Problems with AD
摘要
Active Directory, while still foundational for most organizations’ identity and security, has got a miserable reputation – first and foremost, for its security. A very well-respected IT security professional and a fellow Microsoft MVP recently called AD “a cybersecurity cancer” and called for abandoning it as quickly as possible in favor of SAML-based authentication systems and, ultimately, cloud. This may or may not be feasible middle-term in your particular organization, and the fact that you’re reading this book indicates that you probably fall into the second category, which means that you, like a big portion of the IT world, are stuck with AD for the foreseeable future, making it not a “cancer that can only be attacked by chemo and radiation” but rather a “problem that needs a solution.” And since acknowledging the problem is the necessary first step to solving it, we will devote this chapter to looking at why AD actually appears to be so incredibly bad at what it’s been designed to do and what organizations have it do (there is a difference between the two; we’ll get to that in a bit).