{"id":1824,"date":"2018-08-14T08:39:55","date_gmt":"2018-08-14T08:39:55","guid":{"rendered":"https:\/\/www.teal-consulting.de\/2018\/08\/14\/esae-serie-teil-3-privileged-access-management-und-shadow-principals-feature\/"},"modified":"2019-12-17T11:21:55","modified_gmt":"2019-12-17T11:21:55","slug":"esae-series-part-3-privileged-access-management-and-the-shadow-principal-feature","status":"publish","type":"post","link":"https:\/\/www.teal-consulting.de\/en\/2018\/08\/14\/esae-series-part-3-privileged-access-management-and-the-shadow-principal-feature\/","title":{"rendered":"ESAE series part 3 &#8211; Privileged access management &#038; the shadow principal feature"},"content":{"rendered":"<div class=\"wpb-content-wrapper\">[vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text]\n<div class=\"ebd-block \" data-type=\"text\">\n<p>As already announced in the last article\u00a0(<a class=\"\" title=\"\" href=\"\/en\/2018\/05\/03\/esae-series-part-2-customer-situation-and-architecture\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong data-redactor-tag=\"strong\" data-verified=\"redactor\">LINK<\/strong><\/a>) of the ESAE series, in this article we would like to give you a more in-depth description of the technical core of the ESAE-oriented environment which makes the just-in-time administration possible. This core consists of the shadow principals, temporary group memberships and the new Microsoft Identity Manager (MIM) module &#8216;Privileged Access Management (PAM)&#8217;.<\/p>\n<h3>Conceptual functionality<\/h3>\n<p>Firstly, we&#8217;d like to briefly describe how temporary group memberships and shadow principals Work on their own before we explain the interaction with MIM in more detail.<\/p>\n<h3>Temporary group memberships<\/h3>\n<p>Temporary group memberships are part of the optional AD feature &#8216;Privileged Access Management&#8217; of Windows 2016. As the name implies, it allows for user accounts to only be members of a group for a limited time.<\/p>\n<p>The Active Directory ensures that the group membership expires at exactly the requested time by setting the Kerberos Ticket Granting Ticket (TGT) lifetime to the same runtime as the shortest time to live (ttl) of a group membership.<\/p>\n<p>An example: at log-in, user Ren\u00e9 has a remaining time of 5 minutes in the Domain Administrators group and a remaining time of 10 minutes in the Enterprise Administrators group. The domain controller then issues a TGT with a runtime of 5 minutes.<\/p>\n<p>Temporary group memberships could also be used independently, without shadow principals and MIM-PAM and configured via PowerShell (see below).<\/p>\n<h3>Shadow principals<\/h3>\n<p>A shadow principal is an object that represents a user, group, or computer account from another forest. The shadow principals are also part of the PAM feature. In order to use a shadow principal for the access of resources, a new kind of trust is required: the PAM trust. The PAM trust is an extension of the well-known forest trust.<\/p>\n<p>In order to be able to use the shadow principals for our purposes, a so-called admin forest (or red forest) is set up in addition to the production forest and a PAM trust is established. The production forest trusts the admin forest.<\/p>\n<p>Shadow principals can subsequently be created in the admin forest which contain the SID of groups, e.g. the Domain Administrators group, in the production forest. In the next step, users in the admin forest are added to the &#8216;memberof&#8217; attribute of the shadow principals. If the user of the admin forest from the example then logs in to a resource in the production forest, he or she carries the SID of the domain admin group along with the ticket and is able to perform respective privileged activities such as DCPromo, scheme extensions, etc.<\/p>\n<p>Shadow principals can also be used without temporary group memberships and MIM-PAM and can be configured via PowerShell.<\/p>\n<h3>MIM-PAM<\/h3>\n<p>Bearing in mind that you can receive privileges in the production forest through the shadow principals without having a user account in this forest, there are some advantages. For example, there is no way for tools like Bloodhound to identify users with these rights. However, this technique also poses dangers. With Active Directory tools, it is very difficult to monitor who used the elevated rights and when. This is where the MIM with PAM functionality comes into play to bring together the other two technologies for just-in-time administration with appropriate governance.<\/p>\n<p>When MIM-PAM is implemented, no user account in the admin forest is a member of a shadow principal per se. Via MIM-PAM, roles are defined which regulate who can request which privileges and for how long. An approval workflow can also be defined.<\/p>\n<p>As an example, there might be a role called &#8216;domain admin&#8217; which adds users to the shadow principal &#8216;domain administrators&#8217;. The role may be requested by users Fabian and Manuel between 8am and 4pm. User Alexander has to approve the request. The role has a runtime of 60 minutes.<\/p>\n<p>The roles can be requested either via PowerShell or via an optional portal. The request and assignment of the roles will be logged accordingly.<\/p>\n<p><b data-redactor-tag=\"b\">Technical functionality<\/b><\/p>\n<h3>Temporary group memberships<\/h3>\n<p>For temporary group memberships, the optional feature &#8216;Privileged Access Management&#8217; must be activated, as mentioned above. For this, the Forest Functional Level has to be at least 2016.<\/p>\n<p>The feature can be activated using the following command:<\/p>\n<p><i data-redactor-tag=\"i\">Enable-ADOptionalFeature &#8216;Privileged Access Management Feature&#8217;-Scope ForestorconfigurationSet -Target corp.customer.de<\/i><\/p>\n<\/div>\n[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1230&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_column_text]Subsequently, we can add a user to a group for a limited time:<\/p>\n<p><i data-redactor-tag=\"i\">Add-ADGroupMember -Identity &#8216;Domain Admins&#8217; -Members &#8216;Rene&#8217; -MemberTimeToLive (New-TimeSpan -Days 5)<\/i>[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1231&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_column_text]In order to display the TTL of group memberships, the following command can be used:\u00a0<i data-redactor-tag=\"i\">Get-ADGroup &#8216;Domain Admins&#8217; -Property member -ShowMemberTimeToLive<\/i>[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1232&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_column_text]<b data-redactor-tag=\"b\"><u data-redactor-tag=\"u\">Shadow principals<\/u><\/b><\/p>\n<p>Here, too, the optional feature &#8216;Privileged Access Management&#8217; has to be activated.<\/p>\n<p><i data-redactor-tag=\"i\">Enable-ADOptionalFeature &#8216;Privileged Access Management Feature&#8217;-Scope ForestorconfigurationSet -Target red.customer.local<\/i>[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1233&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_column_text]The trusting production forest must also have Forest Functional Level 2016 or Windows Server 2012R2 with the patch KB3156418 (<a href=\"https:\/\/support.microsoft.com\/en-us\/help\/3156418\/may-2016-update-rollup-for-windows-rt-8-1-windows-8-1-and-windows-serv\" target=\"_blank\" rel=\"noopener noreferrer\"><strong data-redactor-tag=\"strong\" data-verified=\"redactor\">https:\/\/support.microsoft.com\/en-us\/help\/3156418\/may-2016-update-rollup-for-windows-rt-8-1-windows-8-1-and-windows-serv<\/strong><\/a>\u00a0).<\/p>\n<p>After activating the feature, there are some relevant objects and classes:<\/p>\n<h3>msDS-ShadowPrincipalContainer:<\/h3>\n<p>In this container, all shadow principals are stored. The default container is created here:<\/p>\n<p>CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=customer,DC=de<\/p>\n<p>In principle, further containers can be created, but these then do not function with Kerberos.<\/p>\n<h3>msDS-ShadowPrincipal:<\/h3>\n<p>This class represents an object from an external forest. Objects of this class can only be created in a shadow principal container and the attribute msDS-ShadowPrincipalSid must have a value.<\/p>\n<p>A shadow principal can represent any user, security group, or computer. As with temporary groups, you can set a time to live for the member attribute.<\/p>\n<p>When the shadow principal is created in the default container CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=customer,DC=de, the membership of a user in this shadow principal will be inserted into the Kerberos ticket, just like with any other group membership. However, the restriction applies that only users of the same forest can be members of a shadow principal.<\/p>\n<h3>msDS-ShadowPrincipalSid:<\/h3>\n<p>This attribute contains the SID of the object from the external forest. You cannot add a SID from the same domain or the same forest. Naturally, the respective trust has to exist in order to add the SID.<\/p>\n<h3>Usage of the shadow principals<\/h3>\n<p>Before the shadow principals can be used appropriately, a respective trust has to be created first (prerequisite: name resolution between the forests has to work). The trust attributes &#8216;SIDHistory&#8217; has to be configured to &#8216;Yes&#8217; and &#8216;Quarantine&#8217; to &#8216;No&#8217;:<\/p>\n<p>The following commands must be executed in the productive domain:<\/p>\n<p>netdom trust corp.customer.de \/Domain:red.customer.local \/Add \/UserD:<span id=\"cloakd894d379b078818776a606a363c41a3d\"><a href=\"mailto:administrator@red.customer.local\">administrator@red.customer.local<\/a><\/span>\u00a0\/PasswordD:* \/UserO:<span id=\"cloake46d21793c26422b3058a9062f1e3032\"><a href=\"mailto:administrator@corp.customer.de\">administrator@corp.customer.de<\/a><\/span>\u00a0\/PasswordO:*<\/p>\n<p>netdom trust corp.customer.de \/domain:red.customer.local \/ForestTRANsitive:Yes<\/p>\n<p>netdom trust corp.customer.de \/domain:red.customer.local \/EnableSIDHistory:Yes<\/p>\n<p>netdom trust corp.customer.de \/domain: red.customer.local \/EnablePIMTrust:Yes<\/p>\n<p>netdom trust corp.customer.de \/domain: red.customer.local \/Quarantine:No[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1234&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1235&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_column_text]In the red forest, the following command is to be executed:<\/p>\n<p>netdom trust red.customer.local \/domain:corp.customer.de \/ForestTRANsitive:Yes<\/p>\n<p>Subsequently, the shadow principals can be used via PowerShell, as seen in the following example.<\/p>\n<p>Using the following commands, a shadow principal for the domain admin group from the production forest is created:<\/p>\n<p>$CORPPrincipal = &#8220;Domain Admins&#8221;<\/p>\n<p>$CorpDC = &#8220;corpdc02.corp.customer.de&#8221;<\/p>\n<p>$ShadowSuffix = &#8220;CORP-&#8221;<\/p>\n<p>$CorpShadowPrincipal = Get-ADGroup -Identity $CORPPrincipal -Properties ObjectSID, SamAccountName -Server $CorpDC<\/p>\n<p>$ShadowPrincipalContainer = &#8220;CN=Shadow Principal Configuration,CN=Services,&#8221;+(Get-ADRootDSE).configurationNamingContext<\/p>\n<p>New-ADObject -Type &#8220;msDS-ShadowPrincipal&#8221; -Name &#8220;$ShadowSuffix$($CorpShadowPrincipal.SamAccountName)&#8221; -Path $ShadowPrincipalContainer -OtherAttributes @{&#8216;msDS-ShadowPrincipalSid&#8217;= $CorpShadowPrincipal.ObjectSID}[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1236&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1237&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_column_text]We can now add a user from the admin forest to the member attribute and give them temporary rights in the production forest, if desired:<\/p>\n<p>Set-ADObject -Identity &#8220;CN=CORP-Domain Admins, CN=Shadow Principal Configuration,CN=Services,CN=Configuration,DC=red,DC=customer,DC=local&#8221; -Add @{&#8216;member&#8217;=&#8221;&lt;TTL=3600, CN=Manuel,CN=Users,DC=red,DC=customer,DC=local&gt;&#8221;}[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1238&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1239&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_column_text]\n<h3>MIM-PAM<\/h3>\n<p>The depiction of the installation of MIM-PAM would go beyond the scope of the article which is why we only refer to the documentation by Microsoft at this point (<a href=\"https:\/\/docs.microsoft.com\/de-de\/microsoft-identity-manager\/pam\/configuring-mim-environment-for-pam\" target=\"_blank\" rel=\"noopener noreferrer\"><strong data-redactor-tag=\"strong\" data-verified=\"redactor\">https:\/\/docs.microsoft.com\/de-de\/microsoft-identity-manager\/pam\/configuring-mim-environment-for-pam<\/strong><\/a>).<\/p>\n<p>However, we would like to show you how to create and request roles, as well as demonstrate the log entries mentioned above.<\/p>\n<p>Firstly, add the user to PAM:<\/p>\n<p>$user = New-PAMUser -PrivOnly -SourceDomain red.customer.local -SourceAccountName &#8220;Manuel&#8221;<\/p>\n<p>$user[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1240&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_column_text]Then, add the group to PAM:<\/p>\n<p>$cred = Get-Credential<\/p>\n<p>$group = New-PAMGroup -SourceGroupName &#8220;Server Admins&#8221; -SourceDomain corp.customer.de -SourceDC corpdc02.corp.customer.de -Credentials $cred[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1241&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_column_text]Finally, define the new role:<\/p>\n<p>$role = New-PAMRole -DisplayName &#8220;CorpAdmins&#8221; -TTL 00:03:00 $group -Candidates $user[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1242&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_column_text]Now, the user can request the role as follows:<\/p>\n<p>New-PAMRequest -RoleDisplayName &#8220;CorpAdmins&#8221;[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1243&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1244&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1245&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1246&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1247&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1248&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1249&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1250&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1251&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1252&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_column_text]However, the rights can also be restored prematurely as follows:<\/p>\n<p>Close-PAMRequest -RoleDisplayName &#8220;CorpAdmins&#8221;[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1253&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_column_text]If a user requests the role, but isn&#8217;t authorised to, the following, somewhat misleading, error message is received:[\/vc_column_text][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1254&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_column_text]In conclusion, you could say that with shadow principals, Microsoft has given us a powerful tool to make credential theft attacks more difficult, but that the red forest needs special protection for misuse to be prevented. In the next article, we would like to describe what we have done to achieve this in a specific customer scenario.<\/p>\n<p>Special thanks goes to Holger for the MIM-PAM screenshots :-).<\/p>\n<p>Below are some sources and follow-up links:<\/p>\n<p><a href=\"https:\/\/secureidentity.se\/msds-shadowprincipal\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong data-redactor-tag=\"strong\" data-verified=\"redactor\">https:\/\/secureidentity.se\/msds-shadowprincipal\/<\/strong><\/a><\/p>\n<p><a href=\"https:\/\/blogs.technet.microsoft.com\/fieldcoding\/2017\/05\/09\/privileged-access-management-demystified\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong data-redactor-tag=\"strong\" data-verified=\"redactor\">https:\/\/blogs.technet.microsoft.com\/fieldcoding\/2017\/05\/09\/privileged-access-management-demystified\/<\/strong><\/a><\/p>\n<p><u data-redactor-tag=\"u\" data-verified=\"redactor\"><\/u><a class=\"\" title=\"\" href=\"https:\/\/blogs.technet.microsoft.com\/askds\/2016\/03\/09\/previewing-server-2016-tp4-temporary-group-memberships\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong data-redactor-tag=\"strong\" data-verified=\"redactor\">https:\/\/blogs.technet.microsoft.com\/askds\/2016\/03\/09\/previewing-server-2016-tp4-temporary-group-memberships\/<\/strong><\/a><u data-redactor-tag=\"u\" data-verified=\"redactor\"><\/u><\/p>\n<p><a href=\"https:\/\/docs.microsoft.com\/de-de\/microsoft-identity-manager\/pam\/privileged-identity-management-for-active-directory-domain-services\" target=\"_blank\" rel=\"noopener noreferrer\"><strong data-redactor-tag=\"strong\" data-verified=\"redactor\">https:\/\/docs.microsoft.com\/de-de\/microsoft-identity-manager\/pam\/privileged-identity-management-for-active-directory-domain-services<\/strong><\/a><\/p>\n<p><u data-redactor-tag=\"u\" data-verified=\"redactor\"><\/u><a href=\"https:\/\/docs.microsoft.com\/en-us\/powershell\/module\/mimpam\/?view=idm-ps-2016sp1\" target=\"_blank\" rel=\"noopener noreferrer\"><strong data-redactor-tag=\"strong\" data-verified=\"redactor\">https:\/\/docs.microsoft.com\/en-us\/powershell\/module\/mimpam\/?view=idm-ps-2016sp1<\/strong><\/a>[\/vc_column_text][vc_empty_space height=&#8221;40&#8243;][vc_column_text]Source: <a href=\"https:\/\/de.freepik.com\/fotos-vektoren-kostenlos\/hintergrund\" target=\"_blank\" rel=\"noopener\">freepik.com<\/a>[\/vc_column_text][vc_empty_space height=&#8221;50&#8243;][vc_raw_html]JTNDYSUyMGhyZWYlM0QlMjJqYXZhc2NyaXB0JTNBaGlzdG9yeS5iYWNrJTI4JTI5JTIyJTNFJTNDc3BhbiUyMHN0eWxlJTNEJTIyY29sb3IlM0ElMjAlMjNmZjIwNzAlM0IlMjIlM0UlM0MlM0MlMjBCYWNrJTNDJTJGc3BhbiUzRSUzQyUyRmElM0U=[\/vc_raw_html][vc_empty_space height=&#8221;50&#8243;][vc_separator type=&#8221;small&#8221; position=&#8221;center&#8221; color=&#8221;#eeeeee&#8221; thickness=&#8221;2&#8243; width=&#8221;1100&#8243;][vc_empty_space height=&#8221;100&#8243;][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_column_text]\n<h2>LATEST POSTS<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;]\n<div class='latest_post_holder boxes three_columns one_row' >\n    <ul>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/01\/logging-in-instead-of-breaking-in\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h3 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/01\/logging-in-instead-of-breaking-in\/\">\u201cLogging In instead of Breaking In\u201d: Why your identities are the biggest security risk<\/a><\/h3>\n                            <p class=\"excerpt\">Attackers no longer \u201csimply\u201d break in, they LOG in. If you\u2019re still relying on traditional defenses in 2026, we believe you\u2019ve probably already lost the battle for your data....<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">01 April, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/29\/bsi-update-grundschutz\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h3 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/29\/bsi-update-grundschutz\/\">BSI Update: Grundschutz++ Will become mandatory in 2028 &#8211; why you should take action now<\/a><\/h3>\n                            <p class=\"excerpt\">The wait is over: The BSI has published the first guidelines for Grundschutz++. What at first glance looks like additional bureaucratic red tape is, in fact, the new \u201cstate of the art\u201d for NIS2. ...<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">29 April, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/01\/29\/bye-bye-rc4\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-539x303.png\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-539x303.png 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-300x169.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-1024x575.png 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-768x432.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-1536x863.png 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-700x393.png 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4.png 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h3 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/01\/29\/bye-bye-rc4\/\">Bye-bye RC4: Your guide to the Kerberos transition in April 2026<\/a><\/h3>\n                            <p class=\"excerpt\">The clock is ticking for one of the longest-lasting (and most insecure) ciphers in our networks. Microsoft is getting serious and pushing for the shutdown of RC4 encryption in the Kerberos protocol....<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">29 January, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n        <\/ul>\n<\/div>[\/vc_column][\/vc_row]\n<\/div>","protected":false},"excerpt":{"rendered":"<p>As already announced in the last article (LINK) of the ESAE series, in this article we would like to give you a more in-depth description of the technical core <\/p>\n","protected":false},"author":5,"featured_media":1229,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[10],"tags":[],"class_list":["post-1824","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1824","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/comments?post=1824"}],"version-history":[{"count":6,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1824\/revisions"}],"predecessor-version":[{"id":1970,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1824\/revisions\/1970"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media\/1229"}],"wp:attachment":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media?parent=1824"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/categories?post=1824"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/tags?post=1824"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}