#adfs — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #adfs, aggregated by home.social.
-
Reminder: Die gültigen #Zertifikat-Laufzeiten schrumpfen.
🟡 15. März 2026: 200 Tage ☹️
🟠 15. März 2027: 100 Tage 🤢
🔴 15. März 2029: 47 Tage 🤮Unser Status:
✅ #LetsEncrypt (wo einfach möglich) aktiviert
✅ 30-Tage-Zertifikate der internen AD CS PKI für Intranetdienste auf #WindowsServer und #Linux mit #PowerShell vollautomatisiert
⏳ AD FS, Exchange#sysadmin #admin #itsicherheit #zertifikate #tls #ssl #reminder #adcs #adfs #pki #intranet #internet
-
/* Calculate the boot block checksum on an ADFS drive. Note that this will appear to be correct if the sector contains all zeros, so also check that the disk size is non-zero!!! */
https://elixir.bootlin.com/linux/v6.15.6/source/include/linux/adfs_fs.h#L7-L11
-
Используй MFA, Люк: как второй фактор помогает защитить подключения
Да пребудет с вами сила, хабравчане! Меня зовут Кирилл Подсухин, я technical product manager в компании Контур. Я вместе с командой разработал систему двухфакторной аутентификации Контур.ID. Я часто представляю нашу команду как джедаев, которые борются с ситхами — злоумышленниками, которые пытаются завладеть логинами и паролями сотрудников. Преступники делают это кучей разных способов, а мы, как силы добра, им противостоим. Собственно, о том, какие существуют атаки и как двухфакторная аутентификация помогает нам защитить данные, я и хочу рассказать. Материал будет интересен ИБ-специалистам да и просто всем, кто хочет разобраться в вопросе получше.
https://habr.com/ru/specials/881352/
#безопасность #безопасность_данных #аутентификация #двухфакторная_аутентификация #adfs #2fa #radius #ssh #защита_данных
-
Hackers Using Fake Microsoft ADFS Login Pages to Steal Credentials https://hackread.com/hackers-fake-microsoft-adfs-login-pages-steal-credentials/ #Cybersecurity #PhishingScam #CyberAttack #Microsoft #Security #Phishing #ADFS #Scam #MFA
-
Phishing Campaign Bypasses Microsoft ADFS MFA: Protect Your Organization - https://www.redpacketsecurity.com/sophisticated-phishing-attack-bypasses-microsoft-adfs-mfa/
-
Настройка SSO Авторизации Для BookStack
Одним из наиболее удачных сервисов (среди мне известных ) для хранения внутренней документации является BookStack . По тому как его развернуть и выполнить Базовую настройку можно прочитать на ОФ сайте, там прекрасная документация. Но вот вопрос настройки авторизации SSO используя ADFS информация достаточно поверхностная, да и то что в инете можно найти требует достаточно глубоких знаний темы. Посему решил поделиться компиляцией информации по данному вопросу
-
Running your own #ADFS doesn't seem to be too bad to me right now.
-
This is an absolutely brutal takedown of #Microsoft. How they aren't drowning in lawsuits. 🤷♂️
I totally understand the resistance to disabling smart card #SSO for the US govt. That's a huge change (but NYPD did it 🤔)
But MS should have been working on this non stop to help detect/mitigate. Then to outright lie about when they knew.
How any security professional could say 'well it requires access to the server' as a boundary. 😂
#SolarWinds #ADFS #InfoSec #SAML
https://www.propublica.org/article/microsoft-solarwinds-golden-saml-data-breach-russian-hackers
-
Two posts in 1 day! One of the last reasons that you might still need ADFS just got removed. https://techcommunity.microsoft.com/t5/microsoft-entra-blog/public-preview-external-authentication-methods-in-microsoft/ba-p/4078808. #infosec #microsoft365 #ADFS
-
Can you put #ExchangeServer into a disconnected or one-way-tusted resource forest and use #ADFS federation or Hybrid Modern Auth to authenticate users?
Can you combine this with #EntraID Application Proxy?
-
𝗦𝗶𝗺𝗽𝗹𝗶𝗳𝗶𝗲𝗱 𝗱𝗲𝗽𝗹𝗼𝘆𝗺𝗲𝗻𝘁 𝘄𝗶𝘁𝗵 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿 𝗳𝗼𝗿 𝗜𝗱𝗲𝗻𝘁𝗶𝘁𝘆
"Microsoft Defender for Identity is an essential part of a modern security practice, helping your organization protect against, and respond to, identity-based threats. In this blog we will show you the simple steps for deploying Microsoft Defender for Identity within your environment."
#defenderforidentity #mdi #microsoft #microsoftsecurity #defender #adfs #domaincontroller #activedirectory #itdr #azure #adfs #adcs #deployment
-
Anybody use `asdf` or `ASDF` as your visual queue for a "content placeholder" or a "TODO"?
I use that left-hand home row of QWERTY keys as a placeholder all the time, so it makes #ADFS (active directory federation services) look like a typo when I see it.
My brain is silly.
-
Microsoft Defender for Identity (#MDI) on #ADFS. Did you know that after installing the sensor on ADFS, you must make one important setting or the sensor will not run at all?
I mentioned last time that installing MDI on ADFS is supported. A lot of administrators don't know this or don't consider it important and don't install Microsoft Defender for Identity on ADFS. Yet ADFS is very often the entry point for a threat actor. And when they do install the sensor, they are surprised that the sensor doesn't run and don't know why...
After installing the sensor on ADFS, you need to make one important setting in the Microsoft Defender for Identity setting portal - set the FQDN of at least some domain controllers via clicking on the ADFS server. Without this setting, the sensor on ADFS will not boot at all and less experienced administrators usually have no idea why.
-
Are you monitoring what's happening in your local Active Directory?
Microsoft Defender for Identity (#MDI#MDI) is a cloud service that monitors your local Active Directory. It collects many different signals, such as Windows Events or logs, but it also collects and evaluates network traffic. Data for Microsoft Defender for Identity is collected by agents that are installed on domain controllers or #ADFS#ADFS servers. Alternatively, if direct installation is not possible, standalone agents can be used to which logs and traffic itself are forwarded via port mirroring. Data evaluation is then performed in the cloud and no additional local infrastructure is needed.
Microsoft Defender for Identity can detect many different attacks on local identities, such as #Pass#Pass-The-Hash, Golden Ticket attacks, environmental scanning, and many others. However, a very powerful component is machine learning, which learns the standard behavior of individual objects in Active Directory, based on which it is then able to detect anomalies.
-
Complete guidance on how to get off of that ADFS narcotic.
"Active Directory Federation Services (AD FS) decommission guide" | Microsoft Learn
https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/decommission/adfs-decommission-guide
#adfs #AzureAD #identity #msftadvocate -
I recently finished recording a video with @ramirocld showing the last few steps you would need to take to fully migrate from #adfs to #azuread. https://youtube.com/watch?v=D0M-N-RQw0I&si=EnSIkaIECMiOmarE. It’s about 10 mins but lots of folks skip over these last few remaining steps. There is also a free workshop running next week where we go in depth on the full process that’s time zone friendly https://techcommunity.microsoft.com/t5/community-events-list/microsoft-workshops-how-to-successfully-migrate-away-from-ad-fs/td-p/3668480. If you attend the Americas one you’ll hear @JefTek, @jorgelopez and myself talking through it and taking your questions.
-
… and yes, those new floppy discs do work. 😁👍
2023 and I’m formatting 5.25” disks like a pro. 😆
-
Are you a #Microsoft #ActiveDirectory / #M365 / #AzureAD administrator? Do you live in the Louisville KY Area? Do you like free food? Come check out this month's LouMUG talk where I'll be discussing challenges and how migrate from #ADFS to #AzureAD for authentication. The event is Friday, 2023-01-27 11:00-1:00. It's a great networking opportunity.
https://www.loumug.org/moving-off-of-adfs/ -
If you are still using #ADFS next week there are 3 free workshops you should look to attend, each time zone friendly to EMEA, APAC and Americas. They cover migrating your apps off of #adfs to #azuread and how to flip the authentication from #adfs to #azuread. If this is something you'd wanted to do but were sure the steps to take, all of that will be covered as well as HOW you can go make the case to your leadership teams to get time and resources to work on this. Sign-up here https://techcommunity.microsoft.com/t5/community-events-list/upcoming-microsoft-workshops-how-to-successfully-migrate-away/m-p/3668480
-
I was asked recently to help provide my experiences with migration from federated to cloud authentication with #AzureAD.
While I may not work in a consulting role these days, I wanted to share my learnings working with customers, and included some solid community advice.
#aad #entra #azure #azureactivedirectory #adfs
https://ericonidentity.com/2022/12/01/field-notes-migration-from-federation-to-cloud-authentication/
-
A step-by-step guide to create golden SAML