# active directory

Published articles for active directory.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## How Does CockroachDB Automate SQL User Lifecycle Management?

DevFeed: [How Does CockroachDB Automate SQL User Lifecycle Management?](<https://devfeed.tech/articles/how-does-cockroachdb-automate-sql-user-lifecycle-management-23818.md>)

Original publisher: [Read original article](<https://cockroachlabs.com/blog/sql-user-lifecycle-management-automation>)

Author: Pritesh Lahoti,Biplav Saraf,Sourav Sarangi

Published: 2026-08-28T00:00:00Z

Content type: tutorial

Language: en

Sources: [Cockroach Labs](<https://devfeed.tech/sources/cockroach-labs.md>)

Topics: [CockroachDB](<https://devfeed.tech/topics/cockroachdb.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [okta](<https://devfeed.tech/topics/okta.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [cockroachdb](<https://devfeed.tech/tags/cockroachdb.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [okta](<https://devfeed.tech/tags/okta.md>)

### AI overview

The article addresses how CockroachDB automates SQL user lifecycle management and notes that large enterprises commonly rely on identity provider and identity and access management platforms such as Okta, Microsoft Entra ID, Microsoft Active Directory, and Ory.

### Source excerpt

Fortune 1000 enterprises widely rely on major Identity Provider (IdP) and Identity and Access Management (IAM) platforms like Okta, Microsoft Entra ID, Microsoft Active Directory, and Ory.

## What SPIFFE Answers for Workload Identity and What It Doesn't

DevFeed: [What SPIFFE Answers for Workload Identity and What It Doesn't](<https://devfeed.tech/articles/what-spiffe-answers-for-workload-identity-and-what-it-doesn-t-29859.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/spiffe-workload-identity/>)

Author: info@goteleport.com (Rob Cobbins)

Published: 2026-05-29T00:00:00Z

Content type: opinion

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [SPIFFE](<https://devfeed.tech/topics/spiffe.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [passwd](<https://devfeed.tech/topics/passwd.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [saml](<https://devfeed.tech/topics/saml.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [aws](<https://devfeed.tech/tags/aws.md>), [identity](<https://devfeed.tech/tags/identity.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [passwd](<https://devfeed.tech/tags/passwd.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [saml](<https://devfeed.tech/tags/saml.md>), [spiffe](<https://devfeed.tech/tags/spiffe.md>)

### AI overview

This article examines what SPIFFE provides for workload identity and where it falls short. It argues that SPIFFE offers a sound way for machines to prove their identities without shared secrets, but does not define authorization and leaves workload registration largely to implementations.

### Source excerpt

Learn about the workload identity questions SPIFFE can't answer and considerations for filling gaps in the spec.

## Native Windows automation without Docker, WSL, or workarounds

DevFeed: [Native Windows automation without Docker, WSL, or workarounds](<https://devfeed.tech/articles/native-windows-automation-without-docker-wsl-or-workarounds-30728.md>)

Original publisher: [Read original article](<https://www.windmill.dev/blog/windows-workflow-engine>)

Author: Alex Petric

Published: 2026-04-29T00:00:00Z

Content type: article

Language: en

Sources: [Windmill Blog](<https://devfeed.tech/sources/windmill-blog.md>)

Topics: [Windows](<https://devfeed.tech/topics/windows.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [C#](<https://devfeed.tech/topics/csharp.md>), [servers](<https://devfeed.tech/topics/servers.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [ai](<https://devfeed.tech/tags/ai.md>), [automation](<https://devfeed.tech/tags/automation.md>), [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [database](<https://devfeed.tech/tags/database.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [servers](<https://devfeed.tech/tags/servers.md>), [windows](<https://devfeed.tech/tags/windows.md>), [windows-enterprise-powershell-ai](<https://devfeed.tech/tags/windows-enterprise-powershell-ai.md>)

### AI overview

This article explains how Windmill automates Windows servers as a native Windows service. It covers PowerShell, C#, SQL and MSSQL Kerberos authentication, Active Directory access, mixed Windows/Linux workers, approval workflows, and audit trails without requiring Docker or WSL2.

### Source excerpt

How do I automate Windows servers without Docker? Windmill runs natively on Windows as a service with PowerShell, C#, MSSQL Kerberos auth, and Teams integration.

## Кто выпустил гончую. Ищем следы коллекторов BloodHound в логах Windows

DevFeed: [Кто выпустил гончую. Ищем следы коллекторов BloodHound в логах Windows](<https://devfeed.tech/articles/bloodhound-windows-23068.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/kaspersky/articles/1027132/>)

Author: StepVolg ("Лаборатория Касперского")

Published: 2026-04-24T12:37:53Z

Content type: tutorial

Language: ru

Sources: ["Лаборатория Касперского" RU](<https://devfeed.tech/sources/ru-2.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [SOC](<https://devfeed.tech/topics/soc.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [bloodhound](<https://devfeed.tech/tags/bloodhound.md>), [enumerate](<https://devfeed.tech/tags/enumerate.md>), [red-teaming](<https://devfeed.tech/tags/red-teaming.md>), [sharphound](<https://devfeed.tech/tags/sharphound.md>), [siem](<https://devfeed.tech/tags/siem.md>), [soc](<https://devfeed.tech/tags/soc.md>), [windows](<https://devfeed.tech/tags/windows.md>), [windows-1ad1db2b7e3a](<https://devfeed.tech/tags/windows-1ad1db2b7e3a.md>)

### AI overview

The article examines traces left by BloodHound collectors in Windows logs and discusses detecting Active Directory reconnaissance activity.

### Source excerpt

Служба каталогов Active Directory остается одной из самых популярных целей как среди злоумышленников, так и среди специалистов по Red Teaming и пентестеров. С выходом новых версий операционных систем семейства Windows продолжают появляться новые векторы атак на AD, например атаки на Delegated Managed Service Accounts (dMSA) в 2025-м. В ходе каждой атаки есть этап сбора информации, обнаружение которого является более сложной задачей, чем кажется на первый взгляд. Согласно аналитическому отчету нашего сервиса MDR за 2025 год в целом обнаружение данного этапа атак затруднено из-за большого количества ложных срабатываний, что снижает качество обнаружения и уменьшает вероятность предотвращения атаки, особенно в больших инфраструктурах с тысячами активов. Меня зовут Степан Ляхов, я работаю старшим инженером SOC в "Лаборатории Касперского". В этой статье я хочу рассмотреть один из самых популярных инструментов для сбора информации о домене Active Directory, разобрать, какие следы он оставляет в журналах и как обнаружить его активность. Читать далее

## Meet Keycloak at FOSDEM on Jan 30/Feb 01!

DevFeed: [Meet Keycloak at FOSDEM on Jan 30/Feb 01!](<https://devfeed.tech/articles/meet-keycloak-at-fosdem-on-jan-30-feb-01-31751.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2026/01/preparing-fosdem-2026>)

Author: Alexander Schwartz

Published: 2026-01-26T00:00:00Z

Content type: news

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [FOSDEM](<https://devfeed.tech/topics/fosdem.md>), [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [active-directory](<https://devfeed.tech/tags/active-directory.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [fosdem](<https://devfeed.tech/tags/fosdem.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [oauth-2-0](<https://devfeed.tech/tags/oauth-2-0.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openid](<https://devfeed.tech/tags/openid.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak will participate in FOSDEM 2026 in Brussels through a co-hosted Sovereign Identity stand and related identity and access management talks. The article provides event, stand, and schedule details.

### Source excerpt

FOSDEM is a free event for software developers to meet, share ideas and collaborate. Every year, thousands of developers of free and open source software from all over the world gather at the event. Several Keycloak related talks happen at FOSDEM in Brussels on January 31st and February 1st, and meet us and help out at the stand. To get the latest updates, subscribe to our discussion on GitHub. Meet the community at the Sovereign Identity stand On Saturday, January 31st 2026, the Keycloak project will co-host the "Sovereign Identity for server, desktop, and a cloud" stand together with the FreeIPA, SSSD and OpenWallet project. We'll be open from 1000 in the morning until around 1800 in the early evening. We will be at K building on level 1 in group C. Visit this stand to interact with the teams of several popular solutions in this space. Keycloak Extensible self-hosted Single-Sign-On for your applications. Supporting Passkeys, OpenID Connect, OAuth 2.0, SAML 2.0 and Kerberos. Integrating with other Identity Providers through brokerage via SAML or OpenID Connect, or via LDAP. FreeIPA Manage Linux users and client hosts in your realm from one central location, define Kerberos authentication and authorization policies for your identities, create mutual trust with other Identity Management systems. Issue certificates to your users and services. SSSD Open Source Client for Enterprise Identity Management. Enroll your Linux machine into an Active Directory, FreeIPA or LDAP domain. Use remote identities, policies and various authentication and authorization mechanisms to access your computer. OpenWallet Foundation We drive global adoption of open, secure and interoperable digital wallet solutions. We set best practices for digital wallet technology through collaboration on standards-based OSS components that issuers, wallet providers and relying parties can use to bootstrap implementations that preserve user choice, security and privacy. Talks about Keycloak and related top

## Kerberoasting

DevFeed: [Kerberoasting](<https://devfeed.tech/articles/kerberoasting-29092.md>)

Original publisher: [Read original article](<https://blog.cryptographyengineering.com/2025/09/10/kerberoasting/>)

Author: Matthew Green

Published: 2025-09-10T12:00:00Z

Content type: opinion

Language: en

Sources: [Matthew Green](<https://devfeed.tech/sources/matthew-green.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [computer](<https://devfeed.tech/tags/computer.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

This article explains Kerberoasting, a long-standing attack against environments using Microsoft Active Directory. It describes how the technique relates to service accounts, centralized authentication, and RC4, and connects it to the May 2024 ransomware attack on Ascension Health based on a letter from Senator Wyden to Microsoft.

### Source excerpt

I learn about cryptographic vulnerabilities all the time, and they generally fill me with some combination of jealousy ("oh, why didn't I think of that") or else they impress me with the brilliance of their inventors. But there's also another class of vulnerabilities: these are the ones that can't possibly exist in important production software, ... Continue reading Kerberoasting ->

## Keycloak 26.0.5 released

DevFeed: [Keycloak 26.0.5 released](<https://devfeed.tech/articles/keycloak-26-0-5-released-31669.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/11/keycloak-2605-released>)

Author: Keycloak Team

Published: 2024-11-01T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [LDAP](<https://devfeed.tech/topics/ldap.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [release](<https://devfeed.tech/tags/release.md>), [resolved](<https://devfeed.tech/tags/resolved.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 26.0.5 is released with a change that creates LDAP users as enabled by default when using Microsoft Active Directory through the administrative interfaces. The release also includes resolved issues affecting the admin UI, login layout, documentation, identity provider migration, and AD entry updates.

### Source excerpt

To download the release go to Keycloak downloads. Highlights LDAP users are created as enabled by default when using Microsoft Active Directory If you are using Microsoft AD and creating users through the administrative interfaces, the user will created as enabled by default. In previous versions, it was only possible to update the user status after setting a (non-temporary) password to the user. This behavior was not consistent with other built-in user storages as well as not consistent with others LDAP vendors supported by the LDAP provider. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Bugs #31415 Selection list does not close after outside click admin/ui #33607 Fix v2 login layout login/ui #33618 No message for `policyGroupsHelp` admin/ui #33640 Customizable footer (Keycloak 26) not displaying in keycloak.v2 login theme login/ui #34301 Remove inaccurate statement about master realm imports docs #34450 [26.0.2] Migration from 25.0.1 Identity Provider Errors identity-brokering #34467 Do not rely on the `pwdLastSet` attribute when updating AD entries ldap

## What is SAML? A practical guide to the authentication protocol

DevFeed: [What is SAML? A practical guide to the authentication protocol](<https://devfeed.tech/articles/what-is-saml-a-practical-guide-to-the-authentication-protocol-709.md>)

Original publisher: [Read original article](<https://supabase.com/blog/what-is-saml-authentication>)

Author: Kang Ming Tay

Published: 2024-01-17T07:00:00Z

Content type: tutorial

Language: en

Sources: [Supabase Blog](<https://devfeed.tech/sources/supabase-blog.md>)

Topics: [Authentication](<https://devfeed.tech/topics/authentication.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [XML](<https://devfeed.tech/topics/xml.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Security](<https://devfeed.tech/topics/security.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [guide](<https://devfeed.tech/tags/guide.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [openid](<https://devfeed.tech/tags/openid.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [xml](<https://devfeed.tech/tags/xml.md>)

### AI overview

This practical guide explains SAML authentication and how SAML enables single sign-on between identity providers and service providers. It covers employee provisioning, XML-based SAML assertions, X.509 certificate exchange, and the distinction between SAML and broader SSO approaches such as OAuth and OpenID Connect.

### Source excerpt

Learn what is SAML authentication, how it differentiates from SSO, SAML with Postgres, and more.

## Teleport 12

DevFeed: [Teleport 12](<https://devfeed.tech/articles/teleport-12-29891.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/teleport-12/>)

Author: kenneth.dumez@goteleport.com (Kenneth DuMez)

Published: 2023-03-03T00:00:00Z

Content type: release

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Device Trust](<https://devfeed.tech/topics/device-trust.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [device-trust](<https://devfeed.tech/tags/device-trust.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [preview](<https://devfeed.tech/tags/preview.md>), [release](<https://devfeed.tech/tags/release.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Teleport 12 introduces Device Trust in preview, allowing administrators to require access from authenticated and trusted devices and integrate device authorization with Teleport RBAC. The release also previews passwordless certificate-based access for local Windows users without Active Directory and adds per-pod RBAC for Kubernetes access.

### Source excerpt

An overview of all of the new features added to Teleport 12. Device Trust, Passwordless Windows Access for Local Users and more.

## Active Directory Security

DevFeed: [Active Directory Security](<https://devfeed.tech/articles/active-directory-security-29557.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/active-directory-security/>)

Author: info@goteleport.com (Anish Devasia)

Published: 2022-11-30T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [active directory](<https://devfeed.tech/topics/active-directory.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [active-directory](<https://devfeed.tech/tags/active-directory.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [guide](<https://devfeed.tech/tags/guide.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [malware](<https://devfeed.tech/tags/malware.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

An introductory guide to securing Microsoft Active Directory Domain Services (AD DS). It explains AD DS as a directory service for identity management, authentication, authorization, centralized account management, security policies, and permissions, then introduces its security risks and hardening practices.

### Source excerpt

An introductory guide for how to secure and protect Active Directory Security (AD DS).

## My first weeks at Acer Europe

DevFeed: [My first weeks at Acer Europe](<https://devfeed.tech/articles/my-first-weeks-at-acer-europe-40831.md>)

Original publisher: [Read original article](<https://mutto.fyi/posts/2022/10/first-weeks-acer/>)

Published: 2022-10-16T00:00:00Z

Content type: opinion

Language: en

Sources: [Mutt0-ds Notes](<https://devfeed.tech/sources/mutt0-ds-notes.md>)

Topics: [Azure](<https://devfeed.tech/topics/azure.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [etl](<https://devfeed.tech/topics/etl.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Purview](<https://devfeed.tech/topics/purview.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [data-governance](<https://devfeed.tech/topics/data-governance.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [azure](<https://devfeed.tech/tags/azure.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [data-governance](<https://devfeed.tech/tags/data-governance.md>), [databases](<https://devfeed.tech/tags/databases.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [etl](<https://devfeed.tech/tags/etl.md>), [purview](<https://devfeed.tech/tags/purview.md>)

### AI overview

A Business Intelligence Developer reflects on their first weeks at Acer Europe, describing the transition from a small company to a large IT organization. The post covers the scale of its data, reporting, ETL, Azure services, and cross-team work, along with the information overload and learning challenges of the first week.

### Source excerpt

This is a post for my future self when I will be asking myself: "How were my first days at Acer like?". Note: I'm working at Acer EMEA HQ,...

## How to Connect to Microsoft SQL Server Remotely Using Teleport

DevFeed: [How to Connect to Microsoft SQL Server Remotely Using Teleport](<https://devfeed.tech/articles/how-to-connect-to-microsoft-sql-server-remotely-using-teleport-29614.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/connect-microsoft-sql-remotely/>)

Author: travis.rodgers@goteleport.com (Travis Rodgers)

Published: 2022-09-20T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [sql-server](<https://devfeed.tech/topics/sql-server.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security](<https://devfeed.tech/topics/security.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [VPC](<https://devfeed.tech/topics/vpc.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [audit](<https://devfeed.tech/tags/audit.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [security](<https://devfeed.tech/tags/security.md>), [sql-server](<https://devfeed.tech/tags/sql-server.md>), [vpc](<https://devfeed.tech/tags/vpc.md>)

### AI overview

This tutorial explains how to connect to Microsoft SQL Server remotely using Teleport and Active Directory authentication. It recommends Windows authentication, limiting public exposure through network isolation, and enabling auditing for logins, sessions, and SQL queries.

### Source excerpt

In this blog post, we'll look at how to connect to Microsoft SQL Server remotely using Teleport and Active Directory Authentication.

## Removing Calendar Invites using PowerShell + Azure CLI

DevFeed: [Removing Calendar Invites using PowerShell + Azure CLI](<https://devfeed.tech/articles/removing-calendar-invites-using-powershell-azure-cli-32350.md>)

Original publisher: [Read original article](<https://dustn.dev/post/2021-12-20-removing-calendar-invites-using-azure-cli/>)

Author: dustin@dustn.dev (Dustin Summers)

Published: 2021-12-20T10:26:38Z

Content type: tutorial

Language: en

Sources: [Dustin Summers](<https://devfeed.tech/sources/dustin-summers.md>)

Topics: [PowerShell](<https://devfeed.tech/topics/powershell.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [azure](<https://devfeed.tech/tags/azure.md>), [cli](<https://devfeed.tech/tags/cli.md>), [commands](<https://devfeed.tech/tags/commands.md>), [it-management-services-powershell-microsoft-azure-azure-active-directory](<https://devfeed.tech/tags/it-management-services-powershell-microsoft-azure-azure-active-directory.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [powershell](<https://devfeed.tech/tags/powershell.md>)

### AI overview

The article describes removing calendar invitations created by a departing employee while retaining the employee's account temporarily. It discusses PowerShell access problems on updated Macs caused by differing OpenSSL versions and presents Azure CLI as an alternative for managing the Azure environment.

### Source excerpt

Apart from my day job, I moonlight helping small-to-medium size companies' install and manage secure IT infrastructures, along with building and creating applications for them. I offer these services (and more) through my company, Attica, LLC. It is a passion of mine to help companies that are starting out have a solid IT/Cyber infrastructure that can scale with their company as these businesses are vulnerable and common targets of ransomware and phishing attacks.

## Identity-based, passwordless access to Windows hosts across all computing environments.

DevFeed: [Identity-based, passwordless access to Windows hosts across all computing environments.](<https://devfeed.tech/articles/identity-based-passwordless-access-to-windows-hosts-across-all-computing-environments-29625.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/desktop-access/>)

Author: ben@goteleport.com (Ben Arent)

Published: 2021-12-15T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Windows](<https://devfeed.tech/topics/windows.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [remote access](<https://devfeed.tech/topics/remote-access.md>), [Security](<https://devfeed.tech/topics/security.md>), [servers](<https://devfeed.tech/topics/servers.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [password](<https://devfeed.tech/tags/password.md>), [rdp](<https://devfeed.tech/tags/rdp.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [security](<https://devfeed.tech/tags/security.md>), [servers](<https://devfeed.tech/tags/servers.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The article introduces Teleport Desktop Access for Windows hosts, extending Teleport's passwordless, certificate-based access model from Linux to Windows. It discusses RDP, Active Directory, remote access, and security risks associated with password-based access and privileged directory services.

### Source excerpt

An overview Teleport Desktop Access providing securing access to Windows Fleets.

## How SAML Authentication Works?

DevFeed: [How SAML Authentication Works?](<https://devfeed.tech/articles/how-saml-authentication-works-29677.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/how-saml-authentication-works/>)

Author: info@goteleport.com (Russell Jones)

Published: 2021-04-13T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [saml](<https://devfeed.tech/topics/saml.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [auth0](<https://devfeed.tech/tags/auth0.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [saml](<https://devfeed.tech/tags/saml.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

This tutorial explains how SAML 2.0 exchanges authentication and authorization information between services, focusing on its use in enterprise single sign-on. It introduces the security benefits of centralized identity and consistent authentication, along with key terminology such as principal and identity provider.

### Source excerpt

At its core, Security Assertion Markup Language (SAML) 2.0 is a means to exchange authorization and authentication information between services. Learn how saml works.

## Attacking Smart Card Based Active Directory Networks

DevFeed: [Attacking Smart Card Based Active Directory Networks](<https://devfeed.tech/articles/attacking-smart-card-based-active-directory-networks-32631.md>)

Original publisher: [Read original article](<https://ethicalchaos.dev/2020/10/04/attacking-smart-card-based-active-directory-networks/>)

Author: CCob

Published: 2020-10-04T19:31:42Z

Content type: tutorial

Language: en

Sources: [Ethical Chaos](<https://devfeed.tech/sources/ethical-chaos.md>)

Topics: [active directory](<https://devfeed.tech/topics/active-directory.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [private key](<https://devfeed.tech/topics/private-key.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [kerberos](<https://devfeed.tech/topics/kerberos.md>), [public key](<https://devfeed.tech/topics/public-key.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [cobalt-strike](<https://devfeed.tech/tags/cobalt-strike.md>), [hooking](<https://devfeed.tech/tags/hooking.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [pin](<https://devfeed.tech/tags/pin.md>), [pinswipe](<https://devfeed.tech/tags/pinswipe.md>), [pki](<https://devfeed.tech/tags/pki.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [rubeus](<https://devfeed.tech/tags/rubeus.md>), [smart-card](<https://devfeed.tech/tags/smart-card.md>), [swipe](<https://devfeed.tech/tags/swipe.md>), [weaponize](<https://devfeed.tech/tags/weaponize.md>)

### AI overview

This article examines attacks against smart-card-enforced Active Directory networks. It explains that a physical smart card is not necessarily required for smart-card logon when the corresponding private key is available, describes certificate requirements and policy-related certificate abuse, and introduces PKINIT as public-key support for Kerberos pre-authentication.

### Source excerpt

Introduction Recently I was involved in an engagement where I was attacking smart card based Active Directory networks. The fact is though, you don't need a physical smart card at all to authenticate to Active Directory that enforces smart card logon. The attributes of the certificate determine if it can be used for smart card [...] The post Attacking Smart Card Based Active Directory Networks appeared first on Ethical Chaos.

## Teleport Demo and Overview Video - Modern SSH

DevFeed: [Teleport Demo and Overview Video - Modern SSH](<https://devfeed.tech/articles/teleport-demo-and-overview-video-modern-ssh-29917.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/teleport-demo-video/>)

Author: ev@goteleport.com (Ev Kontsevoy)

Published: 2020-07-16T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [ssh](<https://devfeed.tech/topics/ssh.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Raspberry Pi](<https://devfeed.tech/topics/raspberry-pi.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [audit](<https://devfeed.tech/tags/audit.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [github](<https://devfeed.tech/tags/github.md>), [google](<https://devfeed.tech/tags/google.md>), [guide](<https://devfeed.tech/tags/guide.md>), [k8s](<https://devfeed.tech/tags/k8s.md>), [linux](<https://devfeed.tech/tags/linux.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [raspberry-pi](<https://devfeed.tech/tags/raspberry-pi.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [sso](<https://devfeed.tech/tags/sso.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

This video demonstrates how Teleport implements SSH best practices, including SSH certificates, single sign-on, browser and command-line access, centralized session auditing, Kubernetes access, and connections to edge devices such as a Raspberry Pi.

### Source excerpt

Teleport allows easy implementation of SSH best practices. Here is a video that takes a deep dive into how Teleport works.

## How to Setup MS AD FS 3.0 as Brokered Identity Provider in Keycloak

DevFeed: [How to Setup MS AD FS 3.0 as Brokered Identity Provider in Keycloak](<https://devfeed.tech/articles/how-to-setup-ms-ad-fs-3-0-as-brokered-identity-provider-in-keycloak-31562.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2017/03/how-to-setup-ms-ad-fs-30-as-brokered>)

Author: Hynek Mlnařík

Published: 2017-03-23T00:00:00Z

Content type: tutorial

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [saml](<https://devfeed.tech/topics/saml.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [idm](<https://devfeed.tech/tags/idm.md>), [installation](<https://devfeed.tech/tags/installation.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [tls](<https://devfeed.tech/tags/tls.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

A setup guide for configuring Microsoft Active Directory Federation Services 3.0 as a brokered SAML identity provider in Keycloak. It covers SSL/TLS prerequisites, certificate trust configuration, metadata import, signature settings, mapper configuration, and AD FS relying-party trust setup.

### Source excerpt

This document guides you through initial setup of Microsoft Active Directory Federation Services 3.0 as a brokered identity provider Keycloak. Prerequisites Two server hosts: Microsoft Windows Server 2012 with Active Directory Federation Services (AD FS) installed. The AD domain will be named DOMAIN.NAME in this post. Keycloak server. This can be generally placed anywhere but here it is expected to be running on separate host DNS setup: The Windows host name will be fs.domain.name in this post The Keycloak host name will be kc.domain.name in this post Setup Keycloak Server Keycloak server has configured for SSL/TLS transport - this is mandatory for AD FS to communicate with it. This comprises two steps: Setup keycloak for incoming HTTPS connections - steps are provided in Server Installation guide. Export AD FS certificate into a Java truststore to enable outgoing HTTPS connections: In the AD FS management console, go to Service -> Certificates node in the tree and export the Service communications certificate. Import the certificate into a Java truststore (JKS format) using Java keytool utility. Setup the truststore in Keycloak as described in Server Installation guide. Setup Identity Provider in Keycloak Setup Basic Properties of Brokered Identity Provider In the Identity Providers, create a new SAML v2.0 identity provider. In this post, the identity provider will be known under alias adfs-idp-alias. Now scroll to the bottom and enter the AD FS descriptor URL into Import from URL field. For AD FS 3.0, this URL is https://fs.domain.name/FederationMetadata/2007-06/FederationMetadata.xml. Once you click "Import", check the settings. Usually, you would at least enable Validate signature option. If the authentication requests sent to the AD FS instance are expected to be signed, which is also usually the case, you have to enable Want AuthnRequests Signed option. Importantly, then the SAML Signature Key Name field that shows after enabling the Want AuthnRequests Signed o

## Change default WSUS port from 8530 to 80 on Windows Server 2012

DevFeed: [Change default WSUS port from 8530 to 80 on Windows Server 2012](<https://devfeed.tech/articles/change-default-wsus-port-from-8530-to-80-on-windows-server-2012-27602.md>)

Original publisher: [Read original article](<https://gagor.pro/2014/01/change-default-wsus-port-from-8530-to-80-on-windows-server-2012/>)

Author: Tom

Published: 2014-01-24T00:00:00Z

Content type: tutorial

Language: en

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [Windows](<https://devfeed.tech/topics/windows.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Server](<https://devfeed.tech/topics/server.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [active-directory-wsus](<https://devfeed.tech/tags/active-directory-wsus.md>), [change-wsus-port](<https://devfeed.tech/tags/change-wsus-port.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [compatibility](<https://devfeed.tech/tags/compatibility.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [gpo](<https://devfeed.tech/tags/gpo.md>), [ipv6](<https://devfeed.tech/tags/ipv6.md>), [port](<https://devfeed.tech/tags/port.md>), [windows](<https://devfeed.tech/tags/windows.md>), [windows-server-2012-wsus](<https://devfeed.tech/tags/windows-server-2012-wsus.md>), [wsus](<https://devfeed.tech/tags/wsus.md>), [wsus-configuration](<https://devfeed.tech/tags/wsus-configuration.md>), [wsus-ipv6-issue](<https://devfeed.tech/tags/wsus-ipv6-issue.md>), [wsus-port-80](<https://devfeed.tech/tags/wsus-port-80.md>)

### AI overview

A tutorial explains how to change the default WSUS port from 8530 to port 80 on Windows Server 2012. It addresses an IPv6-only configuration and compatibility with older configurations.

### Source excerpt

Learn how to change the default WSUS port from 8530 to 80 on Windows Server 2012, ensuring compatibility with older configurations and resolving IPv6-only issues.

## Manage Windows 8.1 and Windows Server 2012 R2 in WSUS 3.0

DevFeed: [Manage Windows 8.1 and Windows Server 2012 R2 in WSUS 3.0](<https://devfeed.tech/articles/manage-windows-8-1-and-windows-server-2012-r2-in-wsus-3-0-27605.md>)

Original publisher: [Read original article](<https://gagor.pro/2014/01/manage-windows-8-1-and-windows-server-2012-r2-in-wsus-3-0/>)

Author: Tom

Published: 2014-01-16T00:00:00Z

Content type: tutorial

Language: en

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [Windows](<https://devfeed.tech/topics/windows.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Databases](<https://devfeed.tech/topics/databases.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [database](<https://devfeed.tech/tags/database.md>), [domain](<https://devfeed.tech/tags/domain.md>), [install](<https://devfeed.tech/tags/install.md>), [run](<https://devfeed.tech/tags/run.md>), [update](<https://devfeed.tech/tags/update.md>), [updates](<https://devfeed.tech/tags/updates.md>), [windows](<https://devfeed.tech/tags/windows.md>), [wsus](<https://devfeed.tech/tags/wsus.md>), [x86](<https://devfeed.tech/tags/x86.md>)

### AI overview

A practical guide to making Windows 8.1 clients work with WSUS 3.0 on Windows Server 2008. It describes installing two Microsoft updates, reindexing the WSUS database, and running the Server Cleanup Wizard so clients can report and receive updates.

### Source excerpt

After connecting few computers with Windows 8.1 to domain we found that these computers are not recognized or recognized as Windows 6.3 (which is true) on WSUS 3.0 running on Windows Server 2008. The bad thing was that they can't properly report to WSUS and get updates from it. I found that there are two updates that have to be installed (but they're not working without additional steps): http://support.microsoft.com/kb/2720211 external link http://support.microsoft.com/kb/2734608 external link After installation of second update there are two additional steps that have to be performed to get WSUS working:

## DFS - sprawdzanie statusu replikacji

DevFeed: [DFS - sprawdzanie statusu replikacji](<https://devfeed.tech/articles/dfs-sprawdzanie-statusu-replikacji-27573.md>)

Original publisher: [Read original article](<https://gagor.pro/2013/09/dfs-sprawdzanie-statusu-replikacji/>)

Author: Tom

Published: 2013-09-04T00:00:00Z

Content type: tutorial

Language: pl

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [Server](<https://devfeed.tech/topics/server.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [GUI](<https://devfeed.tech/topics/gui.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [gui](<https://devfeed.tech/tags/gui.md>), [server](<https://devfeed.tech/tags/server.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

This Polish developer article explains how to check the replication status of DFS on Windows Server using the `dfsrdiag ReplicationState /member:nazwaservera` shell command. The command does not show percentage progress but can indicate whether synchronization is still occurring and whether errors are present.

### Source excerpt

Ostatnio zbyt dużo grzebię przy "windach" - ale cóż, czasem trzeba. Ostatnio ustawiałem DFS'a z replikacją dla dwóch sporych zasobów i jedna z rzeczy, o którą się rozbiłem to brak jakiegokolwiek podglądu tej synchronizacji z GUI. Ale znalazłem jedno polecenie, które działa w shellu (choć to się chyba batch tutaj nazywa) od Windows Server 2008 R2: dfsrdiag ReplicationState /member:nazwaservera Polecenie co prawda nie podaje postępu procentowego ale można zobaczyć "czy coś jeszcze się synchronizuje" i czy nie ma żadnych błędów. Jeżeli to polecenie to za mało to można spróbować bardziej gadatliwej wersji:

## GPO: Instalacja GIMP'a 2.8

DevFeed: [GPO: Instalacja GIMP'a 2.8](<https://devfeed.tech/articles/gpo-instalacja-gimp-a-2-8-27572.md>)

Original publisher: [Read original article](<https://gagor.pro/2013/08/gpo-instalacja-gimpa-2-8/>)

Author: Tom

Published: 2013-08-06T00:00:00Z

Content type: tutorial

Language: pl

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [Batch file](<https://devfeed.tech/topics/batch-file.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [enterprise deployment](<https://devfeed.tech/topics/enterprise-deployment.md>), [Script](<https://devfeed.tech/topics/script.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [code](<https://devfeed.tech/tags/code.md>), [gpo](<https://devfeed.tech/tags/gpo.md>), [install](<https://devfeed.tech/tags/install.md>), [installation](<https://devfeed.tech/tags/installation.md>), [policies](<https://devfeed.tech/tags/policies.md>), [startup](<https://devfeed.tech/tags/startup.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

A Polish tutorial explains how to deploy GIMP 2.8 through an Active Directory Group Policy startup script on Windows. The batch script checks whether GIMP is installed, silently removes an earlier manually installed version, and installs GIMP 2.8 from a network share.

### Source excerpt

Raz na jakiś czas trzeba coś niestandardowego wrzucić do instalacji w Active Directory a że nie wszystkie aplikacje mają dostępne paczki MSI to trzeba się nieco natrudzić. Poniżej wrzucam skrypt, który instaluje GIMP'a 2.8 z domyślnego instalatora (wersja InnoSetup) przy okazji odinstalowując wcześniejsze wersje zainstalowane ręcznie. Zapisujemy poniższy kod jako np. gimp-install.cmd @echo off REM Installs GIMP cls echo ---------------------------------------------------- echo . echo . echo . Installing/Updating GIMP - Please Wait echo . echo . echo ---------------------------------------------------- REM Test if actual IF exist "%ProgramFiles%\GIMP\bin\gimp-2.8.exe" GOTO SkipInstall REM Exit the application taskkill.exe /F /FI "IMAGENAME eq gimp-2.8.exe" >nul REM Uninstall existing GIMP version, delete folder if exist "%ProgramFiles%\GIMP 2\uninst\unins000.exe" "%ProgramFiles%\GIMP 2\uninst\unins000.exe" /VERYSILENT :: Wait for 20 seconds ping -n 40 127.0.0.1 > NUL if exist "%ProgramFiles%\GIMP 2\" rd "%ProgramFiles%\GIMP 2\" /Q /S REM Install new version "\\serwerplikow.local\Instalki\GIMP\gimp-2.8.4-setup.exe" /VERYSILENT /NORESTART /DIR="%PROGRAMFILES%\GIMP 2.8" REM Skip installation if acctuall :SkipInstall REM Return exit code to SCCM exit /B %EXIT_CODE% Tworzymy nową regułkę GPO i zmierzamy do: Computer Configuration\Policies\Windows Settings\Scripts\Startup W nowym okienku wybieramy Show Files... Wklejamy plik skryptu do tego folderu i teraz możemy dodać go w tym samym oknie (Add...) - dzięki wrzuceniu skryptu w tym miejscu będzie się on automatycznie replikować na inne kontrolery. Skrypt będzie co prawda uruchamiany przy każdym starcie komputera ale pierwszy warunek będzie sprawdzać czy aplikacja jest zainstalowana więc nie spowolni to znacznie startu.

## Fortigate - VPN IPSec PSK XAuth z Android'a 4.x

DevFeed: [Fortigate - VPN IPSec PSK XAuth z Android'a 4.x](<https://devfeed.tech/articles/fortigate-vpn-ipsec-psk-xauth-z-android-a-4-x-27565.md>)

Original publisher: [Read original article](<https://gagor.pro/2013/03/fortigate-vpn-ipsec-psk-xauth-z-androida-4-x/>)

Author: Tom

Published: 2013-03-30T00:00:00Z

Content type: tutorial

Language: pl

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>), [Android](<https://devfeed.tech/topics/android.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [iOS](<https://devfeed.tech/topics/ios.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [android](<https://devfeed.tech/tags/android.md>), [cli](<https://devfeed.tech/tags/cli.md>), [fortigate](<https://devfeed.tech/tags/fortigate.md>), [fortios](<https://devfeed.tech/tags/fortios.md>), [ios](<https://devfeed.tech/tags/ios.md>), [ipad](<https://devfeed.tech/tags/ipad.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [os](<https://devfeed.tech/tags/os.md>), [security](<https://devfeed.tech/tags/security.md>), [vpn](<https://devfeed.tech/tags/vpn.md>)

### AI overview

A tutorial on configuring a Fortigate IPsec XAuth PSK VPN for Android 4.x phones and tablets to access an intranet. It covers CLI-based VPN setup, firewall rules, DNS access, and optional routing to external services, with notes about iOS compatibility.

### Source excerpt

Do niedawna na moim telefonie VPN'ami były: PPTP lub L2TP - oba niespecjalnie mi się podobały. Ale od wersji 4-tej pojawiły się dwa nowe tryby: IPSec Xauth PSK i IPSec Xauth RSA. W pierwszym autoryzacja wykorzystuje login i hasło, w drugim certyfikaty. Tryb IPSec Xauth PSK jest bardzo wygodny bo łatwo można połączyć go z zewnętrznymi mechanizmami uwierzytelniającymi np. LDAP, Active Directory, itp. Pokażę jak skonfigurować swojego Fortigate'a by umożliwić połączenie z telefonów i tabletów na Androidzie 4.x do "Intranetu"1. Większość konfiguracji można przeprowadzić tylko w trybie CLI - zakładam że wiesz jak to zrobić. To co wygodniej można zrobić w trybie WWW to głównie tworzenie reguł dostępu na zaporze.

## Apache: mod\_authnz\_ldap z Active Directory

DevFeed: [Apache: mod\_authnz\_ldap z Active Directory](<https://devfeed.tech/articles/apache-mod-authnz-ldap-z-active-directory-27556.md>)

Original publisher: [Read original article](<https://gagor.pro/2012/12/apache-mod_authnz_ldap-z-active-directory/>)

Author: Tom

Published: 2012-12-14T00:00:00Z

Content type: tutorial

Language: pl

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [active directory](<https://devfeed.tech/topics/active-directory.md>), [Caching](<https://devfeed.tech/topics/caching.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [apache](<https://devfeed.tech/tags/apache.md>), [cache](<https://devfeed.tech/tags/cache.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [linux](<https://devfeed.tech/tags/linux.md>)

### AI overview

A Polish tutorial explains how to configure Apache authentication against Active Directory using LDAP and mod_authnz_ldap, including module activation, LDAP caching, virtual host settings, bind credentials, and access requirements.

### Source excerpt

Gdy już się dorobi systemu Active Directory wygodnie jest wykorzystać jego bazę użytkowników do autoryzacji w różnych miejscach, np. do pewnych "tajnych i tajniejszych" stron w Apache. Najprościej można to zrobić z wykorzystaniem LDAP. Warto sprawdzić czy i jak możemy dostać się do kontrolerów. Gdy już mamy wszystkie potrzebne parametry konfigurujemy Apachego - na początek aktywujemy moduły: a2enmod ldap a2enmod authnz_ldap Teraz możemy edytujemy globalny plik konfiguracyjny mod_ldap'a by ustawić nieco cache'y (bardzo przydatne). Wartości można dostosować do potrzeb ale przykładowe powinny wystarczyć na początku:

[Next page](<https://devfeed.tech/tags/active-directory.md?cursor=WyIyMDEyLTEyLTE0VDAwOjAwOjAwKzAwOjAwIiwgIjA5YjI0NjQ4LWRkZmUtNDVmMS1iOThiLTBlZmZmZmE3ZjNiMyJd>)