Source: 7 signs it’s time for a managed security service provider | CSO Online
Author: unknown
URL: https://www.csoonline.com/article/4041752/microsoft-entra-private-access-brings-conditional-access-to-on-prem-active-directory.html
ONE SENTENCE SUMMARY:
Microsoft Entra enhances security for on-premises Active Directory by integrating with its Zero Trust framework and removing NTLM dependency.
MAIN POINTS:
- Attackers still target on-premises Active Directory installations for network access.
- Microsoft Entra provides conditional access and MFA for on-premises systems.
- Entra Private Access aims to replace VPNs and internal Active Directory resources.
- Requires Kerberos authentication; NTLM must be removed from the network.
- Global Secure Access Administrator role needed for Entra ID setup.
- Requires Windows 10 or higher, and devices must be Entra or hybrid joined.
- Firewall rules include opening TCP port 1337 on domain controllers.
- Test with private apps first to avoid admin lockout issues.
- Audit NTLM usage to enable secure transitions to NTLMv2 and Kerberos.
- Transition involves blocking NTLM and updating affected applications.
TAKEAWAYS:
- Entra integration enhances security for traditional Active Directory setups.
- Eliminating NTLM increases network resilience against ransomware.
- Proper role and licensing are essential for deployment.
- Testing and auditing are critical for a smooth transition process.
- Removing NTLM is challenging but crucial for modern security.