Season 1, Episode 8

Inside Active Directory’s Origin Story: Aaron Turner on Microsoft’s “Kill Novell” Mission

When the mission statement is to kill your competitor, building your product with a security-first mindset is hardly your first priority.  

That’s what Aaron Turner, IANS Faculty & former Microsoft Senior Security Strategist, explained to our co-hosts when he unpacked the origin of Active Directory.  

In part one of this two-part series, Aaron takes us back to the 1990s to talk about Active Directory’s original purpose—and how that’s left us with a massive security debt situation almost 30 years later. 

He shares real-world examples he dealt with during his time at Microsoft that help us understand why AD was never designed as a security solution, but purely as a Windows deployment mechanism: “We saw it where an entire domain were domain admins because it was just easier. And if you look at most of the headwinds we saw in those early days when we were trying to do things like least privilege, applications wouldn’t run unless you were an elaborate admin.” 

With so many global organizations still using on-prem AD today, this episode is a must-watch to learn why AD Security remains a top concern to build strong defenses. 

Key takeaways include: 

  • Why Active Directory shaped how we think about identity today, and its impact on cybersecurity 
  • The reasons why certain areas of cybersecurity, like firewalls, have earned hundreds of billions in investment while identity is just starting to join the security conversation
  • What the NSA Treasury hack teaches us about sound Identity Security practices, and what Aaron recommends you do to help you get there 

Aaron Turner:[00:00:00]
First you have to get inside the mindset of Bill Gates in the mid-’90s. He set the goal of Novell is making a lot of money on Enterprise Directory. And so Microsoft said, “We gotta go steal Novell’s lunch money.” The first version of the active directory feature spec was kill Novell. That was the mission statement.

Active directory was viewed first as how do we sell more Windows? How do we sell more Office? It was a deployment mechanism. It wasn’t necessarily a security boundary. Let’s just say $250 billion has been spent on firewalls. How much has been spent on identity? Maybe 2% of that. As the result of that lack of investment, we’re in this massive identity debt situation.

So they’re going to have to invest in some legacy-focused stuff to say, “Okay, what am I gonna do to fix 25 years of messed up group policy objects?” That’s the decision that has to be made.

Roy Akerman:
Identity isn’t just an operational problem, it’s a security one, and most teams are figuring out in real time.

Rob Ainscough:
This is the podcast where we reverse engineer the meaning of identity security, sharing candid conversations about the people building, fixing, and rethinking identity security from the inside.

Roy Akerman:
I’m Roy Akerman.

Rob Ainscough:
And I’m Rob Ainscough.

Roy Akerman:
Let’s dive in.

Rob Ainscough:
Let’s do it.

Welcome back. Hi, Roy. How are you?

Roy Akerman:
I’m all good. Good to see you, Rob.

Rob Ainscough:
Very good to see you, too. Uh, very excited ’cause, uh, for this episode, uh, we’ve got Aaron Turner with us, right? So Aaron, 30 years in industry, founded his own company, but most importantly for us, worked for Microsoft when Active Directory was becoming a thing, right, that seminal time.

He was there at base camp. Super exciting for us to talk to him.

Roy Akerman:
Like, the designer, the architect.

Rob Ainscough:
The one to blame. Uh, but

Aaron Turner:
let’s- Let’s be very careful here. I was the lowest of the low on the totem pole.

Roy Akerman:
So he said

Rob Ainscough:
that- But you were there … you had first impact. You were there.

Roy Akerman:
Yeah.

Aaron Turner:
Oh,

Rob Ainscough:
I was there. You were there.

Aaron Turner:
I was there, but I was, uh, I was technically a support engineer, which meant I had to deal with all the bugs and all the crap, right? So I, I saw the worst of the worst.

Rob Ainscough:
Wow. Yeah. Still, privileged position to be in, so we’re gonna talk a bit about that. We’re gonna talk about how identity changed over the years, Active Directory’s role, what it means for attackers today, and defenders, right?

So I think we’re gonna have a really interesting session. Um, so to start us off, Aaron, can you give us a bit of your version of your career history and bio for, to start us off?

Aaron Turner:
I started on this journey because I saw the movie WarGames. Like, the, the, in 1984, the movie WarGames released, and I was like, “That seems incredible.

I wonder if I can do that.” Um, and that sent me on a journey of sometimes getting in trouble with computers, right? And then eventually figured out how to make money doing bad things with computers. I, I was a very early penetration tester in the, uh, early to mid-’90s, and, uh, eventually figured out, okay, maybe I can get a job that pays something better than what I was getting just doing odds and ends, uh, of security testing work.

And Microsoft posted a job where they wanted a bilingual, internet-knowledgeable, Novell-experienced individual to join this team. And I- they wanted it to focus on some Latin American opportunities, and so I, I speak Spanish. I lived in Mexico for a little while. Um, knew a little bit about the internet because of the crazy stuff I’d been doing since WarGames, and, uh, and got this amazing opportunity at Microsoft and went on a journey with them where, you know, basically we had to found some of the very foundations of, of what became the internet and enterprise computing.

And spent eight years there. Amazing time to, to learn a ton.

Roy Akerman:
Our, our intelligence officers told us, like, two things that I, I must to, to, to validate with you. The first one is that, uh, like, upon a year of tenure, Bill Gates himself, uh, gave you a carte blanche to actually, uh, do whatever project you want there, of course, with, with a major value.

And the second o- second one is about a gold star, so if you could just, like, start with this, and then, I mean, moving on to our identity talks, that would be great. Can you, can you tell us a little bit about those?

Aaron Turner:
So, uh, in the 1998, ’99 timeframe, the governor of, uh, of Venezuela came to Microsoft and said, “We want to build a countrywide identity platform for every citizen of Venezuela.”

Roy Akerman:
Wow.

Aaron Turner:
And they went down and they used NT4 to try to build this enterprise identity platform, and the move wasn’t up to the task. Sounds promising. And it kept breaking. Kept breaking over and over again. And no one on our team was brave enough to go down to Venezuela, ’cause Venezuela, I mean, it has an even worse rep now, but even back then it was an uncertain place.

And so, because I was familiar with Latin America, I was like, “Okay, I’ll go.” And so I raised my hand and, and went down. And because I helped fix that problem, I figured out how to make some changes to the NT code and that later became the Windows 2000 code. Because I made that change and then was brave enough to go to Venezuela, I was recognized in 1999 with a gold star, which at the time, very limited awards that Bill Gates would give out.

But as a recipient of that, you sort of got the ability to experiment, right? You got some freedom to go, “Hey, you know, you did this great thing. Let’s see what you can do to, to, you know, further Microsoft.” And so my Spanish knowledge, my, uh, bravery in going to Venezuela basically set me up to do amazing things and to work on Active Directory, SQL Server, Windows Mobile, Xbox Live.

Like, I, I got to go and work on all sorts of really cool things in my time there.

Roy Akerman:
All from identity perspective

Aaron Turner:
Sometimes identity, sometimes breaking stuff.

Roy Akerman:
Yeah.

Aaron Turner:
Mm-hmm. Right? Sometimes helping people think about threat models. You know, we didn’t, we didn’t really have a full-blown cybersecurity team until, like, 2002, 2003.

Um, you know, and so, you know, I was there in the early days when we had to… Like, no one had ever built, uh, an enterprise-grade update system like what Windows update was, right? No one had ever thought about how do you update two billion computers at the time. Mm. Um, no one had thought about encrypting hard drives if you lost a laptop.

No one had thought about, you know, these things. And so we had to, we had to think about things that no one had thought about before.

Rob Ainscough:
So today we’re gonna, we’re gonna focus on that Active Directory story, right? So it’s still for, for most companies, you know, we talk about the cloud and all of, you know, the transition that’s happened over the last 10, 15 years.

But the reality is it’s still, you know, the nerve center of enterprise identity for many companies, right? It’s absolutely critical. And, um, as we said, you’ve, you- a really interesting position having been there as that was, you know, being born and, and growing and, and becoming what it is today. I’m just really interested in, you know, where did Active Directory come from?

What was it designed to do? What were you trying to achieve with Active Directory at that time?

Aaron Turner:
So first you have to get inside the mindset of Bill Gates in the mid-’90s. Bill Gates was on a mission to basically build a successful company because he was always paranoid that, that what happened to Wang, what happened to Digital, like, you look at the bodies on the side of the road in computing from the ’80s and the ’90s, and there were a lot of bodies.

Roy Akerman:
Mm.

Aaron Turner:
And so he was paranoid about, you know, we’ve got to go out and conquer. And, and so- He, he set the goal of Novell is making a lot of money on enterprise directory, and Novell was a very strong company, uh, that had basically led in building an enterprise directory. How do you get people to have a good computer experience?

How do you have a username and password? How do you have a good file structure? And so Microsoft said, “We’ve got, we’ve gotta go steal that money. We gotta go steal Novell’s lunch money.” And so the first version of the Active Directory feature spec was kill Novell. Like, that was the, that was the mission statement.

Um, we didn’t have a bunch else, and so the rest of it was interesting, right? For example, I was a huge fan of Kerberos. Like, Kerberos was fairly new at the time. MIT had just released the Kerberos standard. I’m like, “Hey, I think Kerberos is the bomb. I think that’s really gonna be much better.” Because we’re still dealing with NTLM, right?

NTLM, the, the highly susceptible, highly vulnerable protocol that’s easily reversed, and the hashes are broken and that sort of thing. We’re still dealing with NT LAN Manager, right, which was a Windows, uh, NT4 protocol. And so how do you… The, the, the problem that we had was if all we’re there for is to kill Novell, how do you make it a security system?

And that was the tension that existed. Mm. You know, those of us who are security passionate, Active Directory was viewed first as how do we sell more Windows, how do we sell more Office. Like, it was- Mm … a deployment mechanism. It wasn’t necessarily a security boundary.

Roy Akerman:
Really interesting. And, like, yeah, it- it’s interesting, A, like being there and actually, like, s- like rebuilding something else maybe better that will be a displacement for something that, you know, started to grow.

And, you know, I bet that there were, like, multiple trade-offs that you needed to take, right? Because there was, like, time to market and, like, a lot of other things and, like, a shift in the, uh, in the computers, like, world. Like, can you take us back, then, I don’t know, like ’98, maybe a little bit later, and, like, tell us what were the initial trade-offs that, that, you know, like, the builders and the designers, like, uh, should have, you know, decide on?

Aaron Turner:
Well, so the, uh, as I mentioned, the goal of Active Directory was to sell more Windows and sell more Office, right? Speed to deployment, right? How do you deploy a whole bunch of systems? Um, and so in that speed to market, it lost some things like multi-factor authentication, right? MFA wasn’t, like, a core design principle of Active Directory, right?

It was something that was like, “Oh, maybe some partners will figure that out.” And, and folks like RSA and Gemalto, right- Mm-hmm … did come forward to say, “Yeah, we’ll, we’ll do that MFA work,” right? But for example, one of the tasks that, that fell to me is I was responsible for doing the regression testing for all of the third-party MFA tokens.

And at, at that point in time, the only way you could get an MFA token to work is you had to replace the GINA. You had to build a GINA shim- Ooh, that’s deep … which is a kernel level, you know, this is kernel level operations on a Windows, uh, domain controller, sometimes on the endpoint. Let’s just say if I didn’t see 300 blue screens in a day, I wasn’t doing my job, right?

Because those GINAs were poorly written. We w- we at Microsoft provided poor guidance to do that, and so, so, but so when someone came to you and said, “Hey, let’s deploy MFA,” and they went and did a proof of concept and they got 10 blue screens and they were like, “No, I, I, that’s okay. I’m good without MFA, thanks.

I, I don’t want to use MFA.” Um, and so there’s an example of lack of focus from a security perspective because today we would pr- we would perceive MFA as core, like that, that, that is a core fundamental feature that needs to be… And so there’s an example. Yeah. Another example is, um, you know, we had these security boundaries which were forests, right?

You had forests and then domains, and you could build cross-forest trusts, and you could have- Mm-hmm … one-way trusts or bi-directional trusts and all this stuff. And, and then you had groups and nested groups, and then you had group policy objects and all this stuff, and all of this stuff was designed from a, a, a function out…

Like a, a deployment of Windows perspective, not from a security boundary perspective.

Rob Ainscough:
Yeah.

Aaron Turner:
So how do you force a cross-forest trust to have the right level of granularity? And oh, by the way, because the Microsoft licensing, when it, once it kicked in, most people were not motivated to have a domain account for domain admin and a domain account for your Exchange server i, in inbox.

You would commingle that, right? So now you’ve commingled your control plane, so the same account that you’re using to read your email is the same account you use for domain admin.

Roy Akerman:
Mm.

Aaron Turner:
Right? And so that’s not a good situation.

Roy Akerman:
Yeah. Mm. So- sounds like there was a lot of level of z- of abstraction when it comes to trust, like cross-domain, cross-forest.

Like how do we create trust when we create a single, like a s- like a, a different entity that we’ll need to validate and to authenticate when we can have that trust. I bet that there were a lot of discussions about that.

Aaron Turner:
Well, first off, while other folks had tried to do this before, so for example, um, AT&T with a lot of their Unix work, um, the government, you know, that sort of thing, people had tried to go on this path, but they’d never tried to do it at the low cost of ownership that Microsoft was trying to get it done, right?

Mm-hmm. So, so for example, it’s one thing to build a- an elaborate enterprise authentication system when you have PhDs working at Bell Labs, right? The AT&T people, they knew what they were doing. But when you take, uh, when you take a system administrator for your local hospital and make them a domain admin, like, the system administrator for a local hospital is not the same as a PhD working for Bell Labs.

Like, those are two different personalities. They’re two different personas. And so by introducing these very capable, um, systems, Windows Servers, Exchange Servers, SQL Servers, to these mid-to-low, you know, enterprise situations where maybe they don’t have good security architecture, they don’t have good security operation teams, like, they don’t have this capability, it really set up some really bad situations where like, “Well, why don’t we just make everyone domain admin?

It makes it easier. Everyone domain admin.”

Roy Akerman:
Yeah.

Aaron Turner:
And we saw that, where an entire domain were domain admins because it was just easier. It just, it made their jobs easier. They didn’t have to troubleshoot why this application wasn’t working or whatever. Mm-hmm. And, and if you look at most of the, the headwinds we saw in those early days when we were trying to do things like least privilege, like some of the early Adobe, um, applications wouldn’t run unless you were an elaborate admin, right?

Mm-hmm. Just, it just wouldn’t

Rob Ainscough:
run. It’s common, yeah.

Aaron Turner:
And so you ended up with these overprivileged situations. So, so oftentimes the, the vendor ecosystem was against you, right? So say I want to do least privilege. Oh, but I can’t because I need to use this app.

Rob Ainscough:
Mm-hmm.

Aaron Turner:
Oh, okay.

Roy Akerman:
Well, that’s something to take into account, where sometimes we, we blame the infrastructure builders or like, you know, the foundational things like Active Directory, that they needed to satisfy so many other areas of development, like other vendors.

And, and I think that again, like, the- these trade-offs are today’s, like, bread and butter for a lot of attackers, right? Mm-hmm. Like, we’re speaking about not only Active Directory as a tool, but as a set of concepts that actually established what we think about identity today. So I hope that it’s not too fast that I’m doing that, but like I’m, I’m curious.

So let’s fast-forward to nowadays for a second. Maybe we’ll go back again. Uh, but, but as you’re seeing identity has this kind of like a very hot topic today, right? Tons of capital poured in order to solve that problem. It evolves with AI and with NHI and with a lot of other buzzwords around, around the things.

Like, um, how do you see, uh, attackers, uh, like, defenders’ games around that? Like, what do you see that, like the core principles that are still, or not are still, that are being abused by attackers today, um, and you know, again, the games around that?

Aaron Turner:
So first let’s look at the economics of identity okay? So so let’s take the total amount spent on firewalls from 1999 till today.

So I, before this, as I was preparing for this, I went and did some rough research. Let’s just say $250 billion has been spent on firewalls for the last 25 years, okay? Um, how much has been spent on identity?

Rob Ainscough:
Yeah.

Aaron Turner:
Maybe 2% of that. Like, no- nowhere close, right? I mean, just a, a true fraction of that. And part of the reason why was because of the, of Microsoft’s strategy of bringing, uh, Active Directory to market.

Oh, buy a Windows server license, and oh, by the way, you get this identity thing for free, for free- Mm … included. Mm. And so as a result, a CIO, if they’re approached, say, “Well, what’s your identity strategy?” “Well, it’s Active Directory.” Well, Active Directory isn’t an identity strategy. Active Directory is maybe an authentication system.

It’s not an identity governance platform. Uh-huh. It’s not a privileges management platform. It’s not a federation platform, right?

Rob Ainscough:
Mm.

Aaron Turner:
So, so as the result of that lack of investment, we’re in this massive identity debt situation relative to firewalls, right? Mm. So where if firewalls have had a line item in the budget for 25 years, identity is just barely getting a line item on the budget now.

And so there’s the economics of identity that has put people behind the eight ball. So if we take that as the ground truth of the economics, we first have to say, “Well, what are we going to do to either disrupt our legacy identity to innovate ourselves out of this through digital transformation,” like I’m gonna get away from these legacy identity problems by moving to native cloud identities or something like that, or am I going to have to retrofit my legacy identity to basically shore it up, to make it so it’s something that’s sustainable?

Roy Akerman:
Mm.

Aaron Turner:
And so th- that’s the decision that has to be made, and unfortunately, most enterprises, they can’t disrupt themselves out of this, so they’re going to have to invest in some legacy-focused stuff to say, “Okay, what am I gonna do to fix 25 years of messed-up group policy objects and poor- Right … SCIM infrastructure and all the stuff that I’ve done?”

I got, uh, one of my favorite questions asked of, of a very experienced Active Directory domain administrator is, “How many times have you gone and looked at how many GPOs are still out there? Like, how many GPOs are in AD e- because you haven’t cleaned them up?”

Roy Akerman:
Mm.

Aaron Turner:
And for an organization that’s had AD for, uh, two decades, usually there are hundreds of GPOs that are unused-

Rob Ainscough:
Yeah

Aaron Turner:
just out there, and- Yeah … somebody deployed it. No one was ever responsible for cleaning that up, and it’s, it’s that

Rob Ainscough:
latent debt. And it’s really interesting ’cause I, I think to your point there, I see companies, as I talk to them now, kind of get stuck in the middle of the journey of shore it up versus modernize away, right?

Yeah. Neither of them are particularly quick or easy with some of the toolsets out there, and they kind of get stuck in the middle where they go, “Okay, well, maybe in five years’ time I’m gonna be cloud first and ephemeral and all these great things that I want to be that will make the world better.” But actually, what about the next five years when your critical systems are still running in Active Directory?

What are we doing there? Because you have to be intentional about that, right.

Roy Akerman:
So, so it’s a complexity that cr- like, uh, started to draw a debt- In the, an architectural debt that led to vulnerability.

Rob Ainscough:
Yep.

Roy Akerman:
And, and again, like all these neg- neglected, the GPOs and the if it ain’t broke, don’t fix it approaches and things like that brought us to an, into a stage that this is one of the most attackable surfaces as of our days.

Although we’re speaking about a technology that was designed in ’28, and, uh, sorry, in 1998, and still, like, had a lot of time in order to fix itself.

Aaron Turner:
So let’s take an example You know, if we, if you look at the kill chain of your average ransomware-as-a-service situation- Mm-hmm … okay, so ransomware-as-a-service is, if, if you’re not familiar with that, that is where, um, there’s a group of Russians, they have set up a ransomware-as-a-service platform and you as a franchisee can go buy their tooling from them, right?

So they- Yeah, RBAs … they, they essentially sell you, they sell you the, the, uh, info stealers, they sell you the, um, lateral movement tools. They s- it’s, it’s like a package, right? You get these tools. All of those tools depend upon an LSASS vulnerability. So if y- if you think about the, the stack that is Active Directory, because if they can get to LSASS on an unpatched Windows server, it doesn’t matter if it’s a domain controller.

Rob Ainscough:
Mm.

Aaron Turner:
Because LSASS, which was designed in 1998, is designed to cache all of the credentials that were ever used on that server as long as the system has been booted, right? So the, what happened is, in people’s focus on availability, the LSASS process keeps running. We never designed LSASS to run forever. We designed LSASS to maybe be booted, like, once a week, right?

Just like, “No, we’re just gonna refresh this,” whatever. So now, what happens is if, if the attacker’s in a ransomware, uh, group can gain access to an unpatched Windows server, and if that LSASS process has been running for months or years, or however long that that server’s been up and running, all of the credentials that have ever been used on that box are there.

Wow. And they can, and they get all of them, and that gives them their lateral movement to just go, “Hmm.” And then the ransomware-as-a-service guys, they dump that LSASS process and their tooling automatically takes that to then see, “Okay, do I have some domain admin credentials here? Okay, I do have a domain admin.

Okay, I’m gonna use a GPO to deploy my encryptors- Right. Yeah, yeah … and deploy my management and, and to exfil my data, and do all the stuff I need to do.” And that’s what happens in ransomware-as-a-service. They don’t need any skills. They have the tools that they’ve got through their franchise agreement with the ransomware-as-a-service group.

Roy Akerman:
Mm.

Aaron Turner:
And so, so that’s an example of LSASS that was designed in 1998, a process that we never considered to be running forever. Mm. But now, because it runs forever, all of those credentials are left there latent for, for theft.

Rob Ainscough:
Mm.

Roy Akerman:
And it’s still there. And I think it’s dragged to the cloud as well because we’re still trying to make connectivity, right?

So we’re syncing our AD, uh, uh, credentials or- Right … you know, w- with, with the cloud, and we all know about all these attacks, right?

Rob Ainscough:
Right.

Roy Akerman:
Um, and others. So it’s keep being dragged, um, instead of, like, being solved to some sort. Yeah. Or that, like, like you said, it gives a place to a lot of vendors to come and build the protection layers on top of that.

Rob Ainscough:
Yeah. I think it’s really interesting ’cause, uh, from a security perspective, we’re almost a victim of the success of Active Directory, right? With people, you know, obviously all of their Windows computers are gonna be plugged in. SQL Server, let’s plug that in. Oh, why don’t we bridge Linux off to AD, right?

Building this systemic risk, and then the cloud came along and said, “Hey-” Let’s sync those credentials out there, right? Let’s make this easy, right? So it’s a victim of its own success, which, you know, really makes us much more vulnerable in terms of that systemic risk for companies, right? So

Aaron Turner:
A lot of organizations don’t understand what Active Directory is actually serving up.

They’re just like, “Oh, it just works,” right? I, I don’t know if it’s NTLM, NTLMv2, LDAP, Kerberos. I, I don’t know what’s actually being served up.

Rob Ainscough:
Mm.

Aaron Turner:
And so I think, you know, step one for any organization is You’re gonna have to turn on success logging, which is, was just expensive and resource intensive. Not all organizations have turned on success logging.

Most organizations have failure logging, right, when, when an authentication fails. So step one is for a period of time you’re gonna have to turn on success logging and, and make sure you have enough storage capacity to store all the success logs.

Rob Ainscough:
Yep.

Aaron Turner:
And so now you’ve got that success logs. Then I love to use tools, um, you know, low-cost data, um, and analytics tools.

My favorite one that has a community edition is called Gravwell, G-R-A-V as in Victor, W-E-L-L. Gravwell has a community edition where you can ingest the raw XML logs from, um, from a domain controller and start building visual force-directed graphs of like, I wanna see every user that’s using LDAP today. I wanna see every user that’s using LLM.

I wanna see every server that’s, that’s pinging Kerberos or whatever. And so I can now create these pockets visually, ’cause we as humans, we need visualization. Like, that’s how we, we form strategies. So now I’ve got a visualization to go, “Oh my gosh, I didn’t realize that I have 1,500 users that are relying on clear, clear text LDAP.

That’s bad.” Like, and, and so, but you won’t know that unless you turn on success logging. So there’s step one. Step two is now that you know what’s out there, what can you kill that’s using that stuff? So one of my favorite judo tricks is, is, okay, so you have these five servers here that are using LDAP.

What do they do? Oh, it’s for some tax compliance system that runs off of, uh, an access database. Okay. Well, let’s just take that data and put it in a power platform and make it cloud native and kill that server, and now I don’t have to worry about LDAP anymore, right? I’ve killed the source of the problem and still met the business need because I can run that access database in the power platform.

I don’t have to have that server there anymore. So what can I do to modernize to eliminate that dependency? And then the last component is once I’m on that path, now what can I do to build a sort of segmented identity strategies to go, I’m going to separate cloud privilege management from on-prem privilege management.

I’m going to separate knowledge workers from privilege users. I, I’m gonna do this segmentation of identity that makes sense. And in fact, back in 2020, the NSA published, in my opinion, one of the m- most important declassified identity documents where they disclosed how they got the Russians out of US Treasury.

So this is a blow-by-blow of six months of the NSA doing battle with the Russians, and good on them for being humble enough to do that because not very many people would raise their hand and say, “Hey, it took us six months to clean up this mess.” And so they did that, and in that document they walk through and they say, “Look-” The, the core problem was that Treasury had five identity planes.

They had on-prem AD, they had AD FS to synchronize to Entra, well, at the time it was called Azure AD. They had Okta and they had Duo. Right, so they had these five different identity layers. And, and what’s interesting is a lot of people will say, “Well, I’ve already migrated to the cloud because I have Okta.”

I have never seen an Okta project work without Active Directory. Yeah. Like, I’ve never seen a core Okta thing work by itself.

Rob Ainscough:
This is what I mean, it’s the nerve center, right? It’s, it’s hanging off that fundamental security of Active Directory at the core.

Aaron Turner:
Yeah. And so in, in the NSA case study, where they’re talking about what happened to Treasury, the Russians were hiding because the NSA would get close, and let’s say they get close with Active Directory indicators of compromise, and they’d go chasing there, and then the Russians would go off and live inside of Okta for a little bit, and they’d live off the land in Okta.

And then they’d get close in Okta, and then they’d go to Duo for a little bit. And they get close in Duo, and then they’d go to Entra. And then they get close in Entra, they’d go to AD FS. And so, so essentially, they were just moving where, like cockroaches, right, where the light was not being shined, and, and, and that’s how they lived.

And so my strong recommendation to people is eliminate your, like, make your identity stack as simple as possible. Mm-hmm. Eliminate the use of… And in fact, in that NSA white paper, at, on page three they say, “If you’re using Exchange Online, you’re crazy using anything with Entra Protect.” Like, like, they make it very clear.

You should be tight on your use of cloud identity.

Roy Akerman:
Mm-hmm. I, I think that, like, th- that story makes sense. However, segmentation is really, really, really hard. You need to know the assets. We need to know, like, the homegrown applications, like the, the end essence of, of access, right? So, uh, I, I believe that even, uh, the Treasury had, like, five IDPs or, like, five of, uh, different directory that needed to sync together be- And each one of them was operated probably by different party, right?

Because of that complexity to segment- Mm. Um, you know, so- some of the assets or, like, the resources that we’re trying to access to. Um, I mean, I wonder, you probably found that as well, you know, in the big retailer that you worked for, right, as an IM leader. How many, like, uh, dozen, like, uh, hundreds of thousands of, uh, human identities, not to mention non-human identities, right?

Yeah,

Rob Ainscough:
absolutely. So I think 400,000 people in the company. Yeah. Uh, you know, anywhere between that and 500,000- So- … depending on the time of year, so huge …

Roy Akerman:
a segmentation, yeah, segmentation’s a bad word or, like, it actually can be done?

Rob Ainscough:
I think it can be done. It’s, I think it’s, uh, there’s two important things. I think one is, like, a mindset shift around what identity’s here to do, and that you’re not just here to protect accounts or add MFA, right?

You’re here to protect what matters to your business. And as you say, understanding what matters, understanding what the authentication flows look like and what the access looks like for that thing, and then designing those rules, but having that technology that really supports you to do that is so important.

It’s not easy to do at that scale. It’s not easy to do when you’ve got that fragmentation and that complexity. But I think the first thing is, is thinking in that way and then trying to build that big picture so you understand what’s going on, to then go from there and take that step. Because, you know, protecting everything everywhere all at once isn’t gonna happen, but you can take some really good steps forward to protect what really matters to your business.

Aaron Turner:
So you need

Roy Akerman:
to see the

Rob Ainscough:
entire forest

Aaron Turner:
before

Rob Ainscough:
you’re actually- Exactly … doing that.

Roy Akerman:
Exactly.

Rob Ainscough:
And

Roy Akerman:
then you

Aaron Turner:
do the right controls.

Roy Akerman:
What lessons can our followers learn from, A, the way that cartels use technology in order to run their, like, uh, fluid operations, and from the other side, how identity can be manipulated, like compromised, doubled, when it comes to the law enforcement side.

Yeah, it seems that we’re building, like, a very interesting episode over here. Interesting.

Rob Ainscough:
That’s it for this episode of Identity Decoded.

Aaron Turner:
If this conversation changed anything that you thought about identity security, share it with someone who’s working

Roy Akerman:
through the same challenges.

Rob Ainscough:
And don’t forget to follow the show so you don’t miss what’s

next.

Identity Decoded

with Roy Akerman & Rob Ainscough

Subscribe so you never miss a new episode.