Yesterday, I spent some time talking with Daniel Stefaniak about Active Directory. Daniel is one of the hosts of the 425Show, so we decided to record and publicly share an hour of our regular 'Old guys yelling at cloud' discussions for this show.
About the 425Show
The 425Show is a Twitch live stream, run by the Microsoft Identity Developer Advocacy crew. Christos Matskas, Stefan van der Wiele and Daniel Stefaniak run this show. Their goal is to provide two livestreams per week at 10 AM ET. Of course, this is 4PM in Europe, hence the name.
When Daniel asked me to join, I didn't hesitate and immediately sais 'Yes'. We found a time slot that suited both of us and just made it work.
Topics
This episode of the 425Show contains our usual banter. If you're looking for some specific tidbits, tune into the following timeframes:
02:11 – 04:48 Introduction
04:48 – 10:31 Active Directory licensing explained
10:32 – 14:51 What's New in AD DS in Windows Server 2008
14:52 – 15:38 Active Directory Functional Levels
15:39 – 18:37 Backup and Restore tests as part of AD projects
18:38 – 21:11 Automating AD changes and rotating krbtgt secrets
21:12 – 24:32 Ungooglable Legacy documentation
24:33 – 27:02 Active Directory Horror Stories
27:03 – 30:58 Learning from books
20:59 – 33:33 Good consultants vs. lazy consultants
33:34 – 34:41 Microsoft Certified Masters
34:42 – 37:02 Active Directory, so lonely
37:03 – 39:20 AD Scalability vs. Azure AD
39:21 – 40:09 KDCProxy
40:10 – 41:44 The logic behind .local domain names
41:45 – 42:30 DNS, typo or PKI?
42:31 – .44:00 Active Directory and KQL
44:01 – 47:04 Krbtgt revisited, with repadmin
47:04 – 47:37 Did Daniel just stop talking there!?
47:38 – 51:45 Active Directory Replication and going back in time
51:46 – 52:21 Linked value replication (LVR) in Windows Server 2003
52:22 – 53:19 Amazed at how Active Directory still keeps running
53:20 – 59:19 Dynamic Access Control and Kerberos Armoring
59:20 – 60:03 Active Directory in Windows Server 2022
60:04 – 62:26 From Functional Levels to Star Trek
62:27 – 64:50 LDAP Pings, DCLocator and other things that might not work as expected
64:51 – 66:43 Nerding out on cloudy things
66:40 – 68:40 Password filters, LSASS crashes and analyzing memory dumps
68:40 – 70:33 Concluding
Login