{"id":2096,"date":"2018-03-30T09:50:56","date_gmt":"2018-03-30T07:50:56","guid":{"rendered":"http:\/\/www.identitycosmos.com\/?p=2096"},"modified":"2018-03-30T09:50:56","modified_gmt":"2018-03-30T07:50:56","slug":"activedirectory-10-security-questions","status":"publish","type":"post","link":"https:\/\/identitycosmos.com\/index.php\/2018\/03\/30\/activedirectory-10-security-questions\/","title":{"rendered":"S\u00e9curit\u00e9 Active Directory, les 10 questions \u00e0 se poser imm\u00e9diatement : Toutes les organisations pensent avoir un tr\u00e8s bon niveau de s\u00e9curit\u00e9 de leur Active Directory\u2026avant\u2026de discuter avec moi !"},"content":{"rendered":"<p><a href=\"http:\/\/www.identitycosmos.com\/http:\/www.identitycosmos.com\/strategie\/securite-active-directory-les-10-questions-a-se-poser-immediatement-toutes-les-organisations-pensent-avoir-un-tres-bon-niveau-de-securite-de-leur-active-directoryavantde-discuter\/attachment\/autruche-tete-dans-le-sable\" rel=\"attachment wp-att-2098\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-2098\" src=\"http:\/\/identitycosmos.com\/wp-content\/uploads\/2018\/03\/autruche-tete-dans-le-sable.jpg\" alt=\"\" width=\"219\" height=\"280\" \/><\/a>\u00a0Chaque semaine, je discute avec des dizaines d&#8217;organisations, des tr\u00e8s grandes, des moyennes, des gigantesques\u2026 c&#8217;est assez vari\u00e9. Le point commun de l&#8217;ensemble de ces organisations, c&#8217;est leur <span style=\"text-decoration: underline;\">certitude<\/span> d&#8217;avoir un environnement Active Directory extr\u00eamement s\u00e9curis\u00e9, c&#8217;est assez amusant.<\/p>\n<p>J&#8217;insiste, mes contacts ne veulent pas \u00ab\u00a0m&#8217;abuser\u00a0\u00bb ou me \u00ab\u00a0faire croire\u00a0\u00bb\u2026 ils sont vraiment <span style=\"text-decoration: underline;\">persuad\u00e9s<\/span> de maintenir un environnement Active Directory s\u00e9curis\u00e9\u2026 Quand je leur demande de fournir une note entre 1 et 10 sur l&#8217;estimation du niveau de s\u00e9curit\u00e9 de leur Active Directory, la plupart des r\u00e9ponses sont positionn\u00e9es entre 7 et 9 &#8211; ils sont malheureusement tr\u00e8s loin de la r\u00e9alit\u00e9\u2026plus pr\u00e9cis\u00e9ment de <span style=\"text-decoration: underline;\">leur<\/span> r\u00e9alit\u00e9\u2026<\/p>\n<p>Evidemment, le nouveau paradigme IT fait que la s\u00e9curit\u00e9 p\u00e9rim\u00e9trique disparait petit \u00e0 petit au profit de la s\u00e9curit\u00e9 de la donn\u00e9es et de la s\u00e9curit\u00e9 de l&#8217;identit\u00e9 \u2013 M\u00eame \u00e0 l&#8217;heure du Cloud public, l&#8217;Active Directory se trouve au centre de cette strat\u00e9gie Data+Identity \u2013 mais \u2013 ce qui est paradoxal, c&#8217;est que la plupart des designs et infrastructures Active Directory ont \u00e9t\u00e9 impl\u00e9ment\u00e9s il y a une dizaine d&#8217;ann\u00e9es, \u00e0 une \u00e9poque o\u00f9 la s\u00e9curit\u00e9 p\u00e9rim\u00e9trique \u00e9t\u00e9 reine et le Cloud public s&#8217;appelait encore ASP\u2026 Il y a donc beaucoup de chose \u00e0 revoir, quitte \u00e0 bousculer les certitudes\u2026<\/p>\n<p>Il est au final assez simple de mesurer le niveau de s\u00e9curit\u00e9 d&#8217;un environnement Active Directory, j&#8217;utilise g\u00e9n\u00e9ralement<strong> 10 questions<\/strong> assez simples me permettant d&#8217;\u00e9valuer le niveau de maturit\u00e9 du client sur la partie Active Directory\u00a0:<\/p>\n<p><!--more--><\/p>\n<div>\n<table style=\"border-collapse: collapse;\" border=\"0\">\n<colgroup>\n<col style=\"width: 47px;\" \/>\n<col style=\"width: 567px;\" \/>\n<col style=\"width: 69px;\" \/>\n<col style=\"width: 72px;\" \/><\/colgroup>\n<tbody valign=\"top\">\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border: solid 0.5pt;\">#<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: solid 0.5pt; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">Questions<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: solid 0.5pt; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">OUI<\/p>\n<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: solid 0.5pt; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">NON<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">1<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">Sans v\u00e9rifier, pouvez me dire combien de comptes sont administrateurs de vos domaines Active Directory\u00a0?<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">2<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">Avez-vous la liste de tous les changements r\u00e9alis\u00e9s et par qui, dans votre annuaire Active Directory depuis 90 jours\u00a0?<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">3<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">Avez-vous une trace vid\u00e9o ou texte de l&#8217;ensemble des actions r\u00e9alis\u00e9es par vos comptes \u00e0 pouvoir sur vos syst\u00e8mes d&#8217;exploitation int\u00e9gr\u00e9s dans Active Directory\u00a0?<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">4<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">Etes-vous capable de restaurer votre For\u00eat Active Directory en moins de 24 h \u2013 Si le client ne sait pas r\u00e9pondre, la question devient\u00a0: avez-vous test\u00e9 de restaurer compl\u00e8tement (compl\u00e8tement = 100% from scratch, on consid\u00e8re ici que aucun DC n&#8217;est en ligne pour faire le test, on part de z\u00e9ro) votre for\u00eat Active Directory sur un environnement d&#8217;int\u00e9gration\u00a0?<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">5<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">Si un utilisateur utilise un outil permettant d&#8217;acc\u00e9der \u00e0 la m\u00e9moire vive de son PC, \u00eates-vous capable de le d\u00e9tecter\u00a0?<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">6<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">Est-ce qu&#8217;un compte administrateur du domaine a la possibilit\u00e9 d&#8217;ouvrir une session sur un serveur membre afin de l&#8217;administrer\u00a0?<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">7<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">Est-ce que le compte de service utilis\u00e9 pour faire tourner vos antivirus sur vos postes de travail est membre du groupe \u00ab\u00a0domain admins\u00a0\u00bb\u00a0?<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">8<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">Est-ce que vos comptes administrateurs de domaine utilisent un deuxi\u00e8me facteur d&#8217;authentification pour ouvrir une session\u00a0?<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">9<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">Dans votre RACI li\u00e9 \u00e0 l&#8217;activit\u00e9 de gestion Active Directory, avez-vous identifi\u00e9 la notion de DATA et de SERVICES\u00a0?<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">10<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">Utilisez-vous un syst\u00e8me de re-certification de vos objets GPOs et Security Group sur un intervalle inf\u00e9rieur \u00e0 1 an\u00a0?<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>Les bonnes r\u00e9ponses sont les suivantes\u00a0:<\/p>\n<div>\n<table style=\"border-collapse: collapse;\" border=\"0\">\n<colgroup>\n<col style=\"width: 47px;\" \/>\n<col style=\"width: 567px;\" \/>\n<col style=\"width: 69px;\" \/>\n<col style=\"width: 72px;\" \/><\/colgroup>\n<tbody valign=\"top\">\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border: solid 0.5pt;\">#<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: solid 0.5pt; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">Questions<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: solid 0.5pt; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">OUI<\/p>\n<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: solid 0.5pt; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">NON<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">1<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">X<\/p>\n<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">2<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">X<\/p>\n<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">3<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">X<\/p>\n<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">4<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">X<\/p>\n<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">5<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">X<\/p>\n<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">6<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">X<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">7<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">X<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">8<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">X<\/p>\n<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">9<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">X<\/p>\n<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: solid 0.5pt; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">10<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\">\n<p style=\"text-align: center;\">X<\/p>\n<\/td>\n<td style=\"padding-left: 9px; padding-right: 9px; border-top: none; border-left: none; border-bottom: solid 0.5pt; border-right: solid 0.5pt;\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>Si le client a moins de 50% de bonnes r\u00e9ponses, et bien c&#8217;est tr\u00e8s simple, <span style=\"color: #ff0000;\"><strong>il est en danger<\/strong><\/span>, je dirais m\u00eame en grand danger\u2026 mais il ne le sait pas&#8230;\u00a0\u00a0bon, du coup, on fait quoi ? on anticipe le danger ou on attend de se faire d\u00e9pouiller ?<\/p>\n<p><a href=\"http:\/\/www.identitycosmos.com\/http:\/www.identitycosmos.com\/strategie\/securite-active-directory-les-10-questions-a-se-poser-immediatement-toutes-les-organisations-pensent-avoir-un-tres-bon-niveau-de-securite-de-leur-active-directoryavantde-discuter\/attachment\/autruche-tete-simple\" rel=\"attachment wp-att-2100\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-2100\" src=\"http:\/\/identitycosmos.com\/wp-content\/uploads\/2018\/03\/autruche-tete-simple.jpg\" alt=\"\" width=\"395\" height=\"400\" srcset=\"https:\/\/identitycosmos.com\/wp-content\/uploads\/2018\/03\/autruche-tete-simple.jpg 395w, https:\/\/identitycosmos.com\/wp-content\/uploads\/2018\/03\/autruche-tete-simple-296x300.jpg 296w\" sizes=\"auto, (max-width: 395px) 100vw, 395px\" \/><\/a>Si votre manager vous explique que la s\u00e9curit\u00e9 co\u00fbte trop cher et que de toute fa\u00e7on Active Directory, cela ne se voit pas et que l&#8217;on ne peut pas avoir de budget, \u00e9crivez un document expliquant ce que vous constatez sur votre AD et la liste de ce que vous proposez de faire pour corriger &#8211; et indiquez que vous d\u00e9gagez votre responsabilit\u00e9 sur les pannes futures de votre service d&#8217;annuaire&#8230; vous verrez cela devrait le d\u00e9tendre \ud83d\ude09<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0Chaque semaine, je discute avec des dizaines d&#8217;organisations, des tr\u00e8s grandes, des moyennes, des gigantesques\u2026 c&#8217;est assez vari\u00e9. Le point commun de l&#8217;ensemble de ces organisations, c&#8217;est leur certitude d&#8217;avoir un environnement Active Directory extr\u00eamement s\u00e9curis\u00e9, c&#8217;est assez amusant.<\/p>\n<p>J&#8217;insiste, mes contacts ne veulent pas \u00ab\u00a0m&#8217;abuser\u00a0\u00bb ou me \u00ab\u00a0faire croire\u00a0\u00bb\u2026 ils sont vraiment persuad\u00e9s de maintenir un environnement Active Directory s\u00e9curis\u00e9\u2026 Quand je leur demande de fournir une note entre 1 et 10 sur l&#8217;estimation du niveau de s\u00e9curit\u00e9 de leur Active Directory, la plupart des r\u00e9ponses sont positionn\u00e9es entre 7 et 9 &#8211; ils sont malheureusement tr\u00e8s loin de la r\u00e9alit\u00e9\u2026plus pr\u00e9cis\u00e9ment de leur r\u00e9alit\u00e9\u2026<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[14,76,110,216],"class_list":["post-2096","post","type-post","status-publish","format-standard","hentry","category-strategie","tag-active-directory","tag-cyber-security","tag-hardening-active-directory","tag-securite"],"_links":{"self":[{"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/posts\/2096","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/comments?post=2096"}],"version-history":[{"count":0,"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/posts\/2096\/revisions"}],"wp:attachment":[{"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/media?parent=2096"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/categories?post=2096"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/identitycosmos.com\/index.php\/wp-json\/wp\/v2\/tags?post=2096"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}