{"id":1840,"date":"2018-05-02T08:16:11","date_gmt":"2018-05-02T08:16:11","guid":{"rendered":"https:\/\/www.teal-consulting.de\/2018\/05\/02\/esae-serie-teil-1-einleitung\/"},"modified":"2021-04-29T13:06:38","modified_gmt":"2021-04-29T11:06:38","slug":"esae-series-part-1-introduction","status":"publish","type":"post","link":"https:\/\/www.teal-consulting.de\/en\/2018\/05\/02\/esae-series-part-1-introduction\/","title":{"rendered":"ESAE series part 1- Introduction"},"content":{"rendered":"<div class=\"wpb-content-wrapper\" id=\"wpb-content-root\">[vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_empty_space height=&#8221;50&#8243;][vc_row_inner row_type=&#8221;row&#8221; type=&#8221;full_width&#8221; text_align=&#8221;left&#8221; css_animation=&#8221;&#8221;][vc_column_inner][vc_column_text]\n<div class=\"ebd-block \" data-type=\"text\">\n<div class=\"ebd-block \" data-type=\"text\">\n<p>In the blog category &#8220;Secure Administration Environment&#8221; we want to share our experiences from customer projects around Microsoft&#8217;s Enhanced Security Administration Environment (ESAE), so that others can learn from our experiences and not stumble across the same problems as we did.<\/p>\n<p>We will start with a series on a very exciting topic that we have been able to work on for a globally active insurer in recent months: The complete implementation of an environment inspired by ESAE.<\/p>\n<p>In this first article of the series, we want to explain what it deals with, why it is necessary and what components the environment is made up of. In further articles, we will examine individual components in more detail and finally to summarize our practical experiences and our handling of the stumbling blocks in the last article.<\/p>\n<p>ESAE is a design approach by Microsoft (<a href=\"https:\/\/docs.microsoft.com\/en-us\/windows-server\/identity\/securing-privileged-access\/securing-privileged-access-reference-material\" target=\"_blank\" rel=\"noopener noreferrer\"><b data-redactor-tag=\"b\">ESAE documentation by Microsoft<\/b><\/a>) to make credential theft and pass the hash\/pass the ticket attacks more difficult or to at least to reduce their impact. There are entire blog series and white papers (<a href=\"http:\/\/adsecurity.org\/\" target=\"_blank\" rel=\"noopener noreferrer\"><b data-redactor-tag=\"b\">http:\/\/adsecurity.org\/<\/b><\/a>\u00a0and\u00a0<b data-redactor-tag=\"b\">Microsoft white paper<\/b>) on credential theft, pass the hash\/pass the ticket, so we&#8217;ll only cover a short summary and provide links to more in-depth topics.<\/p>\n<\/div>\n<div class=\"ebd-block \" data-type=\"text\">\n<p><b data-redactor-tag=\"b\">The problem:<\/b><\/p>\n<p>Because of the way Windows and Active Directory work, there are a number of ways for attackers to read and use passwords or their hashes. All that&#8217;s needed are admin rights on a workstation and freely accessible tools like Mimikatz (<b data-redactor-tag=\"b\"><a href=\"https:\/\/github.com\/gentilkiwi\/mimikatz\" target=\"_blank\" rel=\"noopener noreferrer\"><strong data-redactor-tag=\"strong\" data-verified=\"redactor\">Github<\/strong><\/a><\/b>\u00a0and\u00a0<b data-redactor-tag=\"b\"><a href=\"https:\/\/www.youtube.com\/watch?v=7mLifQiKdfk\" target=\"_blank\" rel=\"noopener noreferrer\"><strong data-redactor-tag=\"strong\" data-verified=\"redactor\">BlueHat talk<\/strong><\/a><\/b>).<\/p>\n<p>Admin rights can be acquired through a phishing attack or a social engineering attack, for example. According to the study &#8216;Wombat Security State of the Phish 2017&#8217;, 76% of all organisations were the victims of phishing attacks in 2016 alone. Particularly with larger organisations, chances are that sooner or later, an attacker will succeed.<\/p>\n<p>In the next step, the attacker will try to spread themselves in the network. In the past, attackers had to spend a lot on moving around the network via trial and error methods in order to eventually acquire privileged accounts. Today, there are tools like Bloodhound (<b data-redactor-tag=\"b\"><a href=\"https:\/\/github.com\/BloodHoundAD\/BloodHound\" target=\"_blank\" rel=\"noopener noreferrer\"><strong data-redactor-tag=\"strong\" data-verified=\"redactor\">Github<\/strong><\/a><\/b>\u00a0and \u2013\u00a0<a href=\"https:\/\/www.youtube.com\/watch?v=wP8ZCczC1OU\" target=\"_blank\" rel=\"noopener\"><b data-redactor-tag=\"b\">DEF CON 24 talk<\/b><\/a>) which display the path from the captured computer to the domain admin account (or any other) within a few minutes.<\/p>\n<p>I advise everyone to look at the linked talks. It&#8217;ll open your eyes!<\/p>\n<\/div>\n<div class=\"ebd-block \" data-type=\"text\">\n<p><b data-redactor-tag=\"b\">The (ESAE) solution:<\/b><\/p>\n<p>As already stated above, ESAE is not a single technique, no tool or service that solves all these problems, but a set of techniques, tools, and work methods that make it difficult for an attacker to acquire highly privileged accounts and cause damage with them.<\/p>\n<p>The core of the solution is to subdivide the IT services and systems into different tiers on the basis of the protection needs and to outsource the admin accounts for the tiers with high protection needs to a separate administration forest.<\/p>\n<\/div>\n<\/div>\n[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][vc_empty_space height=&#8221;20&#8243;][vc_single_image image=&#8221;1221&#8243; img_size=&#8221;full&#8221; alignment=&#8221;center&#8221; qode_css_animation=&#8221;&#8221;][vc_empty_space height=&#8221;20&#8243;][vc_column_text]If you check out the Microsoft documentation, the systems are devided into the tiers as follows:<\/p>\n<p>Tier 0: Entreprise identity systems such as Active Directory, PAM systems, ADFS.<\/p>\n<p>Tier 1: Entreprise applications such as email, collaboration and other line of business applications.<\/p>\n<p>Tier 2: Workstations.<\/p>\n<p>This classification has to be enjoyed with a pinch of salt, of course. Every company has one or another highly protective system which doesn&#8217;t fall into the above definition for tier 0. These systems can and should be protected as well just the same, of course.<\/p>\n<p>The admin accounts don&#8217;t have constant standing administration rights per se, though. These need to be requested via a just-in-time Privilege Access Management (PAM) solution for a defined period of time. Furthermore, the environment can only be administered with hardened Privilege Access Workstations (PAWs).<\/p>\n<p>Since the introduction has become a little bit longer than expected, we&#8217;ll do a cut here and present the specific customer scenario and the selected architecture in the next blog article.[\/vc_column_text][vc_empty_space height=&#8221;40&#8243;][vc_column_text]Source: <a href=\"https:\/\/de.freepik.com\/fotos-vektoren-kostenlos\/hintergrund\" target=\"_blank\" rel=\"noopener\">freepik.com<\/a>[\/vc_column_text][vc_empty_space height=&#8221;50&#8243;][vc_raw_html]JTNDYSUyMGhyZWYlM0QlMjJqYXZhc2NyaXB0JTNBaGlzdG9yeS5iYWNrJTI4JTI5JTIyJTNFJTNDc3BhbiUyMHN0eWxlJTNEJTIyY29sb3IlM0ElMjAlMjNmZjIwNzAlM0IlMjIlM0UlM0MlM0MlMjBCYWNrJTNDJTJGc3BhbiUzRSUzQyUyRmElM0U=[\/vc_raw_html][vc_empty_space height=&#8221;50&#8243;][vc_separator type=&#8221;small&#8221; position=&#8221;center&#8221; color=&#8221;#eeeeee&#8221; thickness=&#8221;2&#8243; width=&#8221;1100&#8243;][vc_empty_space height=&#8221;100&#8243;][\/vc_column][\/vc_row][vc_row css_animation=&#8221;&#8221; row_type=&#8221;row&#8221; use_row_as_full_screen_section=&#8221;no&#8221; type=&#8221;full_width&#8221; angled_section=&#8221;no&#8221; text_align=&#8221;left&#8221; background_image_as_pattern=&#8221;without_pattern&#8221;][vc_column][vc_column_text]\n<h2>LATEST POSTS<\/h2>\n[\/vc_column_text][vc_empty_space height=&#8221;30&#8243;]\n<div class='latest_post_holder boxes three_columns one_row' >\n    <ul>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/01\/logging-in-instead-of-breaking-in\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2023\/03\/blog_headerbild_teal_krux-mit-der-KI_AI.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h3 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/01\/logging-in-instead-of-breaking-in\/\">\u201cLogging In instead of Breaking In\u201d: Why your identities are the biggest security risk<\/a><\/h3>\n                            <p class=\"excerpt\">Attackers no longer \u201csimply\u201d break in, they LOG in. If you\u2019re still relying on traditional defenses in 2026, we believe you\u2019ve probably already lost the battle for your data....<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">01 April, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/29\/bsi-update-grundschutz\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-539x303.jpg\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-539x303.jpg 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-300x169.jpg 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-1024x575.jpg 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-768x432.jpg 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-1536x863.jpg 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header-700x393.jpg 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2022\/09\/teal_blog_on-prem-safe_header.jpg 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h3 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/04\/29\/bsi-update-grundschutz\/\">BSI Update: Grundschutz++ Will become mandatory in 2028 &#8211; why you should take action now<\/a><\/h3>\n                            <p class=\"excerpt\">The wait is over: The BSI has published the first guidelines for Grundschutz++. What at first glance looks like additional bureaucratic red tape is, in fact, the new \u201cstate of the art\u201d for NIS2. ...<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">29 April, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n    \n        <li class=\"clearfix\">\n            <div class=\"boxes_image\">\n                                <a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/01\/29\/bye-bye-rc4\/\"><img decoding=\"async\" width=\"539\" height=\"303\" data-src=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-539x303.png\" class=\"attachment-latest_post_boxes size-latest_post_boxes wp-post-image lazyload\" alt=\"\" data-srcset=\"https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-539x303.png 539w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-300x169.png 300w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-1024x575.png 1024w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-768x432.png 768w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-1536x863.png 1536w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4-700x393.png 700w, https:\/\/www.teal-consulting.de\/wp-content\/uploads\/2026\/01\/Blog-Headerbild_RC4.png 1920w\" data-sizes=\"(max-width: 539px) 100vw, 539px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 539px; --smush-placeholder-aspect-ratio: 539\/303;\"><\/a>\n            <\/div>\n            <div class=\"latest_post\"  >\n                <div class=\"latest_post_text\">\n                    <div class=\"latest_post_inner\">\n                        <div class=\"latest_post_text_inner\">\n                            <h3 itemprop=\"name\" class=\"latest_post_title entry_title\"><a itemprop=\"url\" href=\"https:\/\/www.teal-consulting.de\/en\/2026\/01\/29\/bye-bye-rc4\/\">Bye-bye RC4: Your guide to the Kerberos transition in April 2026<\/a><\/h3>\n                            <p class=\"excerpt\">The clock is ticking for one of the longest-lasting (and most insecure) ciphers in our networks. Microsoft is getting serious and pushing for the shutdown of RC4 encryption in the Kerberos protocol....<\/p>\n                            <span class=\"post_infos\">\n                                                                    <span class=\"date_hour_holder\">\n                                        <span itemprop=\"dateCreated\" class=\"date entry_date updated\">29 January, 2026 <meta itemprop=\"interactionCount\" content=\"UserComments: 0\"\/><\/span>\n                                    <\/span>\n                                                                                                \n                                \n                                                            <\/span>\n                        <\/div>\n                    <\/div>\n                <\/div>\n            <\/div>\n        <\/li>\n        <\/ul>\n<\/div>[\/vc_column][\/vc_row]\n<\/div>","protected":false},"excerpt":{"rendered":"<p>In the blog category &#8220;Secure Administration Environment&#8221; we want to share our experiences from customer projects around Microsoft&#8217;s Enhanced Security Administration Environment <\/p>\n","protected":false},"author":5,"featured_media":1222,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[10],"tags":[],"class_list":["post-1840","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1840","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/comments?post=1840"}],"version-history":[{"count":5,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1840\/revisions"}],"predecessor-version":[{"id":3615,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/posts\/1840\/revisions\/3615"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media\/1222"}],"wp:attachment":[{"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/media?parent=1840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/categories?post=1840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.teal-consulting.de\/en\/wp-json\/wp\/v2\/tags?post=1840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}