In the current issue 11/2021 of iX, Frank Ully, CTO Oneconsult Deutschland AG, completes the series of articles on the topic of Active Directory (AD) security, which was launched last fall. The last part of the series deals with possibilities of actively defending the AD in order to deceive attackers and thus prevent attack attempts at an early stage.

The deception approach pursues the idea of detecting an attacker by luring him into a trap with false trails, for example, supposedly genuine user accounts with misconfigurations as honeypots. If the attacker exploits these apparent vulnerabilities, it triggers an alert, which in turn allows the attack to be quickly countered and prevented. Using this method as a supplement to passive security measures, administrators can further protect the AD.

