Comment on Anybody here running AD on-prem in your homelab?
Godort@lemm.ee 11 months agoI agree that for this size of network AD is definitely not something you want to deal with unless you want to learn how it works.
However, I’m not sure it really increases attack vectors to have it running, outside of the fact that it’s a new network service on the LAN. The out of the box default configuration is not bad these days, security-wise
Unforeseen@sh.itjust.works 11 months ago
The attack vectors I’m thinking of just come from the inherent complexity and centralization. I’m just considering the amount of damage that can be done with a compromised DA account for example vs a non directory environment.
It’s complicated. Done right it can be more secure, not done right it’s less secure.
I also only get brought in for problems for the last however many years, so I’m probaby a bit biased at this point haha.
I have had to tell companies they are going to have to rebuild thier AD from scratch because they didn’t know what thier DSRM password was (usually after a ransomware attack). These are the sort of hassles I think about vs non AD.
wreckedcarzz@lemmy.world 11 months ago
For the rest of us: DSRM
MigratingtoLemmy@lemmy.world 11 months ago
I’ll keep that in mind, thank you