Tag: active-directory

Going Deep With Nested Group Audits

It is one of the top three most complex areas of auditing: nested groups! You know, you find a group listed on an access control list, and you ask for the group members. You get back a list of 25 users, but you know there must be more. So you ask for not only the users, but also the groups that have membership in the original group

Domain Password Policies: Configuring and Auditing Correctly!

Over the past 14 years, I have been around the world helping admins, auditors, and security professionals understand how the domain password policy works in Active Directory. The default behavior has not changed in those 14 years, so you can imagine how many people I have helped, not to mention how many times I have spoken about it. So why mention it here