惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
腾讯CDC
爱范儿
爱范儿
Google DeepMind News
Google DeepMind News
V
V2EX
Blog — PlanetScale
Blog — PlanetScale
Engineering at Meta
Engineering at Meta
GbyAI
GbyAI
量子位
F
Fortinet All Blogs
G
Google Developers Blog
T
The Blog of Author Tim Ferriss
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Hugging Face - Blog
Hugging Face - Blog
Last Week in AI
Last Week in AI
T
Tailwind CSS Blog
J
Java Code Geeks
S
SegmentFault 最新的问题
D
Docker
博客园 - 司徒正美
The GitHub Blog
The GitHub Blog
Jina AI
Jina AI
M
MIT News - Artificial intelligence
博客园 - 【当耐特】

The Register - Off-Prem: Channel

'Death sentence': EU cloud lobby drags Broadcom to Brussels Iran war wreaking havoc on cargo, global delays likely OpenAI asks consultants to help it push Frontier OpenAI asks consultants to help it push Frontier ICO wins battle in fight to fine tech retailer £500k Rising memory costs see vendors change terms and conditions Capgemini to sell biz that has a deal to help ICE Ingram Micro admits ransomware raid exposed staff records Hiring at India’s Big Four outsourcers stalls as AI bites Hiring at India’s Big Four outsourcers stalls as AI bites Accenture to buy Palantir rival, UK-based Faculty The ‘Palantir-ization’ of IT services is upon us Amazon straps AI smart specs to delivery drivers Microsoft pivots to copyright claim in ValueLicensing case Client defended engineer boss lied about dodgy dealings Client defended engineer boss lied about dodgy dealings Node4 awarded £2.4M in damages after Tisski takeover Trump tariff turmoil toys with PC sales, economy not helping Everyone needs an AI phone. No, don't hang up, it's true Microsoft software reselling dispute heads back to UK court KPMG wrote 100-page prompt to build agentic TaxBot Google admits anticompetitive conduct in Australia Foxconn now making more from servers than iPhones Stock in the Channel pulls website amid cyberattack Ebuyer website bought by Fraser Group plc Ingram Micro attackers threaten 3.5 TB data leak this week India, not China, manufactures most US smartphones now India, not China, manufactures most US smartphones now Microsoft exec admits it 'cannot guarantee' data sovereignty Infosec firm Adarma confirms it will enter administration
Microsoft pauses delayed partner ecosystem security update
Simon Sharwood Simon Sharwood · 2023-03-16 · via The Register - Off-Prem: Channel

Channel

Active Directory privilege de-escalation will run for nine days in May before taking June off

Microsoft's delayed effort to ensure its partners don't enjoy unduly privileged access to their clients' systems will run for just nine days before pausing for a month.

Partners of the Redmond-based software colossus have historically relied on "delegated admin privileges" (DAP) to manage and monitor clients' systems and software purchases.

In the wake of criminal attacks on managed services providers and the software they use to tend their clients, Microsoft decided DAP privileges offered dangerously extensive access.

The company therefore created granular delegated admin privileges (GDAP).

As the name implies, GDAP limits the resources and permissions partners enjoy when driving their customers' systems. It also adds zero-trust principles to further reduce the likelihood that an attack on a partner will mean pain for end customers. Partners and Microsoft customers alike were told they would need to stop using DAPs and instead move to GDAPs.

So far, so sensible.

But also a little controversial, because partners can create GDAP profiles in customers' Active Directory implementations – customers don't need to give permission for the creation of GDAP profiles, but do need to sign them off.

The move from DAP to GDAP has been slow. Microsoft set October 31, 2022, as the date on which it would discontinue the software that automates DAP to GDAP migrations, then moved that date to March 1, 2023. Those delays came after Redmondt's initial ambition was for DAP to die by the end of 2022.

A March 15 2023 missive from Microsoft to partners offered an update on the move from DAP to GDAP, which will commence on May 22.

"For relationships that have been transitioned from DAP to GDAP, we'll proceed to remove the corresponding DAP relationships 30 days later," the post states, before adding "However, we'll pause the transition for the month of June 2023 to support the Microsoft fiscal year closure."

Microsoft's fiscal year ends on June 30. Late in a fiscal year, businesses usually scramble to bring in every cent of revenue it's possible to find.

The June pause of GDAP migrations therefore suggests the company has made its own concerns a higher priority than this transition.

For those few days in May, then later in July, Microsoft will make the following changes:

  1. Directory readers – can read basic directory information; commonly used to grant directory read access to applications and guests
  2. Directory writers – can read and write basic directory information; for granting access to applications, not intended for users
  3. License administrator – can manage product licenses on users and groups
  4. Service support administrator – can read service health information and manage support tickets
  5. User administrator – can manage all aspects of users and groups, including resetting passwords for limited admins
  6. Privileged role administrator – can manage role assignments in Azure AD and all aspects of Privileged Identity Management (PIM)
  7. Helpdesk administrator – can reset passwords for non-administrators and Helpdesk administrators
  8. Privileged authentication administrator – can access view, set, and reset authentication method information for any user (admin or non-admin)

The changes listed above should improve security, an outcome Microsoft champions – except, seemingly, in June while it counts its cash. ®