Recent Blog ArticlesNewest TopicsMost LikesTagged:TagProtect Tier 1. Sleep well at Night. In case you have not yet protected Tier 0, consider reviewing our article about protecting Tier 0 the modern way. Tier 1 is more difficult to outline as there are typically different security ...Seamless Security: Smartcard Logon from Entra-Only Machines to domain-joined Servers or AVDs There’s still life in the old dog yet: Even though many consider smart cards as obsolete, with MFA phishing becoming an increasing significant threat, this authentication method is experiencing a ren...Protecting Tier 0 the Modern Way Almost every attack on Active Directory you hear about today – no matter if ransomware is involved or not – (ab)uses credential theft techniques as the key factor for successful compromise. Microsoft...The Nightmare of Validating Certificate Requests At CRSP we help customers to recover from different types of cyber security incidents. This means that we help more or less with wherever help is needed (from hardening AD and AAD, to restoring Excha...NDES Security Best Practices NDES (Network Device Enrollment Server) - if misconfigured or not secured and hardened properly - can be a door opener for the compromise of an Active Directory. Intune - Enrollment Options for End-Entity Certificates Intune supports three different methods to provision certificates to devices or users (SCEP/NDES, PKCS and Imported PKCS). The following article tries to explain the different methods in terms of sec...