Skip to content
Backup and Recovery, Data Security

The Resilience Rundown Podcast: Navigating Active Directory Threats and Protections

Commvault Field CTO Dan Conrad shares his insights.


El director técnico de campo y tecnólogo principal de Commvault, Dan Conrad, participó en el episodio 12 del podcast The Resilience Rundown para charlar con el presentador Thomas Bryant sobre Active Directory. Dan cuenta con más de dos décadas de experiencia en Active Directory.

Amenazas comunes para la EA

Thomas mentioned that many people in the industry tend to overlook authentication and Active Directory when they’re planning for cyber incidents. Dan agreed that the most common threats haven’t changed over his career and tend to boil down to people, processes, and mentalities.

Compartió que la forma en que se administraba Active Directory anteriormente era defectuosa y que los administradores creaban situaciones peligrosas o explotables al moverse por toda la red y hacer todo con credenciales de administrador.

Según Dan, el sistema de inicio de sesión único de Active Directory facilita mucho su uso tanto a los usuarios como a los administradores, pero dejamos huellas allá donde vamos. Y esas huellas pueden ser aprovechadas por los atacantes. Mencionó numerosos ejemplos de filtraciones provocadas por un solo usuario cuyas credenciales habían sido comprometidas.

Mayor seguridad

A lo largo de los años, los administradores, incluido Dan, han realizado avances en las prácticas de seguridad, como gestionar su cuenta habitual por separado de su cuenta de administrador y utilizar soluciones de gestión de acceso privilegiado.

“That’s much more efficient from a security perspective because every time I’m done using it, I check it back in and it changes the password, which nullifies all those hashes I just left across the network so that they can’t be exploited,” he said.

He also mentions the need to be careful about giving out credentials just because someone asks – and keep an eye on third-party domain trust relationships that can put systems at risk.

Buenas prácticas

Thomas preguntó por otras buenas prácticas para proteger Active Directory frente a amenazas, más allá de la separación de funciones y el PAM. Dan mencionó la aplicación de parches, teniendo en cuenta el impacto que esto puede tener en las aplicaciones heredadas. También señaló que lo más importante es saber todo lo que sea posible sobre Active Directory.

“That’s sort of my mentality, that safety net, that you think you know how to detect, you think you know how to patch, you think you know how to do all this stuff,” Dan said. “But if you can’t recover, none of that really matters because there’s going to be something you didn’t know about.”

Función de la copia de seguridad y la recuperación

Thomas’ question on the role of backup and recovery in terms of protecting Active Directory prompted Dan to recall some sticky situations from the past. However, he also mentioned that “the other side of that is having the ability to recover at a granular level, is sort of a very relaxing feeling.”

Escucha el podcast completoaquípara escuchar el resto de la conversación.

More related posts


Thumbnail_Blog-Tabletop-Exercise-2026

SaaS Matters – Enterprise Support Made Possible by Clumio

Read more about SaaS Matters – Enterprise Support Made Possible by Clumio
Thumbnail_Blog-QTFY-Advisory-2026

The QTFY Advisory Is More Than a Threat Warning. It Is a Readiness Test.

Read more about The QTFY Advisory Is More Than a Threat Warning. It Is a Readiness Test.
Thumbnail_Blog-Clumio-S3-Backup-2026

Configuring S3 Backup and Recovery with Clumio

Read more about Configuring S3 Backup and Recovery with Clumio