TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The Lack of Native MFA for Active Directory Is a Big Sin for Microsoft

3 点作者 bozho将近 3 年前

1 comment

technion将近 3 年前
Security comes up on HN a lot, but I&#x27;m amazed this particular issue never really seems to. For nearly any major incident write up, you&#x27;ll see the same old story. Attacker obtained administrative credentials, abused them on a domain controller to own the whole network. Most recent example:<p><a href="https:&#x2F;&#x2F;blog.talosintelligence.com&#x2F;2022&#x2F;08&#x2F;recent-cyber-attack.html" rel="nofollow">https:&#x2F;&#x2F;blog.talosintelligence.com&#x2F;2022&#x2F;08&#x2F;recent-cyber-atta...</a><p>For a company that keeps blogging about the need for MFA[0], to have the major product they&#x27;ve been riding on for 20 years not support any reasonably manageable MFA truly can&#x27;t be understated.<p>I do think one of the issues here is people misunderstanding the problem. Internet forums are awash with people asking about &quot;MFA on Active Directory&quot;, and the answer is usually in the form of third party plugins for RDP connectors. But RDP is only one way to access and damage a domain.<p>[0] <a href="https:&#x2F;&#x2F;www.microsoft.com&#x2F;security&#x2F;blog&#x2F;2020&#x2F;03&#x2F;03&#x2F;single-sign-on-sso-multi-factor-authentication-mfa&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.microsoft.com&#x2F;security&#x2F;blog&#x2F;2020&#x2F;03&#x2F;03&#x2F;single-si...</a>