# active directory

Active Directory is a Windows network directory service for storing, managing, and retrieving identities and relationships among users, groups, and computers.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## How Does CockroachDB Automate SQL User Lifecycle Management?

DevFeed: [How Does CockroachDB Automate SQL User Lifecycle Management?](<https://devfeed.tech/articles/how-does-cockroachdb-automate-sql-user-lifecycle-management-23818.md>)

Original publisher: [Read original article](<https://cockroachlabs.com/blog/sql-user-lifecycle-management-automation>)

Author: Pritesh Lahoti,Biplav Saraf,Sourav Sarangi

Published: 2026-08-28T00:00:00Z

Content type: tutorial

Language: en

Sources: [Cockroach Labs](<https://devfeed.tech/sources/cockroach-labs.md>)

Topics: [CockroachDB](<https://devfeed.tech/topics/cockroachdb.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [okta](<https://devfeed.tech/topics/okta.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [cockroachdb](<https://devfeed.tech/tags/cockroachdb.md>), [entra-id](<https://devfeed.tech/tags/entra-id.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [okta](<https://devfeed.tech/tags/okta.md>)

### AI overview

The article addresses how CockroachDB automates SQL user lifecycle management and notes that large enterprises commonly rely on identity provider and identity and access management platforms such as Okta, Microsoft Entra ID, Microsoft Active Directory, and Ory.

### Source excerpt

Fortune 1000 enterprises widely rely on major Identity Provider (IdP) and Identity and Access Management (IAM) platforms like Okta, Microsoft Entra ID, Microsoft Active Directory, and Ory.

## Native Windows automation without Docker, WSL, or workarounds

DevFeed: [Native Windows automation without Docker, WSL, or workarounds](<https://devfeed.tech/articles/native-windows-automation-without-docker-wsl-or-workarounds-30728.md>)

Original publisher: [Read original article](<https://www.windmill.dev/blog/windows-workflow-engine>)

Author: Alex Petric

Published: 2026-04-29T00:00:00Z

Content type: article

Language: en

Sources: [Windmill Blog](<https://devfeed.tech/sources/windmill-blog.md>)

Topics: [Windows](<https://devfeed.tech/topics/windows.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [C#](<https://devfeed.tech/topics/csharp.md>), [servers](<https://devfeed.tech/topics/servers.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [ai](<https://devfeed.tech/tags/ai.md>), [automation](<https://devfeed.tech/tags/automation.md>), [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [database](<https://devfeed.tech/tags/database.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [servers](<https://devfeed.tech/tags/servers.md>), [windows](<https://devfeed.tech/tags/windows.md>), [windows-enterprise-powershell-ai](<https://devfeed.tech/tags/windows-enterprise-powershell-ai.md>)

### AI overview

This article explains how Windmill automates Windows servers as a native Windows service. It covers PowerShell, C#, SQL and MSSQL Kerberos authentication, Active Directory access, mixed Windows/Linux workers, approval workflows, and audit trails without requiring Docker or WSL2.

### Source excerpt

How do I automate Windows servers without Docker? Windmill runs natively on Windows as a service with PowerShell, C#, MSSQL Kerberos auth, and Teams integration.

## Kerberoasting

DevFeed: [Kerberoasting](<https://devfeed.tech/articles/kerberoasting-29092.md>)

Original publisher: [Read original article](<https://blog.cryptographyengineering.com/2025/09/10/kerberoasting/>)

Author: Matthew Green

Published: 2025-09-10T12:00:00Z

Content type: opinion

Language: en

Sources: [Matthew Green](<https://devfeed.tech/sources/matthew-green.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [computer](<https://devfeed.tech/tags/computer.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

This article explains Kerberoasting, a long-standing attack against environments using Microsoft Active Directory. It describes how the technique relates to service accounts, centralized authentication, and RC4, and connects it to the May 2024 ransomware attack on Ascension Health based on a letter from Senator Wyden to Microsoft.

### Source excerpt

I learn about cryptographic vulnerabilities all the time, and they generally fill me with some combination of jealousy ("oh, why didn't I think of that") or else they impress me with the brilliance of their inventors. But there's also another class of vulnerabilities: these are the ones that can't possibly exist in important production software, ... Continue reading Kerberoasting ->

## Keycloak 26.0.5 released

DevFeed: [Keycloak 26.0.5 released](<https://devfeed.tech/articles/keycloak-26-0-5-released-31669.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/11/keycloak-2605-released>)

Author: Keycloak Team

Published: 2024-11-01T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [LDAP](<https://devfeed.tech/topics/ldap.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [keycloak-release](<https://devfeed.tech/tags/keycloak-release.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [release](<https://devfeed.tech/tags/release.md>), [resolved](<https://devfeed.tech/tags/resolved.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Keycloak 26.0.5 is released with a change that creates LDAP users as enabled by default when using Microsoft Active Directory through the administrative interfaces. The release also includes resolved issues affecting the admin UI, login layout, documentation, identity provider migration, and AD entry updates.

### Source excerpt

To download the release go to Keycloak downloads. Highlights LDAP users are created as enabled by default when using Microsoft Active Directory If you are using Microsoft AD and creating users through the administrative interfaces, the user will created as enabled by default. In previous versions, it was only possible to update the user status after setting a (non-temporary) password to the user. This behavior was not consistent with other built-in user storages as well as not consistent with others LDAP vendors supported by the LDAP provider. Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Bugs #31415 Selection list does not close after outside click admin/ui #33607 Fix v2 login layout login/ui #33618 No message for `policyGroupsHelp` admin/ui #33640 Customizable footer (Keycloak 26) not displaying in keycloak.v2 login theme login/ui #34301 Remove inaccurate statement about master realm imports docs #34450 [26.0.2] Migration from 25.0.1 Identity Provider Errors identity-brokering #34467 Do not rely on the `pwdLastSet` attribute when updating AD entries ldap

## Teleport 12

DevFeed: [Teleport 12](<https://devfeed.tech/articles/teleport-12-29891.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/teleport-12/>)

Author: kenneth.dumez@goteleport.com (Kenneth DuMez)

Published: 2023-03-03T00:00:00Z

Content type: release

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Device Trust](<https://devfeed.tech/topics/device-trust.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [device-trust](<https://devfeed.tech/tags/device-trust.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [preview](<https://devfeed.tech/tags/preview.md>), [release](<https://devfeed.tech/tags/release.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Teleport 12 introduces Device Trust in preview, allowing administrators to require access from authenticated and trusted devices and integrate device authorization with Teleport RBAC. The release also previews passwordless certificate-based access for local Windows users without Active Directory and adds per-pod RBAC for Kubernetes access.

### Source excerpt

An overview of all of the new features added to Teleport 12. Device Trust, Passwordless Windows Access for Local Users and more.

## Active Directory Security

DevFeed: [Active Directory Security](<https://devfeed.tech/articles/active-directory-security-29557.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/active-directory-security/>)

Author: info@goteleport.com (Anish Devasia)

Published: 2022-11-30T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [active directory](<https://devfeed.tech/topics/active-directory.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [active-directory](<https://devfeed.tech/tags/active-directory.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [guide](<https://devfeed.tech/tags/guide.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [malware](<https://devfeed.tech/tags/malware.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

An introductory guide to securing Microsoft Active Directory Domain Services (AD DS). It explains AD DS as a directory service for identity management, authentication, authorization, centralized account management, security policies, and permissions, then introduces its security risks and hardening practices.

### Source excerpt

An introductory guide for how to secure and protect Active Directory Security (AD DS).

## Setting Up a CI/CD Pipeline for Power BI Report Source Control

DevFeed: [Setting Up a CI/CD Pipeline for Power BI Report Source Control](<https://devfeed.tech/articles/a-turbulent-journey-through-power-bi-source-control-40832.md>)

Original publisher: [Read original article](<https://mutto.fyi/posts/2022/11/turbulent-journey-power-bi-source-control/>)

Published: 2022-11-07T00:00:00Z

Content type: tutorial

Language: en

Sources: [Mutt0-ds Notes](<https://devfeed.tech/sources/mutt0-ds-notes.md>)

Topics: [Azure DevOps](<https://devfeed.tech/topics/azure-devops.md>), [CI/CD Pipeline](<https://devfeed.tech/topics/ci-cd-pipeline.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [REST API](<https://devfeed.tech/topics/rest-api.md>), [Git](<https://devfeed.tech/topics/git.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [JSON](<https://devfeed.tech/topics/json.md>), [API](<https://devfeed.tech/topics/api.md>), [dataset](<https://devfeed.tech/topics/dataset.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [ci-cd-pipeline](<https://devfeed.tech/tags/ci-cd-pipeline.md>), [dataset](<https://devfeed.tech/tags/dataset.md>), [devops](<https://devfeed.tech/tags/devops.md>), [directory](<https://devfeed.tech/tags/directory.md>), [environment-variables](<https://devfeed.tech/tags/environment-variables.md>), [git](<https://devfeed.tech/tags/git.md>), [json](<https://devfeed.tech/tags/json.md>), [repository](<https://devfeed.tech/tags/repository.md>), [rest-api](<https://devfeed.tech/tags/rest-api.md>)

### AI overview

This article describes setting up a CI/CD pipeline through Azure DevOps to provide rudimentary version control for Power BI reports. Because .pbix files are binary, the pipeline uploads a report to a Power BI Premium workspace, uses the Power BI REST API and Tabular Editor 2 to extract metadata, and pushes the resulting textual representation back to a Git repository.

### Source excerpt

One of the most annoying issues I have when working with Power BI files is that source control is a real pain. Considering that Microsoft...

## My first weeks at Acer Europe

DevFeed: [My first weeks at Acer Europe](<https://devfeed.tech/articles/my-first-weeks-at-acer-europe-40831.md>)

Original publisher: [Read original article](<https://mutto.fyi/posts/2022/10/first-weeks-acer/>)

Published: 2022-10-16T00:00:00Z

Content type: opinion

Language: en

Sources: [Mutt0-ds Notes](<https://devfeed.tech/sources/mutt0-ds-notes.md>)

Topics: [Azure](<https://devfeed.tech/topics/azure.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [etl](<https://devfeed.tech/topics/etl.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Purview](<https://devfeed.tech/topics/purview.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [data-governance](<https://devfeed.tech/topics/data-governance.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [azure](<https://devfeed.tech/tags/azure.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [data-governance](<https://devfeed.tech/tags/data-governance.md>), [databases](<https://devfeed.tech/tags/databases.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [etl](<https://devfeed.tech/tags/etl.md>), [purview](<https://devfeed.tech/tags/purview.md>)

### AI overview

A Business Intelligence Developer reflects on their first weeks at Acer Europe, describing the transition from a small company to a large IT organization. The post covers the scale of its data, reporting, ETL, Azure services, and cross-team work, along with the information overload and learning challenges of the first week.

### Source excerpt

This is a post for my future self when I will be asking myself: "How were my first days at Acer like?". Note: I'm working at Acer EMEA HQ,...

## How to Connect to Microsoft SQL Server Remotely Using Teleport

DevFeed: [How to Connect to Microsoft SQL Server Remotely Using Teleport](<https://devfeed.tech/articles/how-to-connect-to-microsoft-sql-server-remotely-using-teleport-29614.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/connect-microsoft-sql-remotely/>)

Author: travis.rodgers@goteleport.com (Travis Rodgers)

Published: 2022-09-20T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [sql-server](<https://devfeed.tech/topics/sql-server.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security](<https://devfeed.tech/topics/security.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [VPC](<https://devfeed.tech/topics/vpc.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [audit](<https://devfeed.tech/tags/audit.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [security](<https://devfeed.tech/tags/security.md>), [sql-server](<https://devfeed.tech/tags/sql-server.md>), [vpc](<https://devfeed.tech/tags/vpc.md>)

### AI overview

This tutorial explains how to connect to Microsoft SQL Server remotely using Teleport and Active Directory authentication. It recommends Windows authentication, limiting public exposure through network isolation, and enabling auditing for logins, sessions, and SQL queries.

### Source excerpt

In this blog post, we'll look at how to connect to Microsoft SQL Server remotely using Teleport and Active Directory Authentication.

## Removing Calendar Invites using PowerShell + Azure CLI

DevFeed: [Removing Calendar Invites using PowerShell + Azure CLI](<https://devfeed.tech/articles/removing-calendar-invites-using-powershell-azure-cli-32350.md>)

Original publisher: [Read original article](<https://dustn.dev/post/2021-12-20-removing-calendar-invites-using-azure-cli/>)

Author: dustin@dustn.dev (Dustin Summers)

Published: 2021-12-20T10:26:38Z

Content type: tutorial

Language: en

Sources: [Dustin Summers](<https://devfeed.tech/sources/dustin-summers.md>)

Topics: [PowerShell](<https://devfeed.tech/topics/powershell.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [azure](<https://devfeed.tech/tags/azure.md>), [cli](<https://devfeed.tech/tags/cli.md>), [commands](<https://devfeed.tech/tags/commands.md>), [it-management-services-powershell-microsoft-azure-azure-active-directory](<https://devfeed.tech/tags/it-management-services-powershell-microsoft-azure-azure-active-directory.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [powershell](<https://devfeed.tech/tags/powershell.md>)

### AI overview

The article describes removing calendar invitations created by a departing employee while retaining the employee's account temporarily. It discusses PowerShell access problems on updated Macs caused by differing OpenSSL versions and presents Azure CLI as an alternative for managing the Azure environment.

### Source excerpt

Apart from my day job, I moonlight helping small-to-medium size companies' install and manage secure IT infrastructures, along with building and creating applications for them. I offer these services (and more) through my company, Attica, LLC. It is a passion of mine to help companies that are starting out have a solid IT/Cyber infrastructure that can scale with their company as these businesses are vulnerable and common targets of ransomware and phishing attacks.

## Identity-based, passwordless access to Windows hosts across all computing environments.

DevFeed: [Identity-based, passwordless access to Windows hosts across all computing environments.](<https://devfeed.tech/articles/identity-based-passwordless-access-to-windows-hosts-across-all-computing-environments-29625.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/desktop-access/>)

Author: ben@goteleport.com (Ben Arent)

Published: 2021-12-15T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Windows](<https://devfeed.tech/topics/windows.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [remote access](<https://devfeed.tech/topics/remote-access.md>), [Security](<https://devfeed.tech/topics/security.md>), [servers](<https://devfeed.tech/topics/servers.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [password](<https://devfeed.tech/tags/password.md>), [rdp](<https://devfeed.tech/tags/rdp.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [security](<https://devfeed.tech/tags/security.md>), [servers](<https://devfeed.tech/tags/servers.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The article introduces Teleport Desktop Access for Windows hosts, extending Teleport's passwordless, certificate-based access model from Linux to Windows. It discusses RDP, Active Directory, remote access, and security risks associated with password-based access and privileged directory services.

### Source excerpt

An overview Teleport Desktop Access providing securing access to Windows Fleets.

## Attacking Smart Card Based Active Directory Networks

DevFeed: [Attacking Smart Card Based Active Directory Networks](<https://devfeed.tech/articles/attacking-smart-card-based-active-directory-networks-32631.md>)

Original publisher: [Read original article](<https://ethicalchaos.dev/2020/10/04/attacking-smart-card-based-active-directory-networks/>)

Author: CCob

Published: 2020-10-04T19:31:42Z

Content type: tutorial

Language: en

Sources: [Ethical Chaos](<https://devfeed.tech/sources/ethical-chaos.md>)

Topics: [active directory](<https://devfeed.tech/topics/active-directory.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [private key](<https://devfeed.tech/topics/private-key.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [kerberos](<https://devfeed.tech/topics/kerberos.md>), [public key](<https://devfeed.tech/topics/public-key.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [cobalt-strike](<https://devfeed.tech/tags/cobalt-strike.md>), [hooking](<https://devfeed.tech/tags/hooking.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [pin](<https://devfeed.tech/tags/pin.md>), [pinswipe](<https://devfeed.tech/tags/pinswipe.md>), [pki](<https://devfeed.tech/tags/pki.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [rubeus](<https://devfeed.tech/tags/rubeus.md>), [smart-card](<https://devfeed.tech/tags/smart-card.md>), [swipe](<https://devfeed.tech/tags/swipe.md>), [weaponize](<https://devfeed.tech/tags/weaponize.md>)

### AI overview

This article examines attacks against smart-card-enforced Active Directory networks. It explains that a physical smart card is not necessarily required for smart-card logon when the corresponding private key is available, describes certificate requirements and policy-related certificate abuse, and introduces PKINIT as public-key support for Kerberos pre-authentication.

### Source excerpt

Introduction Recently I was involved in an engagement where I was attacking smart card based Active Directory networks. The fact is though, you don't need a physical smart card at all to authenticate to Active Directory that enforces smart card logon. The attributes of the certificate determine if it can be used for smart card [...] The post Attacking Smart Card Based Active Directory Networks appeared first on Ethical Chaos.

## Teleport Demo and Overview Video - Modern SSH

DevFeed: [Teleport Demo and Overview Video - Modern SSH](<https://devfeed.tech/articles/teleport-demo-and-overview-video-modern-ssh-29917.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/teleport-demo-video/>)

Author: ev@goteleport.com (Ev Kontsevoy)

Published: 2020-07-16T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [ssh](<https://devfeed.tech/topics/ssh.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Raspberry Pi](<https://devfeed.tech/topics/raspberry-pi.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [audit](<https://devfeed.tech/tags/audit.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [github](<https://devfeed.tech/tags/github.md>), [google](<https://devfeed.tech/tags/google.md>), [guide](<https://devfeed.tech/tags/guide.md>), [k8s](<https://devfeed.tech/tags/k8s.md>), [linux](<https://devfeed.tech/tags/linux.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [raspberry-pi](<https://devfeed.tech/tags/raspberry-pi.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [sso](<https://devfeed.tech/tags/sso.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

This video demonstrates how Teleport implements SSH best practices, including SSH certificates, single sign-on, browser and command-line access, centralized session auditing, Kubernetes access, and connections to edge devices such as a Raspberry Pi.

### Source excerpt

Teleport allows easy implementation of SSH best practices. Here is a video that takes a deep dive into how Teleport works.

## How to Setup MS AD FS 3.0 as Brokered Identity Provider in Keycloak

DevFeed: [How to Setup MS AD FS 3.0 as Brokered Identity Provider in Keycloak](<https://devfeed.tech/articles/how-to-setup-ms-ad-fs-3-0-as-brokered-identity-provider-in-keycloak-31562.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2017/03/how-to-setup-ms-ad-fs-30-as-brokered>)

Author: Hynek Mlnařík

Published: 2017-03-23T00:00:00Z

Content type: tutorial

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [saml](<https://devfeed.tech/topics/saml.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [idm](<https://devfeed.tech/tags/idm.md>), [installation](<https://devfeed.tech/tags/installation.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [tls](<https://devfeed.tech/tags/tls.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

A setup guide for configuring Microsoft Active Directory Federation Services 3.0 as a brokered SAML identity provider in Keycloak. It covers SSL/TLS prerequisites, certificate trust configuration, metadata import, signature settings, mapper configuration, and AD FS relying-party trust setup.

### Source excerpt

This document guides you through initial setup of Microsoft Active Directory Federation Services 3.0 as a brokered identity provider Keycloak. Prerequisites Two server hosts: Microsoft Windows Server 2012 with Active Directory Federation Services (AD FS) installed. The AD domain will be named DOMAIN.NAME in this post. Keycloak server. This can be generally placed anywhere but here it is expected to be running on separate host DNS setup: The Windows host name will be fs.domain.name in this post The Keycloak host name will be kc.domain.name in this post Setup Keycloak Server Keycloak server has configured for SSL/TLS transport - this is mandatory for AD FS to communicate with it. This comprises two steps: Setup keycloak for incoming HTTPS connections - steps are provided in Server Installation guide. Export AD FS certificate into a Java truststore to enable outgoing HTTPS connections: In the AD FS management console, go to Service -> Certificates node in the tree and export the Service communications certificate. Import the certificate into a Java truststore (JKS format) using Java keytool utility. Setup the truststore in Keycloak as described in Server Installation guide. Setup Identity Provider in Keycloak Setup Basic Properties of Brokered Identity Provider In the Identity Providers, create a new SAML v2.0 identity provider. In this post, the identity provider will be known under alias adfs-idp-alias. Now scroll to the bottom and enter the AD FS descriptor URL into Import from URL field. For AD FS 3.0, this URL is https://fs.domain.name/FederationMetadata/2007-06/FederationMetadata.xml. Once you click "Import", check the settings. Usually, you would at least enable Validate signature option. If the authentication requests sent to the AD FS instance are expected to be signed, which is also usually the case, you have to enable Want AuthnRequests Signed option. Importantly, then the SAML Signature Key Name field that shows after enabling the Want AuthnRequests Signed o

## GPO: Instalacja GIMP'a 2.8

DevFeed: [GPO: Instalacja GIMP'a 2.8](<https://devfeed.tech/articles/gpo-instalacja-gimp-a-2-8-27572.md>)

Original publisher: [Read original article](<https://gagor.pro/2013/08/gpo-instalacja-gimpa-2-8/>)

Author: Tom

Published: 2013-08-06T00:00:00Z

Content type: tutorial

Language: pl

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [Batch file](<https://devfeed.tech/topics/batch-file.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [enterprise deployment](<https://devfeed.tech/topics/enterprise-deployment.md>), [Script](<https://devfeed.tech/topics/script.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [code](<https://devfeed.tech/tags/code.md>), [gpo](<https://devfeed.tech/tags/gpo.md>), [install](<https://devfeed.tech/tags/install.md>), [installation](<https://devfeed.tech/tags/installation.md>), [policies](<https://devfeed.tech/tags/policies.md>), [startup](<https://devfeed.tech/tags/startup.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

A Polish tutorial explains how to deploy GIMP 2.8 through an Active Directory Group Policy startup script on Windows. The batch script checks whether GIMP is installed, silently removes an earlier manually installed version, and installs GIMP 2.8 from a network share.

### Source excerpt

Raz na jakiś czas trzeba coś niestandardowego wrzucić do instalacji w Active Directory a że nie wszystkie aplikacje mają dostępne paczki MSI to trzeba się nieco natrudzić. Poniżej wrzucam skrypt, który instaluje GIMP'a 2.8 z domyślnego instalatora (wersja InnoSetup) przy okazji odinstalowując wcześniejsze wersje zainstalowane ręcznie. Zapisujemy poniższy kod jako np. gimp-install.cmd @echo off REM Installs GIMP cls echo ---------------------------------------------------- echo . echo . echo . Installing/Updating GIMP - Please Wait echo . echo . echo ---------------------------------------------------- REM Test if actual IF exist "%ProgramFiles%\GIMP\bin\gimp-2.8.exe" GOTO SkipInstall REM Exit the application taskkill.exe /F /FI "IMAGENAME eq gimp-2.8.exe" >nul REM Uninstall existing GIMP version, delete folder if exist "%ProgramFiles%\GIMP 2\uninst\unins000.exe" "%ProgramFiles%\GIMP 2\uninst\unins000.exe" /VERYSILENT :: Wait for 20 seconds ping -n 40 127.0.0.1 > NUL if exist "%ProgramFiles%\GIMP 2\" rd "%ProgramFiles%\GIMP 2\" /Q /S REM Install new version "\\serwerplikow.local\Instalki\GIMP\gimp-2.8.4-setup.exe" /VERYSILENT /NORESTART /DIR="%PROGRAMFILES%\GIMP 2.8" REM Skip installation if acctuall :SkipInstall REM Return exit code to SCCM exit /B %EXIT_CODE% Tworzymy nową regułkę GPO i zmierzamy do: Computer Configuration\Policies\Windows Settings\Scripts\Startup W nowym okienku wybieramy Show Files... Wklejamy plik skryptu do tego folderu i teraz możemy dodać go w tym samym oknie (Add...) - dzięki wrzuceniu skryptu w tym miejscu będzie się on automatycznie replikować na inne kontrolery. Skrypt będzie co prawda uruchamiany przy każdym starcie komputera ale pierwszy warunek będzie sprawdzać czy aplikacja jest zainstalowana więc nie spowolni to znacznie startu.

## Fortigate - VPN IPSec PSK XAuth z Android'a 4.x

DevFeed: [Fortigate - VPN IPSec PSK XAuth z Android'a 4.x](<https://devfeed.tech/articles/fortigate-vpn-ipsec-psk-xauth-z-android-a-4-x-27565.md>)

Original publisher: [Read original article](<https://gagor.pro/2013/03/fortigate-vpn-ipsec-psk-xauth-z-androida-4-x/>)

Author: Tom

Published: 2013-03-30T00:00:00Z

Content type: tutorial

Language: pl

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>), [Android](<https://devfeed.tech/topics/android.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [iOS](<https://devfeed.tech/topics/ios.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [android](<https://devfeed.tech/tags/android.md>), [cli](<https://devfeed.tech/tags/cli.md>), [fortigate](<https://devfeed.tech/tags/fortigate.md>), [fortios](<https://devfeed.tech/tags/fortios.md>), [ios](<https://devfeed.tech/tags/ios.md>), [ipad](<https://devfeed.tech/tags/ipad.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [os](<https://devfeed.tech/tags/os.md>), [security](<https://devfeed.tech/tags/security.md>), [vpn](<https://devfeed.tech/tags/vpn.md>)

### AI overview

A tutorial on configuring a Fortigate IPsec XAuth PSK VPN for Android 4.x phones and tablets to access an intranet. It covers CLI-based VPN setup, firewall rules, DNS access, and optional routing to external services, with notes about iOS compatibility.

### Source excerpt

Do niedawna na moim telefonie VPN'ami były: PPTP lub L2TP - oba niespecjalnie mi się podobały. Ale od wersji 4-tej pojawiły się dwa nowe tryby: IPSec Xauth PSK i IPSec Xauth RSA. W pierwszym autoryzacja wykorzystuje login i hasło, w drugim certyfikaty. Tryb IPSec Xauth PSK jest bardzo wygodny bo łatwo można połączyć go z zewnętrznymi mechanizmami uwierzytelniającymi np. LDAP, Active Directory, itp. Pokażę jak skonfigurować swojego Fortigate'a by umożliwić połączenie z telefonów i tabletów na Androidzie 4.x do "Intranetu"1. Większość konfiguracji można przeprowadzić tylko w trybie CLI - zakładam że wiesz jak to zrobić. To co wygodniej można zrobić w trybie WWW to głównie tworzenie reguł dostępu na zaporze.

## Apache: mod\_authnz\_ldap z Active Directory

DevFeed: [Apache: mod\_authnz\_ldap z Active Directory](<https://devfeed.tech/articles/apache-mod-authnz-ldap-z-active-directory-27556.md>)

Original publisher: [Read original article](<https://gagor.pro/2012/12/apache-mod_authnz_ldap-z-active-directory/>)

Author: Tom

Published: 2012-12-14T00:00:00Z

Content type: tutorial

Language: pl

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [active directory](<https://devfeed.tech/topics/active-directory.md>), [Caching](<https://devfeed.tech/topics/caching.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [apache](<https://devfeed.tech/tags/apache.md>), [cache](<https://devfeed.tech/tags/cache.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [linux](<https://devfeed.tech/tags/linux.md>)

### AI overview

A Polish tutorial explains how to configure Apache authentication against Active Directory using LDAP and mod_authnz_ldap, including module activation, LDAP caching, virtual host settings, bind credentials, and access requirements.

### Source excerpt

Gdy już się dorobi systemu Active Directory wygodnie jest wykorzystać jego bazę użytkowników do autoryzacji w różnych miejscach, np. do pewnych "tajnych i tajniejszych" stron w Apache. Najprościej można to zrobić z wykorzystaniem LDAP. Warto sprawdzić czy i jak możemy dostać się do kontrolerów. Gdy już mamy wszystkie potrzebne parametry konfigurujemy Apachego - na początek aktywujemy moduły: a2enmod ldap a2enmod authnz_ldap Teraz możemy edytujemy globalny plik konfiguracyjny mod_ldap'a by ustawić nieco cache'y (bardzo przydatne). Wartości można dostosować do potrzeb ale przykładowe powinny wystarczyć na początku:

## ldapsearch w Active Directory

DevFeed: [ldapsearch w Active Directory](<https://devfeed.tech/articles/ldapsearch-w-active-directory-27558.md>)

Original publisher: [Read original article](<https://gagor.pro/2012/12/ldapsearch-w-active-directory/>)

Author: Tom

Published: 2012-12-05T00:00:00Z

Content type: tutorial

Language: pl

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [active directory](<https://devfeed.tech/topics/active-directory.md>), [apt](<https://devfeed.tech/topics/apt.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [apt](<https://devfeed.tech/tags/apt.md>), [bash](<https://devfeed.tech/tags/bash.md>), [info](<https://devfeed.tech/tags/info.md>), [install](<https://devfeed.tech/tags/install.md>), [ip](<https://devfeed.tech/tags/ip.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [port](<https://devfeed.tech/tags/port.md>)

### AI overview

A Polish tutorial explains how to use ldapsearch from Linux to query and test access to Active Directory through LDAP. It covers installing ldap-utils, searching the directory, configuring search bases and credentials, applying filters, and extracting user logins or email addresses.

### Source excerpt

Można lubieć AD, można go nie lubieć... Ale jak już się ma to warto czasem zintegrować go z tym... i tamtym... Od strony Linuksa najwygodniej można to osiągnąć przez LDAP. A żeby to dobrze zrobić trzeba najpierw przetestować czy aby wszystko działa jak byśmy sobie tego życzyli. I tutaj bardzo przydatne jest narzędzie ldapsearch. Do odpytywania LDAP'a potrzebujemy jeden pakiecik, który zawiera kilka narzędzi do jego obsługi: apt-get install ldap-utils Teraz możemy próbować przeszukiwać katalog np. tak: