for managing network resources, login credentials, and user authentication. Yet its centrality makes it a prime target for cyberattacks. One such evolving cyberattack is password spraying, a threat that’s gained in complexity in recent years. Password spraying attacks stand out due to their…
Cyber resilience isn’t a single team’s job anymore. Learn about the roles a resilient organization actually needs assembled, long before the next crisis forces the point—and make your case for sending more than one person to the 2026 Hybrid Identity Protection Conference.
AI has changed the face of the attack surface. It has changed how attackers advance and how we defend systems. And it changes the way that Boards must think about the intersection of AI adoption, identity security, and recovery.
Your business leaders are racing to adopt generative and agentic AI to move faster and unlock new efficiencies. As your business bets more on agents, it bets more on your identity fabric. Use this checklist to be sure you’re ready.
Microsoft is deprecating RC4 encryption beginning in April 2026. This post explains the process—and points you to resources that can help.
Dive into EntraGoat Scenario 3, where you’ll discover how individually legitimate Entra ID features, when combined with misconfigured group ownership, can cascade into a privilege escalation chain that elevates a low-level account into a tenant-wide threat.
Editor’s note This scenario is part of a series of examples demonstrating the use of EntraGoat, our Entra ID simulation environment. You can read an overview of EntraGoat and its value here. Certificate Bypass Authority–Root Access Granted EntraGoat Scenario 6 details a privilege escalation technique in Microsoft Entra ID where…
Cyber resilience isn’t a single team’s job anymore. Learn about the roles a resilient organization actually needs assembled, long before the next crisis forces the point—and make your case for sending more than one person to the 2026 Hybrid Identity Protection Conference.
AI has changed the face of the attack surface. It has changed how attackers advance and how we defend systems. And it changes the way that Boards must think about the intersection of AI adoption, identity security, and recovery.
Your business leaders are racing to adopt generative and agentic AI to move faster and unlock new efficiencies. As your business bets more on agents, it bets more on your identity fabric. Use this checklist to be sure you’re ready.
An Active Directory migration and consolidation project is not just a data move. If you carry over legacy delegation mistakes, group nesting, trust relationships, and overprivileged accounts, you simply recreate risky attack paths. Learn how a security-first approach helps you make your new AD environment more secure.
Enterprise organizations with legacy Active Directory (AD) environments have a security problem. Their AD infrastructure has likely degraded over time and now harbors multiple security vulnerabilities because of inefficient architecture, multiple misconfigurations, and poorly secured legacy applications. Yet Active Directory migration and consolidation, especially involving a sprawling AD infrastructure, is…
Active Directory (AD) migration projects can be challenging and complex. Such projects involve the migration of users, groups, computers, and applications from one AD domain or forest to another. Careful planning and execution can help your migration team complete a successful AD migration, with minimal disruption to end users and…
Being a CISO can feel like an unwinnable battle. CISOs today are called to help the business understand cyber risk, put in place controls appropriate to its risk appetite, and ensure that it can withstand or recover quickly from difficult conditions while continuing to deliver required business outcomes. And as…
The fastest way to turn a cyber incident into a business outage is through identity system compromise. Ransomware continues to exploit that fact—and the consequences are real. Here are practical, board-ready steps CISOs can take to boost resilience when those attacks happen.
My friends know I’m a movie buff. Being also a mixed martial enthusiast, one of my all-time favorites is Fight Club, based on Chuck Palahniuk’s first novel. The story is about an identity crisis: rebelling against consumerism, trying to find truth and meaning in life, and becoming a “real” person…
Cyber resilience isn’t a single team’s job anymore. Learn about the roles a resilient organization actually needs assembled, long before the next crisis forces the point—and make your case for sending more than one person to the 2026 Hybrid Identity Protection Conference.
AI has changed the face of the attack surface. It has changed how attackers advance and how we defend systems. And it changes the way that Boards must think about the intersection of AI adoption, identity security, and recovery.
Your business leaders are racing to adopt generative and agentic AI to move faster and unlock new efficiencies. As your business bets more on agents, it bets more on your identity fabric. Use this checklist to be sure you’re ready.
Here’s what you need to know about password guessing and how to protect Active Directory—and your organization.
The Group Policy Preferences feature provides a well-known pathway for cyber attackers to discover easily decoded passwords in Active Directory. Learn to spot and defend against this vulnerability.
Discover how certificate template misconfigurations in Active Directory Certificate Services (AD CS) enable ESC1 attacks—allowing cyber attackers to rapidly escalate privileges and potentially compromise entire networks.
Active Directory (AD) remains the crown jewel of enterprise infrastructure, and for threat actors, the holy grail is clear: gain Domain Admin privileges. This level of privilege effectively grants full control over your environment. Identity protection therefore plays an integral part in enterprise security, and organizations invest great efforts in…
AI agents aren’t just code running quietly in the background. They’re code with agency, wrapped in identity, carrying permissions, making decisions, and crossing boundaries on behalf of someone or something else. Learn how to avoid some simple but important misconfigurations as your organization begins adopting Agent ID at scale.
In the previous chapter of our guide to protecting agent identities, you learned about and practiced using Microsoft’s Agent Registry. In this Practice checkpoint, follow the steps to verify three agent identity authentication flows in Entra ID.
There are plenty of questions on the internet regarding which software should be installed on a domain controller (DC). Which roles should be deployed? Which applications are required? To answer these questions, you must consider what a DC should do in the first place. Which Windows Server roles should you…
Cyber resilience isn’t a single team’s job anymore. Learn about the roles a resilient organization actually needs assembled, long before the next crisis forces the point—and make your case for sending more than one person to the 2026 Hybrid Identity Protection Conference.
Your business leaders are racing to adopt generative and agentic AI to move faster and unlock new efficiencies. As your business bets more on agents, it bets more on your identity fabric. Use this checklist to be sure you’re ready.
Being a CISO can feel like an unwinnable battle. CISOs today are called to help the business understand cyber risk, put in place controls appropriate to its risk appetite, and ensure that it can withstand or recover quickly from difficult conditions while continuing to deliver required business outcomes. And as…
This month marked two milestones for Semperis. First, Deloitte recognized the company as one of the 100 fastest growing technology companies in North America and (for the third consecutive year) one of the top 10 fastest-growing tech companies in the greater New York area. Then, the company was listed for…
On behalf of the entire team, I’m excited to share that Semperis has been named to Inc.’s 2022 list of Best Workplaces. This annual list honors workplaces that are ranked highly by their employees on topics like benefits, trust in senior leadership, change management, and career development. I could not…
The fastest way to turn a cyber incident into a business outage is through identity system compromise. Ransomware continues to exploit that fact—and the consequences are real. Here are practical, board-ready steps CISOs can take to boost resilience when those attacks happen.
Our latest Purple Knight (PK) v4.2 release introduces fundamental changes, particularly concerning the new scoring calculation. Changing from a broader approach that considered all indicators, we’ve now zeroed in on the “failed” indicators, those that highlight genuine security threats in your environment. This shift aims to ensure that the overall…
In an ever-evolving digital landscape, organizations rely on robust identity protection solutions to safeguard sensitive data and maintain secure operations. For most enterprise businesses, that means protecting Active Directory and Entra ID (formerly Azure AD). But identity protection is just as vital for organizations that use Okta, a cloud-based identity…
The BadSuccessor Active Directory attack technique exploits a dangerous Windows Server 2025 vulnerability. Learn how DSP indicators of exposure and compromise enable you to proactively halt malicious activity.
Can you create an AD defense that exploits intruder attack techniques? Learn how to selectively use an attacker’s own methods to detect and expel them.
Post-exploitation tools—such as Cable, the Active Directory-specific pentesting tool—are meant to educate security teams. But attackers use them too. Here’s how to detect and defend against malicious use of the Cable tool.
Being a CISO can feel like an unwinnable battle. CISOs today are called to help the business understand cyber risk, put in place controls appropriate to its risk appetite, and ensure that it can withstand or recover quickly from difficult conditions while continuing to deliver required business outcomes. And as…
An identity an outage anywhere can become a business crisis everywhere. And effective defense means resilience—not just prevention—so operations can continue, even under attack. Learn how Semperis’ acquisition of MightyID expands our comprehensive identity resilience across your entire identity fabric.
The fastest way to turn a cyber incident into a business outage is through identity system compromise. Ransomware continues to exploit that fact—and the consequences are real. Here are practical, board-ready steps CISOs can take to boost resilience when those attacks happen.
Active Directory (AD) remains the crown jewel of enterprise infrastructure, and for threat actors, the holy grail is clear: gain Domain Admin privileges. This level of privilege effectively grants full control over your environment. Identity protection therefore plays an integral part in enterprise security, and organizations invest great efforts in…
AI agents aren’t just code running quietly in the background. They’re code with agency, wrapped in identity, carrying permissions, making decisions, and crossing boundaries on behalf of someone or something else. Learn how to avoid some simple but important misconfigurations as your organization begins adopting Agent ID at scale.
In the previous chapter of our guide to protecting agent identities, you learned about and practiced using Microsoft’s Agent Registry. In this Practice checkpoint, follow the steps to verify three agent identity authentication flows in Entra ID.
When misconfigured Service Principal Names (SPNs) and default permissions align, attackers can exploit Kerberos reflection to gain SYSTEM-level access remotely. Even with Microsoft’s security update, Ghost SPNs can still haunt you. Learn why.
Service accounts are easy to misconfigure, hard to keep track of, and often forgotten, making them ideal entry points for cyber attackers. Learn how DSP expands your ability to discover, monitor, govern, and protect service accounts.
Here’s what you need to know about password guessing and how to protect Active Directory—and your organization.
Stay informed. Get the latest news and resources on identity threat detection and response (ITDR), hybrid Active Directory (AD) security, and cyber resilience, brought to you by Semperis experts.