BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

We’ll Cross that Active Directory Bridge When We Come to it

Posted July 8, 2011    Peter McCalister

It seems like you can’t turn on the news or surf the web without hearing about yet another data breach or information security attack, all of which lead to further consumer unrest and corporate concern about the protection of their own sensitive data. The security structure within most organizations generally provides a multitude of security mechanisms designed to provide protection of sensitive information, but with so many different aspects of security to consider, IT administrators and security officers need to be sure not to overlook the Active Directory.

Earlier this week we announced the acquisition of Likewise Software’s Enterprise and Likewise Open products, expanding our portfolio of inside perimeter privilege delegation, monitoring and auditing solutions to include authentication and auditing management for cloud environments. While designing a secure Active Directory infrastructure is not a simple task, it’s one that is well worth the investment for a variety of reasons, including, but not limited to:

-Eliminate plain-text passwords or replace basic authentication with Kerberos – a problem that Sony faced during April’s data breach of PSN customers
-Replace a Network Information Service (NIS) environment, an obsolete and insecure directory service
-Provide a common, highly secure authentication framework for a heterogeneous network
-Control access to sensitive resources
-Limit access to different servers and other computing assets to privileged users
-Give Windows users single sign-on to intranets and applications running on Unix servers

Active Directory Bridge products are a valuable tool for the IT department; however it’s critical to take precautions to ensure protection of the Active Directory as part of a larger security infrastructure. We’ve reached the bridge, now it’s time to cross it.

Leave a Reply

Additional articles

6

A Quick Look at MS14-068

Posted November 20, 2014    BeyondTrust Research Team

Microsoft recently released an out of band patch for Kerberos.  Taking a look at the Microsoft security bulletin, it seems like there is some kind of issue with Kerberos signatures related to tickets. Further information is available in the Microsoft SRD Blogpost So it looks like there is an issue with PAC signatures.  But what…

Tags:
, , , ,
Password Game Show

Managing Shared Accounts for Privileged Users: 5 Best Practices for Achieving Control and Accountability

Posted November 20, 2014    Scott Lang

How do organizations ensure accountability of shared privileged accounts to meet compliance and security requirements without impacting administrator productivity? Consider these five best practices…

Tags:
, , , , , ,
Triggering MS14-066

Triggering MS14-066

Posted November 17, 2014    BeyondTrust Research Team

Microsoft addressed CVE-2014-6321 this Patch Tuesday, which has been hyped as the next Heartbleed.  This vulnerability (actually at least 2 vulnerabilities) promises remote code execution in applications that use the SChannel Security Service Provider, such as Microsoft Internet Information Services (IIS). The details have been scarce.  Lets fix that. Looking at the bindiff of schannel.dll, we see a…

Tags:
, , , , ,