Guardian of the Directory

Guardians of the Directory

Guardians of the Directory is the podcast for everything Active Directory security, management, and recovery. Join us as we dive into best practices, recent security events, listener Q&As, and expert interviews to equip you with the skills needed to protect your AD environment. Whether you’re an IT pro or a cybersecurity enthusiast, each episode delivers actionable insights to help you stay informed and secure. Become a Guardian of the Directory and tune in to strengthen your defenses!

Author

Guardian of the Directory

Category

Technology

Podcast website

podcasters.spotify.com

Latest episode

Aug 21, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Hybrid Identity is Broken: Rethinking AD, Entra ID & the Bridge in Between 21.08.2025

Welcome to another episode of Guardians of the Directory , where we pull back the curtain on the real-world challenges in securing and managing Active Directory and hybrid identity environments. In this episode, Craig Birch is joined by Sander Berkouwer , identity veteran, Microsoft MVP, and author of the Active Directory Administration Cookbook , to have a brutally honest conversation about hybri...

Blueprinting Zero Trust From: Strategy to Execution with Jerry Chapman 26.06.2025

Welcome back to Guardians of the Directory ! In this episode, Craig Birch is joined once again by Zero Trust expert Jerry Chapman for a deep dive into the Zero Trust Blueprint—a practical model to help organizations shift from theory to execution. Jerry shares insights from his work as Co-Chair of the CISA Zero Trust Working Group and provides a clear framework covering assessment, strategy, roadm...

AdminSDHolder in Active Directory: Hidden Risks and Persistent Threats 01.05.2025

In this episode of Directory Insights in 10 Minutes, Craig Birch breaks down the often-misunderstood AdminSDHolder object in Active Directory and why it's a high-value target for attackers. Learn how the SDProp process uses it to secure privileged groups—and how misconfigurations or legacy permissions can open the door to persistent access.🔍 What you’ll learn:What AdminSDHolder and SDProp really...

Admin Accounts with SPNs — Hidden Risk Behind Kerberoasting 15.04.2025

🔍 Admin Accounts with SPNs — Hidden Risk Behind Kerberoasting | Directory Insights in 10 MinutesIn this episode, Craig Birch breaks down a major Active Directory security blind spot: Kerberoasting via privileged accounts with SPNs (Service Principal Names).You'll learn how attackers exploit these accounts — and how to find, assess, and fix the risk without breaking your apps. Straightforward,...

Kerberos Pre-Auth: Hidden AD Risk 09.04.2025

In this episode of Directory Insights in 10 Minutes, Craig Birch breaks down one of the most overlooked Active Directory misconfigurations: the "Do not require Kerberos pre-authentication" setting.🔍 Why it matters:Enables AS-REP Roasting attacks using tools like Hashcat or John the RipperAllows silent user enumeration without authentication failuresCan go undetected by SIEMs and securit...

Directory Insights in 10 Minutes: Remediating DES Encryption in Active Directory 01.04.2025

Welcome to another episode of Directory Insights in 10 Minutes , powered by Guardians of the Directory . In this quick-hitting session, host Craig Birch walks through the process of identifying and remediating accounts in Active Directory that still rely on outdated Kerberos DES encryption . 🔐 DES is insecure and easily exploited by attackers. Craig shows you how to detect and update these accoun...

Directory Insights in 10 Minutes Reversible Password Encryption – A Hidden Risk 18.03.2025

Summary: In this episode of Directory Insights in 10 Minutes , we dive into a critical yet often overlooked Active Directory misconfiguration — Allowing Password Storage with Reversible Encryption. This setting can override password policies , leaving user credentials exposed to plaintext extraction through common attacker tools like Mimikatz and DCSync . 🚨 Key Takeaways: ✅ How this misconfigura...

Directory Insights in 10 minutes: Password Not Required - The Hidden Risk 11.03.2025

Episode Overview In this episode of Directory Insights in 10 Minutes , we’re exposing a dangerous yet overlooked Active Directory misconfiguration— PasswordNotRequired . Most AD admins assume password policies protect all accounts. They don’t. This attribute allows accounts to override domain password policies, making them vulnerable to blank passwords and easy takeovers. What is the "Passwor...

Directory Insights in 10 Minutes: AD’s Biggest Misconfiguration – Fix It Now! 03.03.2025

Directory Insights in 10 Minutes – Episode 1 🛡️ AD’s Biggest Misconfiguration – Fix It Now! Description: Welcome to the first episode of Directory Insights in 10 Minutes , brought to you by Guardians of the Directory . This series is all about cutting through the noise —no fluff, no filler—just real-world, practical security insights for Active Directory and Entra ID admins. In this episode, we’re...

25 Years of Active Directory: Past, Present & Future! 18.02.2025

Summary In this episode of Guardians of the Directory, host Craig Birch interviews Kevin Kampman, a veteran in directory services, discussing the evolution of Active Directory, its challenges, and the future of directory management. They explore the historical context of directory services, the impact of cloud technology, and the importance of naming conventions in directory management. Kevin shar...

Zero Trust Unveiled: A Cybersecurity Essential 28.01.2025

Summary In this episode of Guardians of the Directory, Craig Birch and Jerry Chapman delve into the concept of Zero Trust in cybersecurity. They discuss its principles, models, and the importance of identity-led security. The conversation highlights the five pillars of Zero Trust, the challenges organizations face with data management, and the complexities of securing applications in a cloud envir...

Recovery Dilemma: Restoring Without Risking Reinfection 20.01.2025

Chad Nichols discusses the complex challenge of restoring Active Directory after a ransomware attack without risking reinfection. He sheds light on the pitfalls of traditional backup methods, which often carry residual malware, and stresses the importance of clean recovery strategies. This critical insight highlights the balance between operational urgency and long-term security.

From Red Team to Teacher: Transforming Cybersecurity Knowledge into Community Power 08.01.2025

Summary In this episode of Guardians of the Directory, host Craig Birch engages with John Harper, founder of Hackers Teaching Hackers, to discuss the evolution of cybersecurity education, the importance of community sharing, and the vulnerabilities within Active Directory. They explore the offensive security landscape, the significance of hands-on learning, and practical strategies for strengtheni...

Active Directory's Dark Side: Underbelly Threats and Shadowy Permissions 23.12.2024

In this episode of Guardians of the Directory, Craig Birch and Derek Melber delve into the complexities of Active Directory security, focusing on the stealthy threats posed by shadow permissions, DC Shadow, and DC Sync. They discuss the historical context of these vulnerabilities, the role of applications in creating shadow permissions, and the importance of cleaning up orphaned SIDs. The conversa...

Hacked Hallways: Cyber Threats in K-12 Education 13.12.2024

Summary This conversation delves into the critical issue of cybersecurity in K-12 education, highlighting the vulnerabilities schools face due to budget constraints, lack of training, and the unique challenges of supporting a diverse student population. Jason, an IT expert, shares insights on the value of school data to cybercriminals, recent case studies of cyber attacks, common attack methods, a...

Active Directory Recovery Post Ransomware 27.11.2024

In this episode of Guardians of the Directory, Craig Birch and Chad Nichols discuss the critical steps needed to recover from a ransomware attack that targets Active Directory. They explore the challenges organizations face during such attacks, the importance of having a solid recovery strategy, and the lessons learned from real-world experiences. The conversation emphasizes the need for preparedn...

Trailer: Guardians of the Directory: Defending the Backbone of Enterprise Security 14.11.2024

In this inaugural episode of Guardians of the Directory, join Craig Birch, Principal Security Engineer and Technical Evangelist at Cayosoft, as he introduces himself and the mission of this podcast dedicated to Active Directory (AD) and Entra ID management, security, and recovery. With over two decades of experience in identity security and a passion for helping AD administrators and security prof...

Beyond Defense: Why Traditional Defenses against Ransomware Fail 14.11.2024

Summary In this episode of Guardians of the Directory, Craig Birch and Mike Brennan discuss the evolving landscape of cybersecurity, particularly focusing on identity security and the challenges organizations face in preventing ransomware attacks. They explore the inadequacies of traditional security measures, the importance of proactive strategies, and the need for continuous monitoring and moder...

Listen to the Guardians of the Directory podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.