Why did I leave Microsoft?
To work full time on 🔥 Maester.
Over 40,000+ tenants today rely on Maester to monitor their tenants daily.
I wanted to make sure that the tests they are running continue to be relevant and evolve as Microsoft 365 and the security landscape evolves.
So today I'm announcing the launch of https://t.co/F5uN233Yh7
Maester Cloud is the portal companion to Maester that lets you track your results over time. It is multi tenant, runs in your cloud (or ours) and more → check out the site for all the features.
More importantly Maester Cloud is a way for me to fund the continued development of the open source Maester core and the tests in Maester.
That is our mission. In fact I worked with the core team @fabian_bader , @Thomas_Live , @MySnozzberries and @SamErde to create the Maester Manifesto (https://t.co/wcm7PnGEMr). It is our promise to the community.
If you value Maester and would like to support and ensure that Maester continues to grow and be healthy, I would be beyond thrilled if your organisation can sponsor this effort.
I would also appreciate it very much if you can share this post with your network to spread awareness.
Thanks!
@MyNameIsMurray That's the perfect scenario.
Keep all on-prem traffic on-prem and all cloud scenarios cloud native.
I am interested in how you auth into your VPN...
Want to guess what your users authenticate with for the 'initial access' to AD when working remotely?
Wait for it...
Entra ID of course ☺️
Entra ID is the hard shell that protects your org.
Hacktive Directory is the yummy chocolate inside the attackers love.
@merill This was potentially available to anyone who was able to find it, anywhere on the internet.
At least with AD you need initial access. There’s still some controls in front of it.
I've been super impressed with @OpenAIDevs Codex GitHub Code Review
It finds high quality bugs, very little noisy review comments (looking at you GitHub Code reviews)
The best part is I can use my existing Open AI subscription without paying for anything extra.
Claude on the other hand limits PR review to Teams and Enterprise. Boo.
I'm looking forward to trying out Codex Security Review soon https://t.co/Mk60P2QM05
https://t.co/E6ktUbKeFF
@sherrod_im@HackingLZ I was in one of the many internal sessions, and you really brought everyone along.
It was one of the clearest explanations I’ve seen of the threat landscape, what happened and how it connects to everyone’s work.
I learned a lot. Thank you!
@sherrod_im@HackingLZ Some of the most significant security efforts I've seen in my lifetime.
Most folks outside Microsoft will never get to know the mountains moved by you and the rest of the teams entrusted with SFI.
I'm looking forward to reading your book on this someday.
I'll be at @wpninjasus in January!! I'll be talking about Active Directory security with a bunch of other amazing Microsoft MVPs & security people.
I'll be posting more about this in the coming weeks, but I HIGHLY recommend coming to check out the event!!
Scottsdale Arizona - January 2027
@steskalj@nikhil_mitt Oh dear.
Want to guess how you sign into GCP and AWS?
AWS is even deprecating their Advanced AWS Managed Service and instead moving most folks to the Entra ID Domain Services model.
@nikhil_mitt asked for more so I'll share here 😀
Here's the reason why it's not expanding the surface to migrate from AD to Entra ID.
Any org using Microsoft 365 already has Entra ID and they are already syncing their identities to Entra ID to access all cloud apps. The attack surface expanded the moment they started using Exchange Online, Teams, take your pick of the service they are using in the cloud.
Thats why migrating from Active Directory to Entra ID and shutting down Active Directory removes a whole swath of attack surfaces.
It's not just theory. Some of the biggest attacks we know (looking at you Solorigate) happened with breaches on-prem and then pivoting to the cloud.
So much so the team I used to work at Microsoft wrote this post (https://t.co/Ra7a18LDGH) because so many customers wanted to know how they could protect the cloud (which is where most orgs business critical data lives these days).
So shutting down ADFS, AD and reducing they dependency on these reduces your attack surface simply because everyone is already running AD and Entra ID. Shutting it down removes a whole class of attack vectors.
Migrating from Active Directory to Entra is by its nature expanding the attack surface. And that’s ok, we can make that trade. But what I don’t think people realize when saying that is you don’t have as much control over it as you think you do.
@steskalj@nikhil_mitt Azure Arc is where Microsoft is investing in this space.
Surely your Server VMs in Azure, AWS and GCP clouds are not joined to AD right?
Agree, the more secure option is to not have trust either way.
The big ones are to not sync privileged identities either way (which is the default for Entra Connect Sync but a lot of folks override it)
Reduce syncing on prem groups to the cloud and vice versa.
It does mean groups get duplicated and need to be maintained on both sides.
Which is why moving complete class of workloads to be exclusively AD or Entra ID will also help you be more secure.
@techspence it seems to me like merill's argument is that your comparison is sort of unfair, because almost nobody is/can be pure AD anymore. ~everyone is hybrid to some degree. so instead of comparing "entra vs AD" you should be comparing "entra vs AD+entra".
👋 Folks after year long hiatus the community powered database of aka•ms is back!!
Bookmark it 👇
https://t.co/VuTPiAM8W7
I made some updates to the site, including a much simpler experience to contribute aka•ms links to the database.
@collysucker@techspence There are ways they can figure out.
Also it boils down to whether we trust them when they say Exploited: No
Also remember they are legally accountable to disclose and I know they took these very seriously.