Entra.Chat

Pushing Microsoft Entra to its Limits to Secure On-Prem AD


Listen Later

In this episode, we talk with an identity expert, ex-Microsoftie and Principal Domain Architect, Mark Renoden, about creating a modern Privileged Access Management (PAM) solution for on-premises Active Directory. Discover how to build a secure "Bastion Forest" architecture using Microsoft Entra. We talk about PIM for Groups, group write-back, phish-resistant credentials, Privileged Access Workstations (PAW), securing an Entra tenant from the ground up, and navigating challenges with Cloud Solution Provider (CSP) permissions.

Watch on YouTube

PS. Can I ask a favor? If you enjoyed this episode please leave a review and rating! Thank you ๐Ÿ™ - Merill

About Mark

As Principal Domain Architect for Identity at Increment, Mark leads the design and delivery of secure, scalable identity architectures grounded in Microsoft Entra ID and aligned with Zero Trust principles. He specializes in helping organisations modernise their infrastructure and navigate complex identity transformations.

Previous to Increment, Mark spent over 20 years at Microsoft in support, field engineering, mission critical and customer experience roles focused on Identity across a wide spectrum of industries in Australia and New Zealand, including Finance, Healthcare, Government, Education and Retail.

LinkedIn - https://www.linkedin.com/in/markrenoden/

๐Ÿ”— Related Links

* DirectoryShield | Increment - https://www.increment.inc/directoryshield

* Entra Security Recommendations - https://aka.ms/EntraSecurityRecommendations

* Securing privileged access overview - https://learn.microsoft.com/en-us/security/privileged-access-workstations/privileged-access-overview

* MIM - Bastion environment - https://learn.microsoft.com/en-us/microsoft-identity-manager/pam/planning-bastion-environment

๐Ÿ“— Chapters

00:46 Securing Your Entra Tenant

02:09 The Quest for a Microsoft-Only PAM Solution

04:21 What is a "Bastion Forest"?

07:50 Reimagining the Bastion Forest for the Cloud

12:53 Architecting a "Secure-by-Default" Tenant

17:41 Phish-Resistant On-Prem Admins

19:50 The Modern Privileged Access Workstation (PAW)

27:04 The Tiered Administration Model Explained

29:51 The Hidden Dangers of CSP Admin Access

34:29 How Fast is PIM for Groups?

Podcast Apps

๐ŸŽ™๏ธ Entra.Chat - https://entra.chat

๐ŸŽง Apple Podcast โ†’ https://entra.chat/apple

๐Ÿ“บ YouTube โ†’ https://entra.chat/youtube

๐Ÿ“บ Spotify โ†’ https://entra.chat/spotify

๐ŸŽง Overcast โ†’ https://entra.chat/overcast

๐ŸŽง Pocketcast โ†’ https://entra.chat/pocketcast

๐ŸŽง Others โ†’ https://entra.chat/rss

Merill's socials

๐Ÿ“บ YouTube โ†’ youtube.com/@merillx

๐Ÿ‘” LinkedIn โ†’ linkedin.com/in/merill

๐Ÿค Twitter โ†’ twitter.com/merill

๐Ÿ•บ TikTok โ†’ tiktok.com/@merillf

๐Ÿฆ‹ Bluesky โ†’ bsky.app/profile/merill.net

๐Ÿ˜ Mastodon โ†’ infosec.exchange/@merill

๐Ÿงต Threads โ†’ threads.net/@merillf

๐Ÿค– GitHub โ†’ github.com/merill



Get full access to Entra.News - Your weekly dose of Microsoft Entra at entra.news/subscribe
...more
View all episodesView all episodes
Download on the App Store

Entra.ChatBy Merill Fernando

  • 5
  • 5
  • 5
  • 5
  • 5

5

5 ratings


More shows like Entra.Chat

View all
StarTalk Radio by Neil deGrasse Tyson

StarTalk Radio

14,346 Listeners

The Infinite Monkey Cage by BBC Radio 4

The Infinite Monkey Cage

1,954 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,647 Listeners

Risky Business by Risky Business Media

Risky Business

371 Listeners

Down the Security Rabbithole Podcast (DtSR) by Rafal (Wh1t3Rabbit) Los

Down the Security Rabbithole Podcast (DtSR)

99 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

651 Listeners

Click Here by Recorded Future News

Click Here

418 Listeners

Microsoft Cloud IT Pro Podcast by Ben Stegink, Scott Hoag

Microsoft Cloud IT Pro Podcast

66 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,076 Listeners

Hacking Humans by N2K Networks

Hacking Humans

315 Listeners

Three Buddy Problem by Security Conversations

Three Buddy Problem

61 Listeners

Hybrid Identity Protection Podcast by Semperis

Hybrid Identity Protection Podcast

3 Listeners

CISO Tradecraftยฎ by G Mark Hardy & Ross Young

CISO Tradecraftยฎ

48 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

45 Listeners

Critical Thinking - Bug Bounty Podcast by Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Critical Thinking - Bug Bounty Podcast

55 Listeners