Categories

Active Directory Backup & Recovery

How to Redefine Cyber Resilience: Start by Rethinking Hybrid Identity Protection

  • Guido Grillenmeier | Principal Technologist, EMEA
  • Aug 19, 2026

Cyber resilience isn’t a single team’s job anymore. Learn about the roles a resilient organization actually needs assembled, long before the next crisis forces the point—and make your case for sending more than one person to the 2026 Hybrid Identity Protection Conference.

How the Five Eyes AI Warning Changes Board Thinking About Cyber Recovery and Resilience

  • Nick Lowther
  • Aug 04, 2026

AI has changed the face of the attack surface. It has changed how attackers advance and how we defend systems. And it changes the way that Boards must think about the intersection of AI adoption, identity security, and recovery.

Identity Resilience Checklist: 6 Ways to Think Beyond Backup

  • Darren Mar-Elia | Principal Security Strategist
  • May 04, 2026

Resilience means you can recover your identity system in a trustworthy way to a level that restores critical business functions. When evaluating any identity resilience solution, demand that your vendor meet this list of non-negotiable requirements—and prove it.

Active Directory Security

What Should You Install on Your Domain Controllers?

  • Tim Beasley
  • Sep 01, 2026

There are plenty of questions on the internet regarding which software should be installed on a domain controller (DC). Which roles should be deployed? Which applications are required? To answer these questions, you must consider what a DC should do in the first place. Which Windows Server roles should you…

How to Redefine Cyber Resilience: Start by Rethinking Hybrid Identity Protection

  • Guido Grillenmeier | Principal Technologist, EMEA
  • Aug 19, 2026

Cyber resilience isn’t a single team’s job anymore. Learn about the roles a resilient organization actually needs assembled, long before the next crisis forces the point—and make your case for sending more than one person to the 2026 Hybrid Identity Protection Conference.

How the Five Eyes AI Warning Changes Board Thinking About Cyber Recovery and Resilience

  • Nick Lowther
  • Aug 04, 2026

AI has changed the face of the attack surface. It has changed how attackers advance and how we defend systems. And it changes the way that Boards must think about the intersection of AI adoption, identity security, and recovery.

AD Security 101

AD Group Risks: Hidden Powers of Account Operators

  • Tim Beasley
  • Aug 28, 2026

Account Operators is an AD group that many people underestimate because it doesn’t contain the word “admins.” The problem is that it gives broad control over identities across the domain—and in Active Directory, identities are privilege. See how attackers use this group to move from “not quite privileged” to “I…

What You’re Missing: Proper LAN Manager Authentication Levels

  • Andrea Pierini
  • Mar 11, 2026

One of the most common misconfigurations I encounter in Active Directory environments is a LAN Manager authentication level set to 2 on domain controllers (DCs). If your reason for staying at level 2 is legacy application compatibility, you can move to level 3 today without breaking those applications.

How to Defend Against a Password Spraying Attack

  • Daniel Petri | Senior Training Manager

Active Directory remains a critical infrastructure component for managing network resources, login credentials, and user authentication. Yet its centrality makes it a prime target for cyberattacks. One such evolving cyberattack is password spraying, a threat that’s gained in complexity in recent years. Password spraying attacks stand out due to their…

Agentic AI

How to Redefine Cyber Resilience: Start by Rethinking Hybrid Identity Protection

  • Guido Grillenmeier | Principal Technologist, EMEA
  • Aug 19, 2026

Cyber resilience isn’t a single team’s job anymore. Learn about the roles a resilient organization actually needs assembled, long before the next crisis forces the point—and make your case for sending more than one person to the 2026 Hybrid Identity Protection Conference.

How the Five Eyes AI Warning Changes Board Thinking About Cyber Recovery and Resilience

  • Nick Lowther
  • Aug 04, 2026

AI has changed the face of the attack surface. It has changed how attackers advance and how we defend systems. And it changes the way that Boards must think about the intersection of AI adoption, identity security, and recovery.

Checklist: Prepare Your Identity Fabric for the Agentic Era

  • Alex Weinert | Chief Product Officer
  • Jul 30, 2026

Your business leaders are racing to adopt generative and agentic AI to move faster and unlock new efficiencies. As your business bets more on agents, it bets more on your identity fabric. Use this checklist to be sure you’re ready.

Community Tools

How to Audit Your Environment for RC4 Encryption

  • Guido Grillenmeier and Rich Peckham
  • Mar 30, 2026

Microsoft is deprecating RC4 encryption beginning in April 2026. This post explains the process—and points you to resources that can help.

EntraGoat Scenario 3: Exploiting Group Ownership in Entra ID

  • Jonathan Elkabas and Tomer Nahum

Dive into EntraGoat Scenario 3, where you’ll discover how individually legitimate Entra ID features, when combined with misconfigured group ownership, can cascade into a privilege escalation chain that elevates a low-level account into a tenant-wide threat.

EntraGoat Scenario 6: Exploiting Certificate-Based Authentication to Impersonate Global Admin in Entra ID

  • Jonathan Elkabas and Tomer Nahum

Editor’s note This scenario is part of a series of examples demonstrating the use of EntraGoat, our Entra ID simulation environment. You can read an overview of EntraGoat and its value here. Certificate Bypass Authority–Root Access Granted EntraGoat Scenario 6 details a privilege escalation technique in Microsoft Entra ID where…

Crisis Management

How to Redefine Cyber Resilience: Start by Rethinking Hybrid Identity Protection

  • Guido Grillenmeier | Principal Technologist, EMEA
  • Aug 19, 2026

Cyber resilience isn’t a single team’s job anymore. Learn about the roles a resilient organization actually needs assembled, long before the next crisis forces the point—and make your case for sending more than one person to the 2026 Hybrid Identity Protection Conference.

How the Five Eyes AI Warning Changes Board Thinking About Cyber Recovery and Resilience

  • Nick Lowther
  • Aug 04, 2026

AI has changed the face of the attack surface. It has changed how attackers advance and how we defend systems. And it changes the way that Boards must think about the intersection of AI adoption, identity security, and recovery.

Checklist: Prepare Your Identity Fabric for the Agentic Era

  • Alex Weinert | Chief Product Officer
  • Jul 30, 2026

Your business leaders are racing to adopt generative and agentic AI to move faster and unlock new efficiencies. As your business bets more on agents, it bets more on your identity fabric. Use this checklist to be sure you’re ready.

Directory Modernization

11 Real-World Risks Hidden in Active Directory Migrations

  • Mike Masciulli
  • Jun 12, 2026

An Active Directory migration and consolidation project is not just a data move. If you carry over legacy delegation mistakes, group nesting, trust relationships, and overprivileged accounts, you simply recreate risky attack paths. Learn how a security-first approach helps you make your new AD environment more secure.

Security-Centric Active Directory Migration and Consolidation

  • Mike Masciulli

Enterprise organizations with legacy Active Directory (AD) environments have a security problem. Their AD infrastructure has likely degraded over time and now harbors multiple security vulnerabilities because of inefficient architecture, multiple misconfigurations, and poorly secured legacy applications. Yet Active Directory migration and consolidation, especially involving a sprawling AD infrastructure, is…

Active Directory Migration: 15 Steps to Success

  • Daniel Petri | Senior Training Manager

Active Directory (AD) migration projects can be challenging and complex. Such projects involve the migration of users, groups, computers, and applications from one AD domain or forest to another. Careful planning and execution can help your migration team complete a successful AD migration, with minimal disruption to end users and…

From the Front Lines

Midnight in the War Room: The CISOs’ Challenge Comes to the Screen

  • Simon Hodgkinson
  • Jul 23, 2026

Being a CISO can feel like an unwinnable battle. CISOs today are called to help the business understand cyber risk, put in place controls appropriate to its risk appetite, and ensure that it can withstand or recover quickly from difficult conditions while continuing to deliver required business outcomes. And as…

Ransomware Defense in 2026: What CISOs Need to Know

  • Sean Deuby | Principal Technologist, Americas

The fastest way to turn a cyber incident into a business outage is through identity system compromise. Ransomware continues to exploit that fact—and the consequences are real. Here are practical, board-ready steps CISOs can take to boost resilience when those attacks happen.

Hello, My Name Is Domain Admin

  • Mickey Bresman

My friends know I’m a movie buff. Being also a mixed martial enthusiast, one of my all-time favorites is Fight Club, based on Chuck Palahniuk’s first novel. The story is about an identity crisis: rebelling against consumerism, trying to find truth and meaning in life, and becoming a “real” person…

Hybrid Identity Protection

How to Redefine Cyber Resilience: Start by Rethinking Hybrid Identity Protection

  • Guido Grillenmeier | Principal Technologist, EMEA
  • Aug 19, 2026

Cyber resilience isn’t a single team’s job anymore. Learn about the roles a resilient organization actually needs assembled, long before the next crisis forces the point—and make your case for sending more than one person to the 2026 Hybrid Identity Protection Conference.

How the Five Eyes AI Warning Changes Board Thinking About Cyber Recovery and Resilience

  • Nick Lowther
  • Aug 04, 2026

AI has changed the face of the attack surface. It has changed how attackers advance and how we defend systems. And it changes the way that Boards must think about the intersection of AI adoption, identity security, and recovery.

Checklist: Prepare Your Identity Fabric for the Agentic Era

  • Alex Weinert | Chief Product Officer
  • Jul 30, 2026

Your business leaders are racing to adopt generative and agentic AI to move faster and unlock new efficiencies. As your business bets more on agents, it bets more on your identity fabric. Use this checklist to be sure you’re ready.

Identity Attack Catalog

How to Defend Against Password Guessing Attacks

  • Daniel Petri | Senior Training Manager

Here’s what you need to know about password guessing and how to protect Active Directory—and your organization.

Group Policy Preferences Abuse Explained

  • Huy Kha | Senior Identity & Security Architect

The Group Policy Preferences feature provides a well-known pathway for cyber attackers to discover easily decoded passwords in Active Directory. Learn to spot and defend against this vulnerability.

ESC1 Attack Explained

  • Huy Kha | Senior Identity & Security Architect

Discover how certificate template misconfigurations in Active Directory Certificate Services (AD CS) enable ESC1 attacks—allowing cyber attackers to rapidly escalate privileges and potentially compromise entire networks.

Identity Security Research Library

Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover

  • Shai Laron | Security Researcher
  • Aug 05, 2026

Active Directory (AD) remains the crown jewel of enterprise infrastructure, and for threat actors, the holy grail is clear: gain Domain Admin privileges. This level of privilege effectively grants full control over your environment. Identity protection therefore plays an integral part in enterprise security, and organizations invest great efforts in…

Where Things Might Go Wrong with Agent Identities in Entra ID—and How to Prevent Disaster

  • Semion Vasilevitzky and Jonathan Elkabas
  • Jul 12, 2026

AI agents aren’t just code running quietly in the background. They’re code with agency, wrapped in identity, carrying permissions, making decisions, and crossing boundaries on behalf of someone or something else. Learn how to avoid some simple but important misconfigurations as your organization begins adopting Agent ID at scale.

Practice Checkpoint 4: Verifying Tokens and Claims in 3 Entra ID Authentication Flows

  • Semion Vasilevitzky and Jonathan Elkabas
  • Jul 11, 2026

In the previous chapter of our guide to protecting agent identities, you learned about and practiced using Microsoft’s Agent Registry. In this Practice checkpoint, follow the steps to verify three agent identity authentication flows in Entra ID.

Identity Threat Detection & Response

What Should You Install on Your Domain Controllers?

  • Tim Beasley
  • Sep 01, 2026

There are plenty of questions on the internet regarding which software should be installed on a domain controller (DC). Which roles should be deployed? Which applications are required? To answer these questions, you must consider what a DC should do in the first place. Which Windows Server roles should you…

How to Redefine Cyber Resilience: Start by Rethinking Hybrid Identity Protection

  • Guido Grillenmeier | Principal Technologist, EMEA
  • Aug 19, 2026

Cyber resilience isn’t a single team’s job anymore. Learn about the roles a resilient organization actually needs assembled, long before the next crisis forces the point—and make your case for sending more than one person to the 2026 Hybrid Identity Protection Conference.

Checklist: Prepare Your Identity Fabric for the Agentic Era

  • Alex Weinert | Chief Product Officer
  • Jul 30, 2026

Your business leaders are racing to adopt generative and agentic AI to move faster and unlock new efficiencies. As your business bets more on agents, it bets more on your identity fabric. Use this checklist to be sure you’re ready.

Our Mission: Be a Force for Good

Midnight in the War Room: The CISOs’ Challenge Comes to the Screen

  • Simon Hodgkinson
  • Jul 23, 2026

Being a CISO can feel like an unwinnable battle. CISOs today are called to help the business understand cyber risk, put in place controls appropriate to its risk appetite, and ensure that it can withstand or recover quickly from difficult conditions while continuing to deliver required business outcomes. And as…

Duns 100 Ranks Semperis in Top 15 to Work For

  • Yarden Gur

This month marked two milestones for Semperis. First, Deloitte recognized the company as one of the 100 fastest growing technology companies in North America and (for the third consecutive year) one of the top 10 fastest-growing tech companies in the greater New York area. Then, the company was listed for…

What It Means to be a Mission-Driven Company

  • Mickey Bresman

On behalf of the entire team, I’m excited to share that Semperis has been named to Inc.’s 2022 list of Best Workplaces. This annual list honors workplaces that are ranked highly by their employees on topics like benefits, trust in senior leadership, change management, and career development. I could not…

Purple Knight

Ransomware Defense in 2026: What CISOs Need to Know

  • Sean Deuby | Principal Technologist, Americas

The fastest way to turn a cyber incident into a business outage is through identity system compromise. Ransomware continues to exploit that fact—and the consequences are real. Here are practical, board-ready steps CISOs can take to boost resilience when those attacks happen.

Purple Knight Scoring Improves Understanding of Identity System Security Vulnerabilities

  • Ran Harel

Our latest Purple Knight (PK) v4.2 release introduces fundamental changes, particularly concerning the new scoring calculation. Changing from a broader approach that considered all indicators, we’ve now zeroed in on the “failed” indicators, those that highlight genuine security threats in your environment. This shift aims to ensure that the overall…

Semperis Offers New Protection Against Okta Breaches

  • Semperis Research Team

In an ever-evolving digital landscape, organizations rely on robust identity protection solutions to safeguard sensitive data and maintain secure operations. For most enterprise businesses, that means protecting Active Directory and Entra ID (formerly Azure AD). But identity protection is just as vital for organizations that use Okta, a cloud-based identity…

Semperis University

BadSuccessor: How to Detect and Mitigate dMSA Privilege Escalation

  • Semperis Team

The BadSuccessor Active Directory attack technique exploits a dangerous Windows Server 2025 vulnerability. Learn how DSP indicators of exposure and compromise enable you to proactively halt malicious activity.

Exploiting the Intruder’s Dilemma for Active Directory Defense

  • Huy Kha | Senior Identity & Security Architect

Can you create an AD defense that exploits intruder attack techniques? Learn how to selectively use an attacker’s own methods to detect and expel them.

Defending Against Cable: Prevent Malicious Use of Post-Exploitation Tool

  • Huy Kha | Senior Identity & Security Architect

Post-exploitation tools—such as Cable, the Active Directory-specific pentesting tool—are meant to educate security teams. But attackers use them too. Here’s how to detect and defend against malicious use of the Cable tool.

The CISO’s Perspective

Midnight in the War Room: The CISOs’ Challenge Comes to the Screen

  • Simon Hodgkinson
  • Jul 23, 2026

Being a CISO can feel like an unwinnable battle. CISOs today are called to help the business understand cyber risk, put in place controls appropriate to its risk appetite, and ensure that it can withstand or recover quickly from difficult conditions while continuing to deliver required business outcomes. And as…

Semperis Acquires MightyID: Expands True Cyber Resilience Across Multi-IdP Environments

  • Alex Weinert | Chief Product Officer

An identity an outage anywhere can become a business crisis everywhere. And effective defense means resilience—not just prevention—so operations can continue, even under attack. Learn how Semperis’ acquisition of MightyID expands our comprehensive identity resilience across your entire identity fabric.

Ransomware Defense in 2026: What CISOs Need to Know

  • Sean Deuby | Principal Technologist, Americas

The fastest way to turn a cyber incident into a business outage is through identity system compromise. Ransomware continues to exploit that fact—and the consequences are real. Here are practical, board-ready steps CISOs can take to boost resilience when those attacks happen.

Threat Research

Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover

  • Shai Laron | Security Researcher
  • Aug 05, 2026

Active Directory (AD) remains the crown jewel of enterprise infrastructure, and for threat actors, the holy grail is clear: gain Domain Admin privileges. This level of privilege effectively grants full control over your environment. Identity protection therefore plays an integral part in enterprise security, and organizations invest great efforts in…

Where Things Might Go Wrong with Agent Identities in Entra ID—and How to Prevent Disaster

  • Semion Vasilevitzky and Jonathan Elkabas
  • Jul 12, 2026

AI agents aren’t just code running quietly in the background. They’re code with agency, wrapped in identity, carrying permissions, making decisions, and crossing boundaries on behalf of someone or something else. Learn how to avoid some simple but important misconfigurations as your organization begins adopting Agent ID at scale.

Practice Checkpoint 4: Verifying Tokens and Claims in 3 Entra ID Authentication Flows

  • Semion Vasilevitzky and Jonathan Elkabas
  • Jul 11, 2026

In the previous chapter of our guide to protecting agent identities, you learned about and practiced using Microsoft’s Agent Registry. In this Practice checkpoint, follow the steps to verify three agent identity authentication flows in Entra ID.

Uncategorized

Exploiting Ghost SPNs and Kerberos Reflection for SMB Server Privilege Elevation

  • Andrea Pierini

When misconfigured Service Principal Names (SPNs) and default permissions align, attackers can exploit Kerberos reflection to gain SYSTEM-level access remotely. Even with Microsoft’s security update, Ghost SPNs can still haunt you. Learn why.

Improve Hybrid AD Security with Automated Response and Streamlined Administration

  • Eran Gewurtz | Director of Product Management

Service accounts are easy to misconfigure, hard to keep track of, and often forgotten, making them ideal entry points for cyber attackers. Learn how DSP expands your ability to discover, monitor, govern, and protect service accounts.

How to Defend Against Password Guessing Attacks

  • Daniel Petri | Senior Training Manager

Here’s what you need to know about password guessing and how to protect Active Directory—and your organization.

AD security resources

Stay informed. Get the latest news and resources on identity threat detection and response (ITDR), hybrid Active Directory (AD) security, and cyber resilience, brought to you by Semperis experts.