That Other Book

The picture is provided by a friend and generated
by what probably was marketed as “AI”.

I am not going to publish a book on HOW to actually configure things “Building Modern Active Directory” is describing. However, I feel that some of the topics did not get the coverage they deserve by Microsoft or by any of the previous authors. In some cases, coverage exists but I strongly disagree with the methodology described there. In these cases, I will provide a book chapter here.

Authentication Policies – Why, What and How

Many concepts of the Modern AD are based on Authentication Policies – arguably the best thing that happened to Kerberos since the introduction of AES encryption. Unfortunately, the concept remains a little vague, design and administration are not self-explanatory by any standard, and troubleshooting arcane at best. Time to unpack this part of AD in a structured way.

Authentication Policies – Across Forests

AuthN Policies and Silos are not trivial even within one AD forest where they are part of the forestwide Kerberos configuration. What if they need to be applied across forests? What about one-way trusts, most important of which is undoubtedly the Red Forest architecture? If these are among questions that keep you awake at night, you will find your answers here.

Tier Zero isolation the easy and consistent way

Once we covered Authentication Policies in sufficient detail, we have all we need to provide a hands-on approach to Tier 0 isolation.

Virtual PAW that will survive a pentest

Virtual PAWs are the Holy Grail of AD security – pure doctrine says they shouldn’t be possible, and the most trusted admins have to lug multiple notebooks around. In this chapter we will explore just how far, exactly, we need to reduce the paranoia level in order for virtual PAWs to become acceptable even for Tier 0 administration.

Red Forest that really gets you more secure

The purpose of a Red Forest is very simple: to offset the structural challenge we have in AD that any principal can be make God in its own forest by assigning privileges to it. By keeping the administrative principal capable of such an act out of the – potentially vulnerable – Golden Forest we strive to reduce its exposure. There are, however, many misconceptions around the Red Forest concept, which we want to take care of.


Are you missing another “what” or “how” chapter that you couldn’t find in another book? I cannot promise to provide it here on short notice, but if you have a copy of my book, leave a review of it where you bought it, hit me up on LinkedIn or BlueSky, and I will see what I can do!