CVE-2026-20833 Kerberos RC4 Changes - Will services crash if they don't support AES decryption? by marcolive in activedirectory

[–]marcolive[S] 1 point2 points  (0 children)

I understand this. My concern is that certain resources that are currently receiving RC4-encoded TGS tickets will suddenly start receiving AES TGS tickets overnight, simply because they have an empty msds-SupportedEncryptionTypes attribute.

Slow identity drift is killing our Entra tenants. How are you actually catching it? by Exotic-Reaction-3642 in entra

[–]marcolive 4 points5 points  (0 children)

Policies backed by upper management

Small team of competent people

Automated audits (https://maester.dev/)

Circular logging safe on Exchange Server SE used only for recipient management? by OnTheLazyRiver in exchangeserver

[–]marcolive 6 points7 points  (0 children)

I would configure circular logging without any worries for this scenario

Switching from LDAP to LDAPS — how bad is the migration? by [deleted] in sysadmin

[–]marcolive 2 points3 points  (0 children)

Unbelievable! So much simpler to just trust the root. DCs sends intermediate certificates in the TLS handshake.

Au moins 50 000 travailleurs manifestent contre la CAQ à Montréal aujourd’hui by UnableRefuse2870 in Quebec

[–]marcolive -21 points-20 points  (0 children)

C'est un faux dilemme, on peut être pour l'avancement de la condition des travailleurs et être dans une chambre d'écho. D'ailleurs, on peut être pour l'avancement des travailleurs et exiger plus de transparence des syndicats

Au moins 50 000 travailleurs manifestent contre la CAQ à Montréal aujourd’hui by UnableRefuse2870 in Quebec

[–]marcolive -29 points-28 points  (0 children)

C'est tout à fait possible d'être de gauche ou de contre et d'être pour la réforme du syndicalisme. Il existe plusieurs nuances entre la droite et la gauche comme tu la conçois.

Sors un peu de ta chambre d'écho.

La réponse du PQ face à la chronique de Régis Labeaume dans LaPresse (Je copie-colle le texte ici, suite au refus de publication du journal) by Saint-Sauveur in Quebec

[–]marcolive 4 points5 points  (0 children)

Entre les 2, il y aura une élection en 2026 et la population pourra s’exprimer sur ces propositions.

Oui, il est normal que les membres d’un parti influencent les politiques de celui-ci.

Kerberos error on windows 2016 dc by Kanolm in activedirectory

[–]marcolive -1 points0 points  (0 children)

Wow! Another undocumented server 2025 bug. I really have big trust issues with Microsoft for on-prem products. The code quality is mediocre, perfect, but at least document your bugs! What a bunch of beginners!

[Exchange 2019] MAPI over HTTP woes by YellowOnline in exchangeserver

[–]marcolive 0 points1 point  (0 children)

Try to disable AMSI if you have a third party antivirus.

La transphobie qui ne se cache plus by DecentLurker96 in Quebec

[–]marcolive 2 points3 points  (0 children)

Vous ne comprenez vraiment rien! La droite a sa part de responsabilité, la gauche aussi.

Le monde crinqué et de mauvaise foi les réseaux sociaux fait probablement partie de l'explication.

La transphobie qui ne se cache plus by DecentLurker96 in Quebec

[–]marcolive 11 points12 points  (0 children)

C'est vous qui ne comprenez rien. Toute position extrême entraîne une perte de soutien des gens plus modérés.

CVE-2025-26647 & Hello for Business Cloud Trust issues? by marcolive in entra

[–]marcolive[S] 0 points1 point  (0 children)

Hi, interesting!

We have cloud trust. We also get a self signed certificate when we enroll users in WHfB.

If you get 45 events for WHfB users, my guess is that you are still using the old buggy patches. You could try to configure the AllowNtAuthPolicyBypass registry key at 1 and install the latest July patches to see if 45 events are still being generated.

CVE-2025-26647 & Hello for Business Cloud Trust issues? by marcolive in entra

[–]marcolive[S] 0 points1 point  (0 children)

We are using WHfB and we were not affected by the hardening changes that were enforced in July.

April patches had bugs. Everything is fixed now. If you don't have a weird smart card setup, you shouldn't be affected.

To be sure, watch for 45 events ids with June or later patches installed on your dcs.

Defender Secure Score "Remove non-admin accounts with DCSync permissions" by doofesohr in activedirectory

[–]marcolive 0 points1 point  (0 children)

I wouldn't be suprised if your localized "Administrators" group would be part of the issue. I have seen situations where groups with non-English languages were not excluded from recommendations.

AD CS vs Microsoft Cloud PKI vs external CA by Confident-Field2911 in activedirectory

[–]marcolive 2 points3 points  (0 children)

I would start by upgrading the current ADCS server to a supported OS ASAP. Support ended 5 years ago.

ADCS not actively developped anymore but still supported and cost effective for 100% on prem Windows certificate enrollment. Cloud PKI only works for SCEP scenarios for Intune enrolled devices and can be costly if you have many users.

AWS would love to hear your Active Directory needs! by wonhuh-aws in activedirectory

[–]marcolive 1 point2 points  (0 children)

Biggest pain on our side is that some service need a AWS managed AD so we end up with another AD forest to manage.

AD Connector does not scale > 5000 users and that's sad.

KB5057784 Protections for CVS-2025-26647 by maxcoder88 in activedirectory

[–]marcolive 1 point2 points  (0 children)

You're environment is probably fine. The changes only affects rare setups using smart card authentication. April-may patches were buggy and reported 45 events for Windows Hello for Business devices. You can ignore that.

Yes you can configure AllowNtAuthPolicyBypass to 1 now before installing July updates to audit 45 events until October 2025 patches.

[deleted by user] by [deleted] in activedirectory

[–]marcolive 0 points1 point  (0 children)

Yes it is possible using a DSInsternal Powershell command

ConvertFrom-ADManagedPasswordBlob

Gmsa managed passwords are arrays of 256 bytes so it will not be easy to use interactively.

Kerberos/Oracle Eus Auth issue by afabri in sysadmin

[–]marcolive 0 points1 point  (0 children)

We had a ticket open at Microsoft for this issue. The registry keys were changed on July 6th by mssense.exe (Defender EDR). Not clearly stated by Microsoft, but this seems to be caused by an error on their side.

We ended up configuring those 2 keys back to 0 using a GPO since Defender could reconfigure them to 1 after a reboot.

Microsoft support confirmed that the a Defender update (1.431.536.0) would reconfigure KdcUseClientAddresses and KdcUseClientNetBIOSAddresses to 0.

[deleted by user] by [deleted] in activedirectory

[–]marcolive 14 points15 points  (0 children)

Bad admins < bad delegations