Guardian of the Directory

Directory Insights in 10 Minutes

Real-world Active Directory and Entra ID security insights. No fluff. No filler. Just fast, tactical episodes built for overworked IT admins who need answers now. Every other week, we break down misconfigurations, attack paths, recovery gaps, and hybrid identity threats — all in 10 minutes or less. Whether you're chasing down a DCSync abuse, cleaning up toxic permissions, or trying to stay ahead of attackers, this series gives you actionable steps you can implement today.🎧 New episodes drop bi-weekly💡 Built for IT pros who just get it done🎙 Powered by Guardians of the Directory

Author

Guardian of the Directory

Category

Technology

Podcast website

podcasters.spotify.com

Latest episode

Aug 4, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Scattered Spider, ESX Admins, and the Built-In Backdoor to Root 04.08.2025

In this episode, Craig Birch breaks down how Scattered Spider , also known as Octo Tempest , is exploiting a built-in trust relationship between Active Directory and VMware ESXi to escalate privileges and deploy ransomware — all without triggering traditional security tools. Learn how the ESX Admins group becomes an unintentional backdoor to root access on every ESXi host in your environment, and...

Exposing the DNS Danger: Unsecure Dynamic Updates in Active Directory 21.07.2025

Welcome to Directory Insights in 10 Minutes , a bite-sized cybersecurity briefing from Guardians of the Directory . I’m your host, Craig Birch—Principal Security Engineer and Identity Security Enthusiast. In this episode, we dive into a critical misconfiguration that still lurks in many AD environments : DNS zones allowing unsecure dynamic updates. 🔍 Here’s what we cover: What dynamic updates are...

Hidden Admins: How Non-Standard Primary Group IDs Expose Active Directory to Risk 11.07.2025

Welcome to Guardians of the Directory , the podcast where we break down real-world threats, best practices, and insights in Active Directory, Entra ID, and Microsoft identity security. In today’s episode, Craig Birch dives into one of Active Directory’s oldest — and most quietly dangerous — features: the primaryGroupID . While originally designed for POSIX compatibility and legacy systems, this at...

Hidden in Plain Sight: Exposing Shadow Admins in Active Directory 28.05.2025

Shadow admins might not wear capes—but they can bring down your Active Directory if left unchecked. In this episode of Directory Insights in 10 Minutes , Craig Birch takes a sharp dive into AD delegations that slip through the cracks—commonly misconfigured permissions that give users dangerous access without being in official admin groups. You'll learn: What shadow admins are and why they’re s...

AdminSDHolder in Active Directory: Hidden Risks and Persistent Threats 15.05.2025

🎙️ In This Episode of Directory Insights in 10 Minutes Craig Birch breaks down the misunderstood AdminSDHolder object and the SDProp process in Active Directory—why they exist, how they protect privileged groups, and how attackers exploit misconfigurations to maintain persistence. 🔍 What You’ll Learn: • What AdminSDHolder and SDProp actually do • Why they matter for Tier 0 group protection • How...

Admin Accounts with SPNs — Hidden Risk Behind Kerberoasting 15.05.2025

🎙️ In this episode, Craig Birch breaks down one of Active Directory’s most overlooked threats: Kerberoasting via privileged accounts with Service Principal Names (SPNs) . You’ll learn how attackers exploit this common misconfiguration to extract service tickets and crack credentials offline — and how to identify and fix these accounts without breaking critical apps. • What SPNs are — and why they...

Kerberos Pre-Auth: Hidden AD Risk 15.05.2025

🎙️ In this episode, Craig Birch exposes one of the most overlooked Active Directory misconfigurations: the “Do not require Kerberos pre-authentication” setting. Attackers love it — it enables AS-REP Roasting , silent user enumeration, and offline password cracking — and it often flies under the radar of SIEMs and detection tools. • What Kerberos pre-auth actually does • How disabling it creates an...

Remediating DES Encryption in Active Directory 15.05.2025

🎙️ In this episode of Directory Insights in 10 Minutes , powered by Guardians of the Directory , Craig Birch walks you through detecting and remediating a legacy misconfiguration that still haunts many AD environments: accounts limited to DES-only Kerberos encryption . DES is weak, deprecated, and easily cracked — yet it's still lurking in environments where older configurations or forgotten a...

Reversible Password Encryption – A Hidden Risk 15.05.2025

🎙️ In this episode, Craig Birch dives into a critical but often overlooked AD misconfiguration : accounts that allow password storage with reversible encryption . This setting can bypass your domain password policies and expose credentials to plaintext extraction by tools like Mimikatz or DCSync . 🔍 What You’ll Learn: • Why reversible password encryption is still found in AD environments • How it...

Password Not Required - The Hidden Risk 15.05.2025

🎙️ In this episode, Craig Birch exposes one of the most dangerous and overlooked misconfigurations in Active Directory: the PasswordNotRequired attribute. Most AD admins assume password policies apply to all accounts — but this hidden flag allows accounts to exist with blank passwords , silently bypassing domain-wide protections. Attackers know it. Many admins don’t. 🔍 What You’ll Learn:• What th...

Protecting Admin Accounts from Kerberos Delegation Attacks 15.05.2025

Directory Insights in 10 Minutes – Episode 1 Welcome to the very first episode of Directory Insights in 10 Minutes , brought to you by Guardians of the Directory . This series cuts through the noise — no fluff, no filler — just real-world, actionable insights for securing Active Directory and Entra ID . In this kickoff episode, Craig Birch reveals the #1 most overlooked AD misconfiguration — one t...

Listen to the Directory Insights in 10 Minutes podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.