TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The Lack of Native MFA for Active Directory Is a Big Sin for Microsoft

3 pointsby bozhoover 2 years ago

1 comment

technionover 2 years ago
Security comes up on HN a lot, but I&#x27;m amazed this particular issue never really seems to. For nearly any major incident write up, you&#x27;ll see the same old story. Attacker obtained administrative credentials, abused them on a domain controller to own the whole network. Most recent example:<p><a href="https:&#x2F;&#x2F;blog.talosintelligence.com&#x2F;2022&#x2F;08&#x2F;recent-cyber-attack.html" rel="nofollow">https:&#x2F;&#x2F;blog.talosintelligence.com&#x2F;2022&#x2F;08&#x2F;recent-cyber-atta...</a><p>For a company that keeps blogging about the need for MFA[0], to have the major product they&#x27;ve been riding on for 20 years not support any reasonably manageable MFA truly can&#x27;t be understated.<p>I do think one of the issues here is people misunderstanding the problem. Internet forums are awash with people asking about &quot;MFA on Active Directory&quot;, and the answer is usually in the form of third party plugins for RDP connectors. But RDP is only one way to access and damage a domain.<p>[0] <a href="https:&#x2F;&#x2F;www.microsoft.com&#x2F;security&#x2F;blog&#x2F;2020&#x2F;03&#x2F;03&#x2F;single-sign-on-sso-multi-factor-authentication-mfa&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.microsoft.com&#x2F;security&#x2F;blog&#x2F;2020&#x2F;03&#x2F;03&#x2F;single-si...</a>