• Kissaki@feddit.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      1 day ago

      AD is a security nightmare. EntraID requires internet but at least allows zero trust with diverse configuration and importantly without storing or holding session tokens or passwords locally.

      For my company, the only blocker is file share, which can be migrated. All our with integration use ldap and can be migrated to openid. Luckily we don’t have more AD integrated stuff.

      • NaibofTabr@infosec.pub
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        16 hours ago

        AD is a security nightmare.

        True, but so are all of the cloud platforms, so that doesn’t really set it apart. Being legacy tech at this point without a lot of new code being added regularly, most of the weaknesses are pretty well understood.

        EntraID requires internet but at least allows zero trust

        Yeah I’m not convinced that Microsoft as an entity actually grasps the concept of zero trust. I think they likely have their own internal definition of it, just like they had their own definition of web standards back in the Internet Exploder days.

        Look at what happened recently with Edge, where they claimed that storing user credentials in cleartext was “intended behavior”:

        https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-to-stop-loading-cleartext-passwords-in-memory-on-startup/