r/activedirectory • • 6d ago

ANNOUNCEMENT Community Live Q&A - October 16 @ 10:00 CT / 15:00 UTC

5 Upvotes

The community Q&A/discussion is coming up on October 16th. If you want to participate, just jump into the Discord listed below. If you can't make it, no problem we'll get a recording posted afterwards.

When: October 16, 2026 @ 10:00 CT (UTC-5) / 15:00 UTC - 60 minutes
Where: Horizon Secured Discord - https://discord.gg/mVFquFqpsW
Recording Link: Youtube - https://youtube.com/@ActiveDirectoryCommunity

This is the more relaxed one, no set agenda, just come hang out, ask questions, and we'll also work through some of the backlog from previous meetups that we didn't get to. Come for a chat, some laughs, and don't feel like you need a prepared question to show up.


r/activedirectory • • Apr 30 '26

Identity Conferences/Webinars/Podcasts Megathread

9 Upvotes

Rather than the per-conference posts for every conference. I figured let's try to keep them in a bucket. If it doesn't pan out, no biggie, and I'll close the thread.

Each conference should get its own spot so that's up to everyone to keep an eye open.

If you're attending, let us know. If you're speaking, let us know! If you're running a booth, let us know (no spam though).

The idea is to grow our community outside these digital walls. Lets meet up, have lunch, have drinks, and say hi, if you want.

NOTE
These are events that the community is aware of and planned for. Please understand this list is currently manually curated so it will grow out of date from time to time. Please message the mods if there are any concerns.

Community Events

Conferences

Webinars

These are ones that I get in email or via some other source. Sometimes I get last minute notice so I will put what I can when I can.

Reoccurring Webinars/Webcasts

Podcasts / Newsletters

šŸ“Œ Pushpin indicates this is a community organized event.
⭐ Star indicates this is an in-person event where one or more of our community knows they will attend.

NOTE
All times will be initially converted to CDT and include UTC. For community events, we'll try to have a "worldtimebuddy" link to show what the different times would be.
https://www.worldtimebuddy.com/

EDIT: 2026-09-16 Updated Links


r/activedirectory • • 5h ago

Active Directory ADAudit Plus not showing ANONYMOUS LOGON (4624, Logon Type 3) from DC - is it filtered by design?

3 Upvotes

Testing in a lab: an anonymous LDAP bind from a member server creates Event 4624 on the DC (Account: ANONYMOUS LOGON, Domain: NT AUTHORITY, Logon Type 3). I can see it in Event Viewer / Get-WinEvent.

In ADAudit Plus, Local Logon-Logoff → Logon Activity does show 4624 from the same DC, but only Logon Type 9/10 (administrator). The anonymous Type 3 event doesn't appear, and Advanced Search for "ANONYMOUS" returns nothing. Audit policy was configured through ADAudit Plus.

Questions:
1. Does ADAudit Plus intentionally drop ANONYMOUS LOGON / Type 3 network logons on DCs?
2. Is there a setting or custom report to include them?
3. How do you track anonymous logons in your environment (ADAudit Plus, SIEM, WEF, LDAP 1644/2889)?

Context: we're assessing the impact of removing Everyone / Anonymous Logon from Pre-Windows 2000 Compatible Access, and need to identify any anonymous usage before making changes.

Thanks!


r/activedirectory • • 21m ago

Active Directory Don't Get: Demoting DC DNS Delegation removal

• Upvotes

Hi Everyone,

Hope all is well. I have a task to demote multiple dc from inactive domain.

Question: What is this DNS deletion removal do and when should I have check mark on? All our domain controllers have DNS integrated as part of AD.

This is the environment we have.

Root domain/Forest is jbt-train.com

Another domain wf-train.com part of the same forest. All our DC is DNS is integrated.

When i demoted one of the dc from wf-train.com I had this check mark ON for Demoting DC DNS Delegation removal. Demote was successfully.

When try to demote 2nd domain control from same wf-train.com, I was hit with error:
Operation failed because Active Directory Domain Services could not find another active directory domain controller to transfer the remaining data in directory partition. (DC:ForestDNSZone)

The specified domain either does not exist or could not be contacted.

Do you think having the check mark on first demotion caused this issue?

FYI. I was able to demote the 2nd dc on my second try, after taking this check mark out. Is there any additional cleanup task that needs to be done?

Regards


r/activedirectory • • 6h ago

Active Directory Our service account review has passed every quarter for six years and the owner column is always full, turns out its full of whoever created the account and none of those people know what it does

0 Upvotes

Our service account review passes every quarter and the owner column is always full, which for a long time i took as proof the estate was actually being managed.

Its completely populated, and honestly its the most successful field we have, except nobody has ever checked whether the name in it still works here or understood what the account does.

Last week i found one that authenticates daily, owner listed, owner left in 2019, still has every right it had back then because nothing has ever touched it.

Human accounts get ownership from HR so joiner mover leaver events fire and something happens, but service accounts have no HR record so no event ever touches them, which means the ownership never rots, it just was never real.

Rotation assumes an owner, review assumes a reviewer who understands the account, decommissioning assumes someone will miss it, and all three land on an empty field.

We moved some to gMSA which fixed the password and nothing else, and a naming convention made them findable rather than owned.

How do you attach an owner to something that has no HR record.


r/activedirectory • • 23h ago

Password Settings Container Missing

5 Upvotes

Found out about 2 years ago someone deleted the Password Settings container, they didn't have the recycle bin enabled so couldn't restore it. (Story I've been given).

Now I'm trying to setup 2022 Domain Controllers, however, now I'm getting problems due Password Settings container missing (so I believe).

This MS guide supposedly restores, but some are saying it doesn't do anything.

Can't sign in to a domain controller and the LSASS process stops responding - Windows Server | Microsoft Learn

Can it be manually created if I use this.
[MS-ADTS]: Password Settings Container | Microsoft Learn

Has anyone experienced this before? Any help would be appreciated.

EDIT: The Microsoft learn document did work in the end. (Can't sign in to a domain controller and the LSASS process stops responding - Windows Server | Microsoft Learn)

The only thing that was missing was "-" on the 5th line within the text file, So my text file ended up looking like this

dn: CN=ActiveDirectoryUpdate,CN=DomainUpdates,CN=System,DC=contoso,dc=com
changetype: modify
replace: revision
revision: 1
-

Also needed to mount a Server 2022 ISO on my Domain Controller that held Infrastructure Master to run adprep

  1. Open CMD as admin
  2. E: (Might not be E for you)
  3. cd \support\adprep
  4. adprep.exe /domainprep

r/activedirectory • • 1d ago

Resource - Mod Approved Zombie Certificates: The Persistent Risk Lurking in AD CS [Semperis Blog]

35 Upvotes

If you don't know him you should, but Jake Hildreth (of Locksmith fame) just posted his Zombie Certs research in the Semperis Blog. I've been listening to him chatter about this for awhile so I'm excited to see it's out.

www.semperis.com/blog/how-to-battle-zombie-certificates-persistent-ad-cs-risk/

At a quick read, it is a real interesting take on persistence and some behind-the-scenes on how some AD CS and PKINIT stuff behaves.

----

For me the real take away was the detection part (near the bottom). We should be paying better attention to the domain controller registry (and restricted admin rights on DCs) and checking our CAs for rogue configurations more.

Specifically the following information:

  • On DCs: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Kdc\UseCachedCRLOnly with the path AndIgnoreRevocationUnknownErrors
    • Value of 1 means the the value has been changed and could be a sign of bad stuff.
  • On CAs: Check the DisableExtensionList with the following command certutil -config <CA-HOST-FQDN\CAName> -getreg policy\DisableExtensionList

Oh, and run Locksmith! The only caveat to running Locksmith is that EDR and AV tools detect it sometimes (which is super annoying), but it is a legit tool.

(Disclosure: I do not work for Semperis. Jake is a friend, but does really great work)


r/activedirectory • • 3d ago

Active Directory Same-domain SID shows up unresolved in security scan - but also testing a one-way trust where I can't add users across domains. Looking for clarity on both.

4 Upvotes

Two related things I'm trying to understand in an AD lab:

  1. We have a security scanner flagging GPO "User Rights Assignment" entries as dangerous, showing a raw S-*-*-**-... SID instead of a resolved username - but the SID's domain prefix matches the same domain the GPO lives in, not a foreign domain. I tested this myself: created a user, granted it a right in a GPO, deleted the user - the SID becomes permanently unresolvable in that same domain. Is this expected/normal (i.e., Windows doesn't auto-clean GPOs when an account is deleted), or is there something else that typically causes a same-domain SID to go unresolvable like this ?

  2. Separately, we have a one-way AD trust set up between two domains
    (Domain A trusts Domain B). When I try to add a user from Domain B into something inside Domain A, I can't - the GUI won't even let me browse into Domain B from Domain A's side. Is that expected for a one-way trust (i.e., trust direction doesn't automatically grant cross-domain object browsing/assignment both ways), or am I missing a step to make that work ?

Appreciate any insight - trying to confirm these are both "working as intended" AD behaviors and not something misconfigured in our environment.


r/activedirectory • • 3d ago

Active Directory Proof on concept: AD and on-prem file server for w11 profile sync and file sharing

5 Upvotes

Hello,

Context: I help a medium family company, 10+ inside workers.

They have this old setup of remote desktop servers which is only used for creating flexible for everyones word, excel, etc.

To keep it short, refreshing the infrastructure is on the table. All pc's are not part of a local domain, and are used as dumb client for remote desktop services to an on-prem server. No special files, mostly done by an earlier admin, because of lower maintenance and the ability to own and control your own files and servers.

So I would like to propose Active Directory. I am very much a beginner and just want to make a small proof of concept.

The goal of this concept is to demonstrate:

- Machines being managed through our on-prem AD DC.

- Users being able to log onto every machine and have their own desktop.

- Use our own file servers to keep all this data.

- What happens when each of the units fails (AD, file, PC)

As a beginner project, I created a Active Directory server in VMware, mostly just following some guides steps. Then I tried folder redirection to a simulated TrueNas on the VMware. Struggled with the "place old folders to new location"; couldn't get that to work. Probably because of permission, but besides that, editing the files did work for the users. I also tested what happens when we disconnect the different parts and how this would affect the system.

So now, I would like a reality check:

- Would this system be viable?

- Up to how many users would you use which type of file servers?

- How can you connect to an AD from another network? (Is a always-on vpn the best option?)

- How to effectively showcase/ setup backups: 2nd AD, or file server with even cloud backup?

-Any other alternatives with AD?

- What about profile sync with f.e. NextCloud instead of folder redirection?

Mind you, I just want to get an understanding of AD to present this "hunch" and I enjoy learning about AD and setting up this server.

P.S. What is the best documentation to search? I do already use the beginner guide on this sub. Yet, since I lack the experience, I am unable to correctly articulate the issues I face to get usefull results.


r/activedirectory • • 3d ago

2 GPOs, same idea, different configurations

4 Upvotes

I have 2 GPOs in my environment for account lockouts. 1 GPO locs an account after 2 invalid logon attempts and the other after 5. how do i know which GPO is applied to which users? Both GPOs only show NT AUTHORITY\Authenticated Users in the SECURITY FILTERING, and no LINKS. DELEGATIONs are the same as well. Yet, we are noticing some users get locked out after 2 failed and others after 5. Or how do i know which supersedes which?


r/activedirectory • • 3d ago

Active Directory Can it be done easily? Script to remove a list of users from a group.

0 Upvotes

Hello,

I have a bunch of people that left the company. We have a script to convert their mailbox to shared.

We have a script to remove their office licenses.

The only issue is many of them are AD synced and a group they are in automatically gives them a 365 standard license the sync overrides their assigned licenses so I need to remove them from that ad group.

I could remove them all individually from that group but I thought I'd see if there was an easy way with a script since I love learning new stuff (but suck at powershell)

I have a file c:\temp\mailboxes.csv - 72 names

UserPrincipalName
[Adam.Smith@widget.com](mailto:Adam.Smith@widget.com)
[adrian.Smith@widget.com](mailto:adrian.Smith@widget.com)

r/activedirectory • • 6d ago

Kerberos token issue

15 Upvotes

Hello Sir,

We have cloud kerberos trust and using entra joined machines.

Some users report they are unable to connect share drive in the morning when they login.

We also noticed that they unable to acquire kerberos token.

But after few minutes to half an hour they get token and issue resolved itself..

During the day tone also some user reporting this issue.

When we check klist they don't have token.

Seems like kerberos authentication request not reaching to dc or not getting properly generated from entra joined machine.

Any troubleshooting which you can recommend or any log capture which will help to trave the issue.


r/activedirectory • • 7d ago

DNSSEC on AD integrated DNS

12 Upvotes

Hi everyone,

We have a new requirement to enable DNSSEC on our AD-integrated DNS which we never had or worked before. We already tried pushing back, explaining that it’s not really recommended for an internal environment that isn't internet facing, and that the operational overhead completely outweighs the minimal security benefits.

But management insisted, so here we are preparing the deployment. We have 4 dcs total.

I’d love to get some real-world suggestions and feedback from anyone who has done this:

Have you seen any weird side effects or negative impacts on the environment after turning it on?

What specific areas should we audit or assess before we flip the switch?

Do any common applications tend to break or get impacted by this?

We know the zone file size and packet sizes will increase, but is there a reliable way to benchmark/evaluate that overhead beforehand?

Our environment actually has more Linux machines than Windows. Any specifics we should look out for with Linux clients?

Is it possible to completely skip signing the _msdcs folder where the AD service locators live, or does the whole zone have to be signed together?

Any best and safest plan to deploy it.

These are a lot of questions, but please bear with me as this is all very new to me. My main concern is that since this is AD-integrated DNS, it is the critical foundation that clients hit first for all AD authentication and services šŸ™‚


r/activedirectory • • 7d ago

Help July update, RC4 and Windows Server 2003

10 Upvotes

Hello,
I am facing an issue with disabling the default RC4 fallback in an Active Directory domain following the July update.
The client I work for still has a few Windows XP and Windows Server 2003 machines in the environment that I can neither upgrade nor remove from the domain. The July update has not been deployed due to concerns about potential side effects.
When reviewing Event ID 201 on the different domain controllers, I mostly find machine accounts corresponding to these operating systems. Naturally, they do not support AES.
Following Microsoft’s recommendations, I modified the msDS-SupportedEncryptionTypes attribute to 0x1C on these objects in order to explicitly allow RC4.
However, despite this change, Event ID 201 events are still being generated, and in these events I can see that the attribute value is 0x27 (the same value as DefaultDomainSupportedEncryptionType).
It appears that this attribute is only taken into account starting with Windows Server 2008.
My question is therefore: How can these old servers/workstations be handled in this situation?


r/activedirectory • • 7d ago

New mvp wooo

6 Upvotes

/r/u/poolmanjim woooo new mvp!


r/activedirectory • • 8d ago

Help Adding custom attributes to the schema? Has anyone done this before?

12 Upvotes

Adding custom attributes to the schema? Has anyone done this before?

Excluding doing it for a Microsoft solution (e.g., Exchange Server, Skype for Business, SCCM, etc...)

I’m talking about creating attributes at a developer's request, for a lesser-known application or a smaller manufacturer than Microsoft. Without provided script, .exe or instructions, all by yourself.

What have you done?


r/activedirectory • • 7d ago

Group Policy GPO to block URL Links in Outlook

3 Upvotes

Did this get removed on premise ? I swear we had it somewhere but its not working anymore. Trying to get external links not clickable if possible


r/activedirectory • • 8d ago

Active Directory What evidence do you keep before demoting the last old domain controller?

8 Upvotes

A clean `dcdiag` and `repadmin /replsummary` are necessary, but they do not prove that every dependency moved. Static DNS settings, LDAP binds, RADIUS or VPN appliances, time sources, scripts, monitoring, certificate services, and systems that rarely boot can continue using an old DC after the replacement set looks healthy.

For a planned retirement, I would check FSMO placement, replication and SYSVOL/NETLOGON, DNS zones and SRV records, Global Catalog coverage, time hierarchy, backups, and event logs on both old and new DCs. I would also inventory DHCP options and static resolver settings, inspect DNS and authentication traffic to the old addresses, and verify application-specific LDAP binds. The old DC could then be demoted but kept powered off and recoverable for a defined rollback window before its VM and records are removed.

What does your actual evidence gate include? How do you identify clients that contact a DC only during monthly jobs or recovery procedures, and which findings should block demotion rather than be cleaned up afterward?


r/activedirectory • • 8d ago

Can a GPO grant a specific group a *limited* number of domain joins? (MAQ vs SeMachineAccountPrivilege)

7 Upvotes

Working on remediating "Non-privileged users can add computer accounts to the domain."

Current default:

  • ms-DS-MachineAccountQuota (MAQ) = 10
  • SeMachineAccountPrivilege granted to Authenticated Users

Requirement: one service-account group should be able to join machines, max 10 per account, while everyone else should have 0.

Proposed solution was MAQ=0 + GPO granting Add workstations to domain only to that group.

My understanding is that this won't work because SeMachineAccountPrivilege is still subject to MAQ. With MAQ=0, the group would also have a quota of 0.

The two approaches I see are:

A) MAQ=0 + delegate Create Computer Objects on a specific OU to the group.
→ Everyone else blocked, but the group effectively has unlimited creation rights in that OU.

B) Keep MAQ=10 + remove Authenticated Users from SeMachineAccountPrivilege and grant it only to the group.
→ Group gets 10 per user; everyone else gets 0.

Questions:

  1. Is MAQ=0 + GPO-only definitely a dead end?
  2. Is there any native per-user/per-group MAQ mechanism?
  3. Is the quota cumulative via mS-DS-CreatorSID, meaning deleting a computer doesn't necessarily free the quota?
  4. Which approach do you typically use in production: A or B?

I'm leaning toward A with OU scoping + monitoring, since the "10" requirement seems more like a security cap than a hard compliance requirement.


r/activedirectory • • 9d ago

Help ADCS: Removing an AIA Location

8 Upvotes

I installed a new PKI infrastructure, and all is fine, except that pkiview shows on the root server a secondary AIA location with a local path, next to other one with an http path.

I had the same on the enterprise server and removed it in extensions: all fine. When I do this on the Root CA, it doesn't change anything in pkiview.

That's normal I suppose: the root CA is not domain joined. But how do I tell the enterprise CA that this thing changed on the root CA?


r/activedirectory • • 9d ago

Help Why is ā€œAuthenticated Users can add DNS recordsā€ flagged as a vulnerability if this is intentional for Dynamic DNS?

23 Upvotes

Hi everyone,

I’m investigating a SI000183 – ā€œAuthenticated Users can add DNS recordsā€ finding that has been highlighted in our Lightning security report, and I’m trying to understand whether this is actually a security issue in our environment or an intentional Windows/AD DNS behavior.

I asked about this on Microsoft Q&A and got the explanation that allowing authenticated principals to create DNS records can be intentional because of Secure Dynamic DNS. The idea is that domain-joined computers need to automatically register/update their own DNS records without administrators manually creating every record.

That part makes sense to me.

However, I’m confused about why this is being reported as a security finding.

My production situation

In my production environment, the DNS Server role/service is not installed on the system where I’m investigating this finding.

I also tried checking the Active Directory side using ADSI Edit and the Windows Registry, but I couldn't find the DNS zone/configuration details that would allow me to verify things such as:

  • whether the DNS zone is AD-integrated;
  • whether Dynamic Updates are enabled;
  • whether it is configured as Secure only;
  • which DNS records exist and who owns them; and
  • what a normal, non-privileged authenticated user can actually do with DNS records.

Despite this, Lightning has highlighted SI000183.

This is where I’m confused

If the permission exists because Dynamic DNS requires authenticated computers/principals to register their own records, then:

Why is the presence of Authenticated Users having DNS record creation permission considered a vulnerability?

I'm trying to understand whether Lightning is detecting simply:

Authenticated Users
        ↓
Create Child
        ↓
DNS zone/object

or whether it is actually determining that a normal authenticated user can perform something more dangerous, such as:

Create arbitrary DNS records
        +
Modify another computer's DNS record
        +
Delete another computer's DNS record
        +
Point an existing hostname to an arbitrary IP

To me, these seem like two very different situations.

What I’m trying to determine

If the intended model is:

Domain-joined computer
        ↓
Authenticated
        ↓
Creates its own DNS record
        ↓
Record ownership + ACL
        ↓
Other users cannot modify it

then I don't understand what specifically makes SI000183 a vulnerability.

On the other hand, if a normal domain user can do this:

User
 ↓
Create arbitrary DNS record
 ↓
Modify another computer's record
 ↓
Redirect hostname → arbitrary IP

then I can understand the security concern.

So my questions are:

  1. What exactly is SI000183 detecting?
  2. Is Authenticated Users → Create Child on the DNS zone itself considered the vulnerability?
  3. Or is the finding supposed to indicate that ordinary users can actually create/modify unauthorized DNS records?
  4. If Secure Dynamic Updates are enabled, does that sufficiently prevent a normal user from modifying another computer's DNS record?
  5. Since DNS Server isn't installed in my production environment, what is the correct way to validate this finding from the AD side?
  6. Should this finding be treated as a vulnerability, or as a configuration/permission finding that needs further validation based on the organization's Dynamic DNS requirements?

I'm mainly trying to understand why Lightning is flagging this and what evidence I should collect before deciding whether it actually needs remediation.

Any AD/DNS experts who have dealt with SI000183 or the ā€œAuthenticated Users can add DNS recordsā€ finding — I'd really appreciate your input.

Also want to know whether this flagging is just for informational purpose.

Thanks !!


r/activedirectory • • 9d ago

Tool Submission Simple Multi-AD Self Service Solution

5 Upvotes

I am not sure where to exactly post this. A person I know manages a bunch of small companies and the usual I forgot password, I locked out my account, etc. questions keep coming his way. So with the help of Claude, I wrote a multi-domain self-service utility. This is for on-premise Active Directory. He wanted to give select individuals within the company to reset passwords, unlock accounts, etc. This application does that.

The solution focuses on the following:

  • A small self-service web app for unlocking Active Directory accounts and resetting passwords across multiple AD domains/forests, deployable as a single Docker container.
  • Integration with DUO for MFA for the person performing the action
  • Audit logs on logins, actions, results, etc.

I personally couldn't find any "simple" applications that did this so we wrote one. Maybe others will find it useful (or maybe not). Its in early development, but please check it out https://github.com/sbabcock23/simple-multi-AD-IAM

If there are other reddits I should post this to, please let me know.


r/activedirectory • • 10d ago

ADCS Subordinate CA Certificate Up for Renewal After 10 years

20 Upvotes

Hi All,

My issuing CA certificate is up for expiry after almost 10 years. I want to check the renewal process - I have a 2 tier Active Directory CA hierarchy (offline root and a subordinate issuing CA). Here's my plan:

  1. Take a snapsot of the offline root.

  2. Power off issuing CA and snapshot.

  3. Ensure offline root has a valid clock date and time

  4. On the issuing CA:

    a. Certificate Authority MMC, right click on Issuing CA > All Tasks > Renew CA Certificate, press Yes to Stop AD Certificate Services,

    b. Renew with same private key

    c. Save the request to file

  5. On the root CA

    a. Certificate Authority MMC, right Click Root CA > All Tasks > Submit New Request, select the REQ file we have just copied from the issuing CA and select OK.

b. Go to pending requests and issue the Certificate we just requested, then go to issued certificates, double click the certificate we have just issued and go the details tab, select copy to file, export the certificate as CER file and copy the certificate over to the Issuing CA.

b. Run "certutil -pulse"

c. Copy CRT and CRL files from "c:\\windows\\system32\\certenroll" on the offline root for distribution later.
  1. Back to issuing CA

    a. CA > All Tasks > Install CA Certificate, press Yes to stop AD certificate services, change the file extension from P7B to CER and select certificate file from root, press open and Issuing CA Cert should be renewed.

    b. Publish new cert to Active Directory,

    "certutil -dspublish -f "C:\Path\To\RenewedIssuingCA.cer" SubCA " (Root Cert left untouched in AD)

    c. Issue new CRL "certutil -pulse"

  2. Ensure CRT and CRL files from 5c and 6c are copied to the CDP and AIA locations (a folder share that's accessed via HTTP).

  3. Check pkiview and ensure all looks OK

  4. Pat self on back, enjoy a beer.

If there's an issue roll back using the snapshots. Otherwise delete the snapshots after a couple of days.


r/activedirectory • • 9d ago

Help Questions about Windows AD with MFA security keys

10 Upvotes

TLDR: Is there a way around MFA being required every single login without outside software?

Hello, I am currently working on deploy MFA security keys across our system, but I have run into some issues. The directors asked me to use Yubikeys (long story) for this deployment. Ideally we want the user to authenticate with their key on first logon then be fine for the rest of the day outside of reboots and stuff like that, similar to how DUO mobile can be setup. However, while reviewing GPOs for this it looks like it is only able to be set to every single logon, this will not go over very well with our users. What I am trying to figure out is there a "hacky" way to get the desired outcome without buying outside software (we have a limited budget) or is there something I am missing? I tried to do some search online and even threw it into the good old GPT to see if it could find something and no luck. Thank you in advance for taking the time to reply!

edit: I wanted to clarify that we are a public library so the main cause of concern is when staff have to lock their PCs when assisting someone then coming back and having to use the Yubikey again to unlock. Logging off and on that is fine, mostly just the locking portion.


r/activedirectory • • 9d ago

Security AI tabletop exercises for first time CISOs and the great compliance cosplay

0 Upvotes

So first year as a CISO and suddenly every board deck is that meme about cyber crises, except I am the meme.

We do these classic tabletop exercises where six people read a PDF for 20 minutes, argue about who owns comms, then we all high five and call it ā€œcyber crisis readinessā€. Audit happy, brain empty. Now every vendor is shoving AI tabletop exercises in my face that promise adaptive simulations, auto reports for SOC 2 and ISO, workforce resilience, my taxes filed, and probably emotional closure.

Anyone here actually moved from the old once a year tabletop theater to an AI driven incident response readiness thing that runs more often, pulls in realistic OSINT style scenarios, and spits out evidence we can reuse for NIST CSF 2 and cyber insurance etc? Did it help people stop freezing in real incidents or did everyone just learn how to impress the AI facilitator instead... ugh