Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI agents can inherit local admin rights

An AI agent runs as a process under whatever account launched it, and it inherits that account's access token. If the account has local admin rights, so does the agent, along with every helper process and script it spawns, an example would be Claude Desktop running under an admin account, spawning PowerShell helpers. What makes agents different from a typical privileged app is that their next action often comes from content parsed at runtime, including untrusted input.

Ultimate Guide to Group Policy Management in Active Directory

Group policy management determines whether a domain enforces consistent security settings or drifts into configuration chaos one unaudited change at a time. Creating, linking, filtering, enforcing, delegating and backing up policy objects are the daily mechanics, while inheritance and precedence decide which setting wins when two conflict. Permissions on those objects turn misconfiguration into an attack path.

Top Free Active Directory Management Tools

Free Active Directory management tools handle lockouts, stale accounts, permissions reporting and bulk changes without a purchase order, and most teams already run several without having picked them deliberately. Each one stops somewhere specific. Knowing where the free editions end, and which gaps close only with a licensed product, decides how the next audit goes.

The Largest and Most Notorious Cyber Attacks in History

The most damaging cyber attacks in history rarely involved exotic techniques. A graduate student's experimental worm, a password with no second factor, and an unpatched file transfer tool each caused more damage than any advanced exploit on record. Reading four decades of these incidents in order shows how consistently intruders take the simplest available route, and how little that route has changed since 1988.

The Active Directory Tiered Administration Model Explained

The Active Directory tiered administration model blocks a common path from credential exposure on a compromised workstation to Domain Admin. It separates privileged accounts and systems by scope of control, then enforces logon boundaries so a privileged credential can authenticate only from an approved system. Dedicated accounts and hardened administrative workstations carry most of the weight. A domain admin signs in to a user's laptop to fix a printer problem.

AI Governance Framework: How to Build One That Works

An AI governance framework proves itself the first time somebody asks for proof. The gap that sinks most programs sits under the policy, in the layer where nobody can say which identities reach sensitive data through an AI tool. Ownership, approval paths, control mapping, and live access visibility are what separate a working framework from a well-formatted document, and right now most organizations are missing at least one of the four. AI reaches most organizations through several doors at once.

Microsoft Entra ID monitoring: Detecting suspicious activity

Entra ID monitoring correlates sign-in, audit, and privileged-role activity to expose suspicious identity changes while evidence still exists. Native controls leave gaps in retention, licensing, and correlation, so resilient teams export data, baseline admin behavior, and connect to Entra ID, Privileged Identity Management (PIM), OAuth, Conditional Access, and on-premises Active Directory events in a single workflow.

AI Governance Auditing for Security and IT Teams

AI governance auditing distinguishes between a documented policy and a working control. The audit traces one AI output back through the identity that invoked it, the data it reached, the guardrail that applied, and the record retained afterward. Most programs fail because access is ineffective: nobody can say which identities access sensitive data through an AI assistant, let alone prove the limit is held.

To self-host or not to self-host your password manager

For an individual, self-hosting a password manager is rarely realistic. Most people don't run servers, handle patching, or manage uptime, so a cloud vault ends up being the only practical choice. For an organization, self-hosting becomes a real decision, one your security and IT teams can make deliberately. And once you can choose, you also take on the risks and the responsibility that come with that choice.

Threat Lab Quarterly: August 2026

Netwrix formed a dedicated in-house Security Research team on July 15, 2025, led by Huy Kha, Director of Security Research. The team includes Senior Staff Security Researcher Darryl Baker, a recognized authority on Active Directory and identity security. They research identity, data security, AI, and cloud threats, with the goal of translating security research into practical improvements across Netwrix's product portfolio.