Skip to content

MAHARJAN-BINOD

"Innovate, Implement, Inspire."

Menu
    • Active Directory (AD)
      • ACTIVE DIRECTORY CERTIFICATE SERVICES
      • ACTIVE DIRECTORY DOMAIN SERVICES
      • AZURE-ADCONNECT
      • DOMAIN NAME SERVER (DNS)
    • Azure (AZ)
    • Azure Site Recovery
    • Blog
    • Exchange-Server-2019-CU13
    • Exchange-Server-2019-CU15
    • Exchange-Server-SE
    • FILE-SERVER
    • GPOs
    • GROUP POLICY MANAGEMENT
    • Group Policy Series
    • MAHARJAN-BINOD
    • Microsoft Exchange
    • Microsoft365 (M365)
      • MS-Intune
    • MS-Exchange
    • My Blogs
    • Office-Online-Server (OOS)
    • SHAREPOINT-ONLINE (SP-Online)
    • Why Read My Blog?
    • WINDOWS-SERVER
    • WSUS-SERVER

ACTIVE-DIRECTORY

ACTIVE-DIRECTORY / AD-SECURITY

AD Security Series Part 1: How to Audit and Fix Kerberoasting & AS-REP Roasting

Introduction Start by explaining that attackers don’t always need to “break in”—sometimes they just “ask.” “In Active Directory, certain accounts are configured in a way that allows any authenticated user …

GPO

BitLocker Series Part 5: Automating Recovery Password Cleanup via PowerShell

Introduction Over time, a single computer object in Active Directory can accumulate multiple BitLocker recovery GUIDs. This happens during OS reinstalls, manual decryption/re-encryption cycles, or when “Backup to AD” policies …

GPO

BitLocker Series Part 4: Moving from Auto-Unlock to Manual Security

Introduction In an era where physical device theft and sophisticated “cold boot” attacks are rising, relying on transparent encryption is no longer enough for high-stakes environments. While BitLocker’s “Auto-Unlock” features …

GPO

BitLocker GPO Series | Part 3: Testing Persistence, Portability, and New Hardware

Introduction In Part 2, we secured our internal fixed drives. But a common question from IT managers is: “What happens to the policy when the hardware changes?” In this post, …

GPO

BitLocker GPO Series | Part 2: Automating Protection for Fixed Data Drives

Introduction In the first part of this series, we secured the Operating System drive. However, in many enterprise environments, workstations are equipped with secondary internal drives for storage. Leaving these …

GPO

BitLocker GPO Series | Part 1: Establishing the Security Foundation

Introduction In an era where data breaches can define the reputation of an organization, securing “data at rest” is no longer optional—it is a baseline requirement. For many IT administrators, …

ACTIVE-DIRECTORY

Part 7: The Bridge to the Cloud — Connecting Your City to the World

We have spent this series building a secure, organized, and resilient “Identity City” on our local servers. But in the modern world, your city doesn’t exist in a vacuum. Your …

ACTIVE-DIRECTORY

Part 6: Digital Citizens — Organizing Users and Groups Without the Mess

We have built the city, established the map, and written the laws. Now, it’s time to talk about the people who live there: the Users. In Active Directory, managing users …

ACTIVE-DIRECTORY

Part 5: The City Rules — Managing Thousands with Group Policy

In the previous parts of our series, we built the city, set up the guard towers, and mapped the roads. But a city without laws is just a crowd. To …

ACTIVE-DIRECTORY

Part 4: The Map of the City — Why DNS is Everything

In our last post, we looked at the Guard Towers (Domain Controllers). But how does your computer actually find the Guard Tower in a city of thousands of buildings? It …

Posts navigation

Older posts
Copyright © 2026 MAHARJAN-BINOD. All rights reserved.