<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows AD Trust review in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Windows-AD-Trust-review/m-p/52149#M706</link>
    <description>&lt;P&gt;Both flags are related to Trust relationships in AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is very difficult to say what can go right/wrong without full understanding of the environment.&amp;nbsp; What trusts are set up?&amp;nbsp; What does the forrest look like?&amp;nbsp; Are these flags being used Internally/externally/ both?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Microsoft Technet has a wealth of knowledge on these flags and others.&amp;nbsp; Here is one link:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc794801(v=ws.10)?redirectedfrom=MSDN" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc794801(v=ws.10)?redirectedfrom=MSDN&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SID filtering quarantining is typically used to prevent&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;attackers that have compromised a domain controller in a trusted domain to use the SID history attribute to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;grant themselves unauthorized rights.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Others?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;d&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 24 Jul 2022 22:59:59 GMT</pubDate>
    <dc:creator>dcontesti</dc:creator>
    <dc:date>2022-07-24T22:59:59Z</dc:date>
    <item>
      <title>Windows AD Trust review</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Windows-AD-Trust-review/m-p/52146#M705</link>
      <description>Hello:&lt;BR /&gt;I wanted some quick education on important windows AD Trust terminology for an AD trust relationships audit.&lt;BR /&gt;&lt;BR /&gt;I have researched online but I can’t seem to find good business level (the why behind the what) explanations&lt;BR /&gt;&lt;BR /&gt;Specifically; What is meant by the following flag values&lt;BR /&gt;SID Filtering Forestaware = false (or true)&lt;BR /&gt;SID Filtering Quarintine = false (or true).&lt;BR /&gt;&lt;BR /&gt;what is the significance of these flags, why so, what could go wrong if set one way vs. the other and best practice security settings for them</description>
      <pubDate>Sat, 23 Jul 2022 21:26:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Windows-AD-Trust-review/m-p/52146#M705</guid>
      <dc:creator>Midude2000</dc:creator>
      <dc:date>2022-07-23T21:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Windows AD Trust review</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Windows-AD-Trust-review/m-p/52149#M706</link>
      <description>&lt;P&gt;Both flags are related to Trust relationships in AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is very difficult to say what can go right/wrong without full understanding of the environment.&amp;nbsp; What trusts are set up?&amp;nbsp; What does the forrest look like?&amp;nbsp; Are these flags being used Internally/externally/ both?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Microsoft Technet has a wealth of knowledge on these flags and others.&amp;nbsp; Here is one link:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc794801(v=ws.10)?redirectedfrom=MSDN" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc794801(v=ws.10)?redirectedfrom=MSDN&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SID filtering quarantining is typically used to prevent&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;attackers that have compromised a domain controller in a trusted domain to use the SID history attribute to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;grant themselves unauthorized rights.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Others?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;d&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2022 22:59:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Windows-AD-Trust-review/m-p/52149#M706</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2022-07-24T22:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: Windows AD Trust review</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Windows-AD-Trust-review/m-p/52152#M707</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/985787817"&gt;@Midude2000&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt; Personally I would check with the Center for Internet Security (CIS) &lt;A href="https://www.cisecurity.org/" target="_blank"&gt;https://www.cisecurity.org/&lt;/A&gt; they have a range of guidance and baselines and tools, which help you review the current environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a bunch of free baselines for Microsoft Windows Servers, Desktop etc have a look through those baselines, and register, there is some very good guidelines you can use for reviews and even some tools to check those baselines against as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An example of an updated baseline or benchmark is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisecurity.org/insights/blog/update-cis-microsoft-windows-10-enterprise-release-1703-benchmark-v1-0-0" target="_blank"&gt;https://www.cisecurity.org/insights/blog/update-cis-microsoft-windows-10-enterprise-release-1703-benchmark-v1-0-0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 00:32:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Windows-AD-Trust-review/m-p/52152#M707</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2022-07-25T00:32:33Z</dc:date>
    </item>
  </channel>
</rss>

