---
title: "Authentication Insights Newsletter"
description: "Get monthly insights for Active Directory practitioners."
locale: "en"
updated_at: "2026-09-29T08:40:31.532Z"
canonical: "https://www.isdecisions.com/en/authentication-insights"
---

# Authentication Insights

_Monthly newsletter and webinar series_

Practical insights on authentication and identity for IT teams managing on-prem and hybrid Active Directory environments.

## Authentication Insights webinars

Join us for deep dive sessions with guest experts. Register to attend live and receive the on-demand recording.

### What pentesters fix first: 5 AD hardening wins

Spencer Alessi, Microsoft MVP and Sr. Penetration Tester at SecurIT360, thinks the biggest change with AI is that defenders can't get away with as much anymore. AI lowers the bar for attacks on AD, but the vulnerabilities they exploit aren't new. The good news is, they're also completely fixable.

Sign up below to attend and receive a recording.

## Authentication Insights newsletter

### Active Directory visibility as a security control

How do you know if your Active Directory hardening is working? The hardening work you've done gives you data. But what you can do with that data depends on how much visibility you have (and whether you're actually reading it).

## The Authentication Insights archive

#### Raising the cost of attacks: Hardening AD

Attackers don't need to break your defenses. They just need to find the path of least resistance. The goal for defenders isn't an impenetrable AD. It's making every step forward expensive enough for attackers that it isn't worth taking.

#### Attack paths: How today’s attackers move through AD

When AD is the target, credential theft is only the beginning of the attack. What attackers do next, and how they get from initial access to full domain control, is where most defenses fall short.

#### Why credential theft still works in Active Directory

Weak passwords aren't the only reason credential theft still works in Active Directory environments. Her'es a look at what actually reduces the attack surface.

#### Why strong authentication policy breaks down in hybrid environments

Strong authentication policy means nothing if it’s not consistently enforced. But there's often a gap between authentication policy and implementation. In hybrid Active Directory environments, that’s where things tend to break down.

#### Where should identity live, and who gets to decide?

It's important to understand why security teams are asking this question in the first place. Often, the reason they're asking it says a lot about their priorities: control, sovereignty, and the tradeoffs they're willing (or not) to make.

#### What's stopping MFA?

Simplifying identity security in hybrid Active Directory environments isn't easy. And while many organizations say they're "using MFA," most aren't using it everywhere. Here are three reasons why MFA adoption lags, and how to close the gap.
