RunAs Radio

Fixing a Security Vulnerability in Active Directory with Steve Syfuhs


Listen Later

Why would a security vulnerability take more than two years to fix? Richard chats with Steve Syfuhs about the evolution of the response to KB5015754. Originally published in 2022, the issue involved vulnerabilities in the on-premises certificate authority for Active Directory. Pushing a fix to force the immediate replacement of the certificates could have left users unable to log into Active Directory entirely. Steve explains how the gradual rollout of the fix allowed folks concerned (and paying attention!) to fix it immediately. At the same time, for everyone else, the fix happened as the existing certificates expired. But not every scenario is automatic - some require sysadmin intervention. So, how do you get their attention? The story leads to the February 11, 2025 update that could knock some users off Active Directory, but had an easy and quick fix. The final phase should be September 2025; hopefully, the last stragglers will be ready!

Links

  • KB5014754
  • Microsoft Security Response Center
  • Create and Assign SCEP Certificate Profiles in Intune

Recorded April 10, 2025

...more
View all episodesView all episodes
Download on the App Store

RunAs RadioBy Richard Campbell

  • 4.6
  • 4.6
  • 4.6
  • 4.6
  • 4.6

4.6

80 ratings


More shows like RunAs Radio

View all
This Week in Tech (Audio) by TWiT

This Week in Tech (Audio)

3,010 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

1,982 Listeners

Hanselminutes with Scott Hanselman by Scott Hanselman

Hanselminutes with Scott Hanselman

377 Listeners

Software Engineering Radio - the podcast for professional software developers by se-radio@computer.org

Software Engineering Radio - the podcast for professional software developers

272 Listeners

.NET Rocks! by Carl Franklin and Richard Campbell

.NET Rocks!

37 Listeners

.NET Rocks! by Carl Franklin and Richard Campbell

.NET Rocks!

243 Listeners

MacBreak Weekly (Audio) by TWiT

MacBreak Weekly (Audio)

2,012 Listeners

Windows Weekly (Audio) by TWiT

Windows Weekly (Audio)

868 Listeners

Risky Business by Patrick Gray

Risky Business

364 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

639 Listeners

Intelligent Machines (Audio) by TWiT

Intelligent Machines (Audio)

733 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

284 Listeners

Tech News Weekly (Audio) by TWiT

Tech News Weekly (Audio)

1,073 Listeners

The Cloudcast by Massive Studios

The Cloudcast

154 Listeners

The Stack Overflow Podcast by The Stack Overflow Podcast

The Stack Overflow Podcast

63 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

91 Listeners