Upcoming Updates to AD, Kerberos, and LDAP

Hello everyone, just wanted to ensure you’ve seen that there are upcoming Microsoft changes to Active Directory, Kerberos, and LDAP that may affect your environments.

https://support.microsoft.com/en-us/topic/kb5008383-active-directory-permissions-updates-cve-2021-42291-536d5555-ffba-4248-a60e-d6cbc849cde1

  • KB5008383—Active Directory permissions updates (CVE-2021-42291)
    • Enforcement Mode expected to be enabled by default in April 2023 updates.

https://support.microsoft.com/en-us/topic/kb5020805-how-to-manage-kerberos-protocol-changes-related-to-cve-2022-37967-997e9acc-67c5-48e1-8d0d-190269bf4efb

  • KB5020805: How to manage Kerberos protocol changes related to CVE-2022-37967
    • Enforcement Mode expected to be enabled by default in July 2023 updates.

https://support.microsoft.com/en-gb/topic/kb5021131-how-to-manage-the-kerberos-protocol-changes-related-to-cve-2022-37966-fd837ac3-cdec-4e76-a6ec-86e67501407d

7 Likes

Is there a way to pull the Active Director Event logs?

We created one that runs once a week that pulls the Kerberos Event logs (42,42 and 44)

(event id of it, description of it) of (records whose (event id of it is contained by set of (42;43;44)) of system event log)

If you do not include the date of the event, you can use Reporting to pull the data to excel and dump it in a pivot table. However, we want to do the same for the Active Directory permissions event logs