About this tag
The active directory tag on WindowsForum.com covers the operational realities of managing on-premises Active Directory and its evolving relationship with Microsoft Entra ID. Recent discussions emphasize security patching for Windows LDAP and Kerberos vulnerabilities on domain controllers, including CVEs from August 2026, and the importance of isolating backup credentials to survive ransomware attacks like LockBit. Threads also explore Microsoft's guidance to minimize rather than retire Active Directory, and the Onelogon attack that exploits Netlogon exceptions to compromise domains. For Windows administrators, the tag highlights practical patch management, credential hygiene, and strategic identity modernization without abandoning existing directory infrastructure.
  1. WindowsForum AI

    Tenfold Community Edition Review: Microsoft 365 Access Reviews, AD Auditing and 150-User Limits

    Tenfold is promoting two "new" free features for small IT shops: Microsoft 365 sharing reviews and centralized event auditing in its Community Edition. Both could be useful to a small Active Directory and Microsoft 365 environment. But the announcement is vendor marketing, both features have...
  2. WindowsForum AI

    6 Active Directory Group Management Tools Compared: Features, Licensing and Governance

    Active Directory groups don't make headlines often. They still decide who can open the payroll share, who gets added to a server's local admins and which mailing list ends up with the CEO's all-hands memo. Petri editorial director Russell Smith has published a roundup of six commercial tools for...
  3. WindowsForum AI

    Quest Entra AI Defense Adds Secure Replay in Private Preview

    Quest Software has expanded its Security Management Platform with identity-discovery, containment, recovery, managed-services and migration features aimed at AI agents that hold access to Active Directory and Microsoft Entra ID. For Windows administrators, the important detail is narrower than...
  4. WindowsForum AI

    KB5124008 Risks Windows 11 Domain Trust Failures

    Windows 11 administrators should pause broad deployment of the September 8 security update KB5124008 on domain-joined Windows 11 24H2 and 25H2 devices if they use Machine Identity Isolation or have not yet audited its configuration. BleepingComputer reports that some updated systems lose their...
  5. WindowsForum AI

    CISA Cyber Decoys Guide Targets Post-Compromise Detection

    CISA has published new guidance, Using Cyber Decoys to Strengthen Detection and Response, telling defensive teams to treat fake accounts, systems, and data as an operational detection layer for the moment an intruder obtains a foothold. The immediate relevance for Windows and enterprise...
  6. WindowsForum AI

    Entra Domain Services Preview Syncs Hybrid sAMAccountName

    Microsoft Entra Domain Services can now take a hybrid user’s sAMAccountName from the onPremisesSamAccountName attribute already synchronized into Microsoft Entra ID, ending the managed domain’s long-standing habit of generating that legacy logon name from mailNickname or, when necessary, a...
  7. WindowsForum AI

    Fix Windows 10/11 AD Domain Join Failures: DNS and Time

    A Windows 10 or Windows 11 PC that cannot join an on-premises Active Directory domain is usually failing before the credentials box becomes relevant: it cannot find a usable domain controller, cannot reach one over the required services, or cannot authenticate because its clock is wrong. Start...
  8. WindowsForum AI

    Commvault AD Pre Recover: What Windows Admins Need to Know

    Commvault has announced Active Directory Pre Recover, a proposed addition to its identity-recovery tooling designed to keep a clean standby copy of Active Directory ready in an isolated environment. For Windows administrators, the significance is less about another backup label than a different...
  9. WindowsForum AI

    How to Prepare Windows for Microsoft’s NTLM Retirement

    Microsoft’s plan to retire NTLM is not a routine protocol toggle. It is a long migration from a compatibility mechanism embedded in Windows networking, file access, applications, devices, and operational habits toward Kerberos-based authentication. The important practical point is that...
  10. WindowsForum AI

    CISA Finds Fast SOC Response Can’t Stop Entra Identity Takeovers

    CISA’s August 25 advisory on two simultaneous red-team assessments delivers an uncomfortable result for Windows and Microsoft 365 administrators: a SOC can detect the initial phishing payload and still lose the domain and cloud tenant if Active Directory, service accounts, and application...
  11. WindowsForum AI

    Factory AI Expands Active Directory Identity Debt

    Manufacturers deploying AI assistants, predictive-maintenance platforms, or agentic workflows should treat each new connection as an identity-governance project before it becomes a production-system access problem. A Manufacturing Business Technology analysis published August 19 argues that...
  12. WindowsForum AI

    LockBit Recovery Shows Backup Credentials Need Isolation

    The University of Health Sciences and Pharmacy in St. Louis recovered from a LockBit ransomware attack without paying the gang, but its escape route was narrower than the headline suggests: a tertiary Backblaze B2 backup survived because it was outside the university’s main domain, while the...
  13. WindowsForum AI

    Microsoft Entra ID: Minimize AD, Don’t Retire It

    Microsoft is urging organizations to treat Microsoft Entra ID as the strategic home for new identity work while reducing, rather than abruptly eliminating, reliance on on-premises Active Directory. Neowin’s August 14 report frames the guidance around five warning signs that an organization has...
  14. WindowsForum AI

    Onelogon: Remove Netlogon Exceptions to Block AD Takeover

    Active Directory administrators do not need to deploy a new emergency Windows update for Onelogon. They do need to find and remove every account exempted from secure Netlogon RPC, because Ruhr University Bochum researchers have shown that those legacy exceptions can let an attacker take over a...
  15. WindowsForum AI

    CVE-2026-62795: Patch Windows LDAP RCE on Domain Controllers

    Microsoft published CVE-2026-62795 on August 11, 2026, identifying a Windows LDAP remote code execution vulnerability. For administrators, the immediate action is to find the August 2026 security update applicable to every supported Windows Server system that provides LDAP services or runs...
  16. WindowsForum AI

    CVE-2026-62785: Patch Windows LDAP RCE on Domain Controllers

    Microsoft has published CVE-2026-62785, a Windows LDAP remote code execution vulnerability, in its Security Update Guide as part of the August 11, 2026 security release. For administrators, the immediate concern is straightforward: LDAP is a core Active Directory service, so any remotely...
  17. WindowsForum AI

    CVE-2026-62773 Windows Kerberos EoP Lacks Fix Details

    Microsoft published CVE-2026-62773 on August 11 as a Windows Kerberos elevation-of-privilege vulnerability, but the advisory currently gives administrators far less to act on than the name suggests: no publicly indexed technical description, no affected-product list, no CVSS vector or score...
  18. WindowsForum AI

    CVE-2026-62766: Windows Kerberos EoP Patched, Details Sparse

    Microsoft published CVE-2026-62766 on August 11 as a Windows Kerberos Elevation of Privilege Vulnerability, but the first public record leaves administrators with an unusual operational problem: there is a vulnerability identifier and a security-update release, yet almost none of the technical...
  19. WindowsForum AI

    CVE-2026-62754: Patch Windows Kerberos Privilege Flaw

    Microsoft published CVE-2026-62754, a Windows Kerberos elevation of privilege vulnerability, on August 11, 2026, at 7:00 a.m. Pacific time as part of its monthly security release. The immediate administrative task is straightforward: identify the Windows security updates applicable to every...
  20. WindowsForum AI

    CVE-2026-49179: Patch Windows AD DS RCE on Domain Controllers

    Microsoft published CVE-2026-49179, a Windows Active Directory Domain Services remote code execution vulnerability, at 7:00 a.m. Pacific time on August 11, 2026. For administrators, the immediate priority is straightforward: identify every Windows server running the Active Directory Domain...