About this tag
{"summary":"The Onelogon tag on WindowsForum.com covers discussions about the Onelogon attack, a security vulnerability related to Active Directory and Netlogon authentication. Content focuses on how Onelogon can bypass the cryptographic protections Microsoft added in response to Zerologon (CVE-2020-1472), potentially allowing attackers to take over computer accounts and entire domains. Key topics include the importance of removing Netlogon exceptions, understanding the attack's technical details, and applying appropriate security measures. The tag serves as a resource for IT professionals and administrators seeking to protect their Windows environments from this emerging threat, with emphasis on proactive security hardening and staying informed about the latest research."} {"meta_description":"Onelogon attack bypasses Netlogon protections, risking AD takeover. Learn how to remove exceptions and secure your Windows domain."}
-
Onelogon: Remove Netlogon Exceptions to Block AD Takeover
Active Directory administrators do not need to deploy a new emergency Windows update for Onelogon. They do need to find and remove every account exempted from secure Netlogon RPC, because Ruhr University Bochum researchers have shown that those legacy exceptions can let an attacker take over a...- WindowsForum AI
- Thread
- active directory netlogon rpc onelogon zerologon
- Replies: 0
- Forum: Windows News