We are happy to announce the release of our new SDK!
This is more than just a facelift. We have updated the contents and completely redesigned the layout, so navigating around is now a piece of cake. Comes with a cherry on top – a powerful search feature!
https://t.co/as06Ahj1yl
Did you know? Using only the default audit policies is below the recommended Microsft security baseline. Enable the Advanced Audit Policy Configuration to collect granular information about events in your AD.
Did you know? Using a role-based access control model to assign permissions is more efficient and flexible than managing access control lists (ACLs) across #ActiveDirectory.
Here's how it works in Adaxes: https://t.co/LodzEuyG7w via @YouTube
Review and revoke unnecessary access privileges of service accounts in your #ActiveDirectory. Service accounts are usually prime targets for malicious actors.
@alanburchill This one https://t.co/kD1KE4UBmd says that unless you need isolation or autonomy, it all boils down to cost-efficiency and ease of management, where a single-forest setup shines.
Although multi-forest configurations are possible, it is not recommended to intentionally plan and implement such configurations unless you have special security or autonomy requirements.
To start the week, here is an AD security tip:
Block web browsing on domain controllers and, ideally, block access to the internet altogether. But don't forget about intersite replication traffic - implement secure connections for that.
A quick tip for organizing your AD: having naming conventions for each AD object type can help identifying what the object is and what is its purpose just by looking at its name. You will be amazed how much information can fit in a few characters.
Want to automate the provisioning of #Exchange mailboxes? What about being able to manage #ActiveDirectory and Exchange from the same web interface? With Adaxes, it’s not a dream, it’s reality!
https://t.co/oc2pgHbRr0 via @YouTube
Need ideas on what to do with an empty backlog? Automate #Exchange mailbox provisioning and #Office365 license management with PowerShell or some other means. It will save you a lot of time later.
User accounts with privileged access rights should have more complicated passwords than ordinary user accounts. Configure the fine-grained password policies accordingly.
If your organization grows and more domains or even forests are added, keep trust relationships in check and well-documented. Having two-way transitive trusts everywhere is not exactly secure.
With people working from home due to #Coronavirus outbreak, someone will inevitably forget their password. Having an offsite offline self-service password reset tool for #ActiveDirectory would be very useful, and Adaxes has got you covered.
https://t.co/2bH0WCXpKm via @YouTube
Storing all domain controllers in the built-in Domain Controllers OU is considered best practice by #Microsoft. Having a child OU for each site is even better.
Might be obvious for some, but...
Never assign resource access permissions to individual accounts. You will quickly lose track of who has access to what. Use security groups instead.