AD & Microsoft Security Solutions
Make Kerberoasting, Pass-the-Hash and privilege chains visible; control sessions with Arksoft SessionLimit, SessionAudit, ARKSSPR and ARK2FA.
Protect Your Identity Infrastructure, See the Privilege Chains, Detect the Misconfigurations
In modern organizations, user identity is now at the centre of cyber security.
Active Directory, Microsoft Entra ID and Microsoft 365 environments centrally manage;
- user accounts,
- administrator privileges,
- service accounts,
- group memberships,
- device identities,
- application access,
- authentication processes
these assets.
Attackers therefore mostly target the identity infrastructure before compromising a server directly.
The compromise of a single user account can turn into a broad attack chain in the form of;
Endpoint → Active Directory → Privilege Escalation → Domain Admin → Critical Systems
this progression.
SecureSys AD & Microsoft Security Solutions aim to make the security risks in organizations' Active Directory, Microsoft Entra ID and Microsoft 365 environments visible, to identify misconfigurations and to raise the security level against identity-based attacks.
Why Is Active Directory a Critical Security Component?
At many organizations Active Directory is the central identity infrastructure for users and computers.
Within the domain;
- Users
- Computers
- Servers
- Domain Controllers
- Security groups
- Group Policies
- Service accounts
- Privileged users
work in relation to one another.
This structure can offer a significant advantage from the attacker's perspective.
Because a single weak account or incorrect privilege can be used to move to other systems.
Active Directory Attack Paths
Attackers do not have to target the Domain Admin account directly within Active Directory.
Instead they can use indirect attack paths such as;
Low-Privileged User → Incorrect Group Privilege → Service Account → Administrator Server → Domain Admin
this chain.
Looking at the user list alone is therefore not enough.
The genuinely important matter is Attack Path Analysis, that is, making the attack paths visible.
Privilege Escalation
Misconfigured privileges in Active Directory environments can allow attackers to escalate privilege.
Among the risky situations can be;
- Unnecessary Domain Admin memberships
- Nested Group structures
- ACL errors
- Delegation problems
- Service account privileges
- Local Admin sprawl
- GPO misconfigurations
these conditions.
Kerberoasting
Kerberoasting is one of the frequently used Active Directory attack techniques targeting service accounts.
The attacker can request Kerberos service tickets for the service accounts within the domain and use those tickets in offline password cracking attacks.
Particularly;
- Weak service account passwords
- Passwords unchanged for a long time
- Highly privileged service accounts
can raise the risk considerably.
AS-REP Roasting
Accounts with Kerberos pre-authentication disabled can create a risk of AS-REP Roasting attacks.
The authentication configuration of user accounts should therefore be examined separately in security assessments.
Pass-the-Hash
Should NTLM hash values be seized, an attacker can try to reach other systems with the user's identity without knowing the password.
This technique is important particularly in lateral movement attacks.
Pass-the-Ticket
The seizure of Kerberos ticket information can allow an attacker to act as a privileged user.
Credential protection and privileged account security are therefore core parts of Active Directory security.
Golden Ticket and Kerberos Security
The compromise of the KRBTGT account is an extremely critical event in an Active Directory environment.
The attacker can create a forged Kerberos Ticket Granting Ticket and hold broad privileges within the domain.
The security of Domain Controllers and Tier-0 assets should therefore be addressed separately.
Domain Controller Security
The Domain Controller is one of the most critical systems of an organization's identity infrastructure.
An attacker gaining control over a Domain Controller can affect the security of the whole domain.
Therefore, the;
- EDR
- Network segmentation
- Privileged Access Management
- Administrative tiering
- Log monitoring
- Patch management
- Hardened configuration
controls should be applied.
Tier-0 Security
Tier-0 covers the most critical assets of the identity and security infrastructure.
Among these can be;
- Domain Controller
- Enterprise Admin
- Domain Admin
- PKI
- Identity management systems
- Privileged access infrastructure
these assets.
Tier-0 systems should be separated from ordinary user and server infrastructure.
Active Directory Security Posture Management
Modern AD security is not attack detection alone.
The AD Security Posture Management approach aims to make security risks such as;
- Misconfigurations
- Risky users
- Unnecessary privileges
- Attack paths
- Weak authentication settings
- Legacy protocols
- Risky delegations
- Unused accounts
continuously visible.
Active Directory Hardening
Technical improvement work carries critical importance in Active Directory security.
Within hardening;
- Reduction of Domain Admin accounts
- Local Administrator controls
- Restriction of NTLM use
- SMB security
- LDAP Signing
- LDAP Channel Binding
- Kerberos policies
- Strong password policies
- GPO security
- Legacy protocol reduction
can be assessed.
Microsoft Entra ID Security
With the spread of cloud use, identity infrastructure no longer consists of on-premise Active Directory alone.
Microsoft Entra ID is the identity layer of many critical services such as;
- Microsoft 365
- Azure
- SaaS applications
- Cloud identity
- Conditional Access
- MFA
- Enterprise Applications
and similar platforms.
Entra ID security should therefore be addressed as the continuation of Active Directory security.
Hybrid Identity
Many organizations use a hybrid identity architecture in the form of;
Active Directory ↕ Microsoft Entra ID ↕ Microsoft 365
this structure.
In these estates an on-premise security problem can affect cloud identities, or the compromise of a cloud account can turn into access to on-premise systems.
The security assessment should therefore cover both environments together.
MFA Security
While Multi-Factor Authentication is a critical control in identity security, it is not enough on its own.
Attackers can try to bypass MFA controls through methods such as;
- MFA fatigue
- Session token theft
- Adversary-in-the-Middle phishing
- Legacy authentication
- OAuth abuse
and similar techniques.
MFA should therefore be used together with the;
Conditional Access + Risk Analysis + Session Security + Strong Authentication
approach.
Conditional Access
Conditional Access is one of the core controls of Microsoft identity security.
In access policy, information such as;
- User
- Location
- Device state
- Application
- Risk level
- Authentication method
can be used.
For example, the;
Global Administrator + Unmanaged Device + Foreign IP → Block Access
policy can be applied.
Microsoft 365 Security
Within Microsoft 365 there are critical corporate services such as;
- Exchange Online
- SharePoint Online
- OneDrive
- Teams
and similar platforms.
The security of these services cannot be provided through user passwords alone.
Among the areas that need to be assessed are;
- External sharing
- Mail forwarding
- OAuth applications
- Administrator roles
- MFA
- Conditional Access
- Guest users
- Data sharing
- Security logging
these controls.
Business Email Compromise
One of the most critical threats in Microsoft 365 environments is Business Email Compromise attacks.
An attacker seizing an e-mail account can;
- Change mailbox rules
- Follow financial correspondence
- Create a fraudulent payment request
- Act as an executive
- Exfiltrate data
Microsoft 365 security should therefore not be assessed independently of endpoint security.
OAuth and Enterprise Application Risks
The OAuth permissions granted to third-party applications on Microsoft Entra ID can create a significant security risk.
Risky applications can;
- Read mail
- Reach files
- See user information
- Hold persistent access
Enterprise Application and consent processes should therefore be audited regularly.
Identity Threat Detection & Response – ITDR
ITDR is the security approach aiming to detect and respond to attacks targeting the identity infrastructure.
ITDR assesses the;
Identity + Behavior + Authentication + Privilege + Threat Detection
data together.
For example;
Standard user → Unexpected privileged group membership → Login from a new device → Access to a critical server
can be assessed as a high-risk identity event.
AD and EDR Integration
Endpoint security and identity security complement one another.
For example;
EDR → Credential Dumping detected ↓ AD Security → The user holds access to critical groups ↓ SOC → High-priority alarm
the real risk level of the event can be determined more accurately in this way.
AD + PAM
The security of privileged users is an important component of Active Directory security.
PAM solutions can ensure the controlled use of;
- Domain Admin
- Enterprise Admin
- Server Administrator
- Database Administrator
these accounts.
AD Security, in turn, makes the relationships and attack paths of those accounts within the domain visible.
AD + SIEM + SOC
Active Directory events are one of the critical log sources for SIEM.
Particularly;
- Login Failure
- New User
- Group Membership Change
- Privilege Change
- GPO Change
- Account Lockout
- Kerberos events
should be monitored continuously by the SOC.
The SecureSys AD & Microsoft Security Approach
In Active Directory and Microsoft security projects SecureSys does not merely carry out a product deployment.
First the;
AD Topology → Domain / Forest Analysis → Privileged Account Analysis → Attack Path Analysis → Entra ID Analysis → Microsoft 365 Security Review → Hardening → ITDR → SIEM/SOC Integration
approach can be applied.
AD Security Assessment
Within the assessment;
- Domain structure
- Forest structure
- Trust relationships
- Domain Controllers
- Privileged groups
- Service accounts
- Kerberos settings
- NTLM
- LDAP
- GPO
- ACL
- Delegation
- Local Admin
- Password policy
- Legacy systems
can be analyzed.
Microsoft 365 Security Assessment
On the Microsoft 365 side, areas such as;
- Global Administrator accounts
- MFA
- Conditional Access
- Guest Users
- Mail Forwarding
- External Sharing
- Enterprise Applications
- OAuth Permissions
- Audit Logging
- Security Defaults
can be assessed.
Analyze Your Identity Infrastructure Before the Attackers Do
In modern attacks the attackers' target is mostly not the device but the identity.
The compromise of a user account, an incorrect authorization or a risky service account can turn into attack chains capable of affecting the whole corporate infrastructure.
With SecureSys AD & Microsoft Security Solutions, make the risks in your Active Directory, Entra ID and Microsoft 365 environments visible, detect the attack paths and strengthen your identity infrastructure with Zero Trust principles.
Request an analysis, POC and quote for AD & Microsoft Security Solutions
Arksoft Active Directory & Microsoft Security Solutions
Identity, Session and Access Security in Microsoft Infrastructure
In corporate Microsoft infrastructure, security is not limited to creating Active Directory users and applying password policy.
The questions of;
On how many different devices a user can open a session, On which systems they hold active sessions, How session activity is audited, How they manage their passwords, Whether authentication is protected by a second factor
are important parts of Active Directory security.
With Arksoft solutions, SecureSys offers answers to security needs such as controlling user sessions in Microsoft Active Directory environments, auditing activity, making password processes secure and multi-factor authentication.
Arksoft SessionLimit
Bring Active Directory User Sessions Under Control
SessionLimit is a solution for controlling users' concurrent sessions in Active Directory environments.
In corporate estates, the same user account being usable concurrently on more than one computer can create a risk both operationally and from a security perspective.
For example, the;
User A → session open on PC-01 → second session on PC-15 → third session at a different location
scenario can create a situation that needs examining from an account sharing or unauthorized use perspective.
With SessionLimit the aim is to prevent the uncontrolled use of Active Directory accounts by restricting users' concurrent sessions with central policy.
Why SessionLimit?
It can be assessed particularly in estates where;
- Shared user accounts need reducing
- User account sharing needs controlling
- Concurrent sessions need restricting
- Active Directory access security needs raising
- Unauthorized user activity needs reducing
these needs are present.
Arksoft SessionAudit
Make Active Directory Sessions Visible
SessionAudit can be positioned for monitoring and auditing users' session activity in Microsoft and Active Directory environments.
In identity security, answering only the question;
"Can the user log into the system?"
is not enough.
At the same time, the questions;
Who logged in? From which computer did they log in? When did they log in? How long did the session last? Which user used which endpoint?
need to be answerable.
By increasing this visibility SessionAudit supports security, audit and incident investigation processes.
Its Importance from a SIEM and SOC Perspective
In a security incident, the SOC team seeing only the IP address may not be enough.
For example, when access to a critical system is carried out from the;
10.10.10.25
IP address, being able to answer the question;
Which user was using this IP at that moment?
quickly makes incident response considerably easier.
Technologies providing session visibility such as SessionAudit can therefore be assessed as a security layer complementing SIEM and SOC operations.
Arksoft ARKSSPR
Self-Service Password Reset
ARKSSPR is a solution for users to manage Active Directory password processes securely and in a controlled way with the Self-Service Password Reset – SSPR approach.
In corporate estates one of the significant causes of Help Desk calls is the;
"I forgot my password."
request.
In the traditional method the user contacts the IT or Help Desk team and asks for their password to be reset.
With ARKSSPR the user can carry out the password reset as self-service after the appropriate authentication checks.
The Advantages of SSPR
The Self-Service Password Reset approach can offer significant advantages in terms of;
- Reducing the Help Desk operational load
- Speeding up password reset processes
- Improving the user experience
- Standardizing password processes
- Raising authentication security
these factors.
Arksoft ARK2FA
Two-Factor Authentication for Active Directory
ARK2FA is an identity security solution for strengthening user access with a second verification factor rather than protecting it with username and password alone.
Should the password be seized by an attacker, on systems using password-based authentication alone the attacker can gain access directly.
In the 2FA approach, by contrast;
Username + Password + Second Verification Factor
are used together.
The attacker's access to the system is thereby made harder even if the password has been seized.
Why 2FA?
Applying strong authentication controls is important particularly for;
- Critical users
- Administrator accounts
- Remote access
- Sensitive systems
- Privileged users
these cases.
How Do Arksoft Solutions Complete Active Directory Security?
These four products in fact form a fine structure complementing one another:
SessionLimit In how many places can a user open a session?
SessionAudit Where and when did the user open a session?
ARKSSPR How does the user manage the password reset process securely?
ARK2FA How do we verify more strongly that the user really is the right person?
An integrated Microsoft identity security layer can thereby be built in the form of;
Active Directory ↓ Identity ↓ Authentication ↓ Session Control ↓ Session Audit ↓ Password Security ↓ 2FA
this structure.
SecureSys + Arksoft
At SecureSys we design Arksoft solutions as projects around the organization's existing Active Directory and Microsoft infrastructure.
The process;
AD Analysis → User and Group Analysis → Determining Security Requirements → Product Selection → POC → Deployment → Policy Creation → Active Directory Integration → SIEM/SOC Integration → Operations & Support
can be carried out in this way.
Do Not Merely Manage Your Active Directory — Control It
Active Directory security is not merely applying a strong password policy.
Restrict the session. Audit the session. Make password processes secure. Verify identity with a second factor.
Increase the control you hold over your Microsoft identity infrastructure with SecureSys and Arksoft solutions.
Request a demo, POC and quote for Arksoft AD & Microsoft Solutions
Want to learn more about this service?
Our expert team will reach out for a free consultation as soon as possible.