Active Directory improvements in Windows Server 2025

  • Thread starter Thread starter Dan Cuomo
  • Start date Start date
D

Dan Cuomo

Spoiler (Highlight to read)

Windows Server 2025 is the most secure and performant release yet! Download the evaluation now!



Looking to migrate from VMware to Windows Server 2025? Contact your Microsoft account team!

Windows Server 2025 is the most secure and performant release yet! Download the evaluation now! Looking to migrate from VMware to Windows Server 2025? Contact your Microsoft account team!

The 2024 Windows Server Summit was held in March and brought three days of demos, technical sessions, and Q&A, led by Microsoft engineers, guest experts from Intel®, and our MVP community. For more videos from this year’s Windows Server Summit, please find the full session list here.



This article focuses on improvements to Active Directory in Windows Server 2025.



What's new in Active Directory for Windows Server 2025​




The AD product group presents and demonstrate some of the new AD capabilities coming in Windows Server 2025, including new functional levels, security enhancements, and improved scalability.






Protecting Active Directory from management plane attacks​




Mind the management plane! Whether your organization is running Active Directory on-premises, hybrid, or fully in the cloud, virtualized domain controllers are almost always present. But when is the last time you checked to ensure your privileged access model, aka Tier 0, extended to encompass the management plane?

Explore the common modern deployment scenarios for virtualized domain controllers and examine the relationship with the management plane. Why? Because attackers can exploit a weakly implemented privileged model and use the management plane as an easy back door into Active Directory.

In this session, we explore scenarios where organizations can unknowingly leave the door open to these attacks, diving deep into commonly observed gaps, and walking through a demonstration of using the management plane as a means of pivoting into Active Directory. Learn how to defend yourself and get actionable recommendations your organization can take today to ensure that the management plane does not become an attacker’s new friend.






The evolution of Windows authentication​




As the security landscape evolves, Windows must continue to change to protect users and organizations. Foundational to this is user authentication. In Windows Server 2025 and Windows vNext, we have created completely new Kerberos features to minimize use of NTLM in your environments. This session explains and demonstrates IAKerb, Local KDC, IP SPN, and the roadmap to the end of NTLM.

Continue reading...
 
Back
Top