Welcome to the first in our three-part blog post series on Microsoft Active Directory data backup and recovery. This series will explore the criticality of AD in your resilience strategy and considerations for protection. Let’s begin with an introduction of why AD is so important.
Ransomware has become a perpetual game of cat and mouse. As IT and security teams strive to stay one step ahead, threat actors ruthlessly mine for new methods, means, and vectors for their exploits. Their latest focus is AD. As a core element of centralized management, AD has become a primary target and pathway to execute ransomware attacks. Now more than ever, it’s critical that today’s businesses consider AD protection in their overarching security and ransomware response strategies.
Die Schlüssel zum Schloss
Als weit verbreitete Authentifizierungslösung für kleine, mittlere und große Unternehmen fungieren Microsoft AD und Entra ID als Torwächter der Autorisierungsprozesse für Netzwerke, Anwendungen und Umgebungen. AD ist die zentrale Schaltstelle für den Systemzugriff und verwaltet einen sich ständig verändernden Bestand an Benutzern, Gruppen, Richtlinien und Anwendungsberechtigungen.
While AD simplifies the administration of access to key systems, it can be particularly challenging to secure as it holds the keys to an organization’s most crown jewels – its infrastructure and data. It also has become a data protection blind spot for many organizations. One misconfiguration, leaked password, or dormant account can enable a bad actor to elevate privileges and steal, corrupt, or deny access to critical applications and their data.
Zahlreiche Arbeitsabläufe in Unternehmen sind auf AD angewiesen, um Mitarbeitern Zugriff auf kritische Geschäftssysteme zu gewähren, die für die Erzielung von Einnahmen, die Patientenversorgung, die Aufrechterhaltung des Produktionsbetriebs und die Unterstützung gemeinnütziger Initiativen unerlässlich sind. Ohne AD käme der Geschäftsbetrieb zum Erliegen.
Einen Angriff ausweiten
Experts are finding AD is playing a key and increasingly larger role in executing attacks. In fact, eine Studie von EMA Research showed that 50% of organizations experienced an attack on AD/Entra ID in the last one to two years. By exploiting blind spots, bad actors can compromise privileged accounts, mimic authorized users, and silently traverse infrastructure, workstations, and applications to establish their foothold. Failing to safeguard AD enables attackers with a centralized location to control and sever access to critical business assets.
Wie Commvault Hilft
Um Active Directory vor Ransomware zu schützen, sind speziell entwickelte Tools erforderlich, mit denen sich die Folgen von Angriffen beheben lassen. Zwar haben einige Unternehmen eigene Lösungen entwickelt, doch deren Wartung, Pflege und Verwaltung ist zeitaufwendig. Mit Commvault Cloud erhalten Sie einen dedizierten Schutz aus einer Hand für Microsoft Active Directory und Entra ID, der Ihnen hilft, Ihre Daten schnell wiederherzustellen.
Frequent backups enable users to undo damaging and unwanted changes to objects and attributes, including users, groups, app registrations, and more. Fast, granular recovery options allow administrators to view what’s changed in their environment and easily recover missing, damaged, or misconfigured items to thwart ongoing attacks.
Visit Commvault.com/platform/active-directory, to learn more about how Commvault helps safeguard AD against corruption, accidental deletion, or malicious attacks.