<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Legacy Things]]></title><description><![CDATA[Le radici nascoste dell’IT moderno]]></description><link>https://www.legacythings.it</link><image><url>https://substackcdn.com/image/fetch/$s_!kkFJ!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf5f5b73-cbd0-43af-957a-01e6c2c39191_1024x1024.png</url><title>Legacy Things</title><link>https://www.legacythings.it</link></image><generator>Substack</generator><lastBuildDate>Wed, 29 Jul 2026 14:07:34 GMT</lastBuildDate><atom:link href="https://www.legacythings.it/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Marco Lelli]]></copyright><language><![CDATA[it]]></language><webMaster><![CDATA[legacythings@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[legacythings@substack.com]]></itunes:email><itunes:name><![CDATA[Marco Lelli]]></itunes:name></itunes:owner><itunes:author><![CDATA[Marco Lelli]]></itunes:author><googleplay:owner><![CDATA[legacythings@substack.com]]></googleplay:owner><googleplay:email><![CDATA[legacythings@substack.com]]></googleplay:email><googleplay:author><![CDATA[Marco Lelli]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Capitolo #5 - Illusione]]></title><description><![CDATA[La realt&#224; non cambia, cambia il punto di osservazione]]></description><link>https://www.legacythings.it/p/capitolo-5-illusione</link><guid isPermaLink="false">https://www.legacythings.it/p/capitolo-5-illusione</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Tue, 28 Jul 2026 07:30:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZKMh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cf7861d-e894-4f6c-80e8-f0c1ce9440e0_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>English version available here &#8594;<a href="https://www.legacythings.it/p/chapter-5-illusion"> [EN]</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZKMh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cf7861d-e894-4f6c-80e8-f0c1ce9440e0_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZKMh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cf7861d-e894-4f6c-80e8-f0c1ce9440e0_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ZKMh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cf7861d-e894-4f6c-80e8-f0c1ce9440e0_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ZKMh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cf7861d-e894-4f6c-80e8-f0c1ce9440e0_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ZKMh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cf7861d-e894-4f6c-80e8-f0c1ce9440e0_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZKMh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cf7861d-e894-4f6c-80e8-f0c1ce9440e0_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1cf7861d-e894-4f6c-80e8-f0c1ce9440e0_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2891642,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/207933762?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cf7861d-e894-4f6c-80e8-f0c1ce9440e0_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZKMh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cf7861d-e894-4f6c-80e8-f0c1ce9440e0_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ZKMh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cf7861d-e894-4f6c-80e8-f0c1ce9440e0_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ZKMh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cf7861d-e894-4f6c-80e8-f0c1ce9440e0_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ZKMh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1cf7861d-e894-4f6c-80e8-f0c1ce9440e0_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Aprile 1983</strong>, un anno prima gli Imagination suonavano <em>&#8220;Just an illusion&#8221;</em>, e senza saperlo stavano dando un titolo perfetto a ci&#242; che sarebbe diventato una pietra miliare dell&#8217;intrattenimento.</p><p>Io non mi ricordo cosa stessi facendo. Avevo sei anni e di sicuro non avevo ancora una tastiera tra le mani. Per&#242; quella sensazione me la ricordo bene, perch&#233; quando il cervello capisce di essere stato ingannato, poi se lo segna da parte.</p><p><span>Siamo a New York City, a Liberty Island. </span>Lo show &#232; pronto, le luci sono puntate, e migliaia di persone stanno per vedere una cosa impossibile. Il famosissimo <strong>David Copperfield</strong> ha in programma un numero molto ambizioso: <em><strong>fare sparire in diretta la Statua della Libert&#224;</strong></em>.</p><p>Lo show inizia, un crescendo di tensione, cala un grande sipario e la &#8220;magia&#8221; si compie. Passano pochi minuti, il sipario scivola a terra e&#8230; la statua non c&#8217;&#232; pi&#249;!</p><p><strong>L&#8217;illusione &#232; avvenuta.</strong> O almeno lo &#232; per il pubblico. Chi conosce i retroscena sa che la statua &#232; ferma, &#232; il pubblico ad essersi spostato.</p><div><hr></div><p style="text-align: center;"><em>La realt&#224; non cambia, cambia il punto da cui la osservi.</em></p><div><hr></div><p>Puntando i riflettori sul mondo IT, il 1983 &#232; stato pieno di fermento. Il 1&#176; gennaio <strong>Arpanet</strong>, che poi diventer&#224; Internet, adotta il protocollo <strong>TCP/IP</strong>. In casa Microsoft viene rilasciato il <strong>MS-DOS 2.0</strong> e a fine anno viene annunciato <strong>Windows</strong>, molto prima che il mondo lo veda davvero.</p><p>Tanti piccoli semi che avrebbero messo radici profonde nell&#8217;IT moderno. E che in quel momento davano l&#8217;<strong>illusione</strong> di avere il futuro gi&#224; tra le mani.</p><p>Quarant&#8217;anni dopo, le illusioni sono ancora presenti, solo pi&#249; sofisticate. Il caso di oggi non si manifesta come un errore chiaro, ma come un comportamento &#8220;strano&#8221; che sembra capovolgere la logica&#8230; finch&#233; non decidiamo di cambiare prospettiva.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.legacythings.it/subscribe?"><span>Iscriviti ora</span></a></p><h2>Il caso &#8220;strano&#8221;</h2><p><strong>2026.</strong> Un cliente, un member server, un&#8217;esigenza apparentemente ordinaria.</p><p>Su quella macchina deve essere installato un modulo software che, per fare il suo lavoro, richiede due cose:</p><blockquote><p><span>&#183; </span>essere amministratore locale</p><p><span>&#183; </span>poter eseguire alcune operazioni su Active Directory tramite Remote Server Administration Tools (RSAT)</p></blockquote><p>&#200; una richiesta che, chi lavora in ambito IT, ha visto decine di volte. Nulla che richieda particolare attenzione, se non la definizione della delega precisa su Active Directory.</p><p>Si procede rispettando il &#8220;Principle of Least Privilege&#8221; (POLP):</p><blockquote><p><span>&#183; </span>si crea un <strong>gMSA</strong></p><p><span>&#183; </span>lo si configura per eseguire il servizio</p><p><span>&#183; </span>per le operazioni &#8220;locali&#8221; lo si aggiunge agli <strong>Administrators</strong> del member server</p></blockquote><p>Non un Domain Admin, non un account personale, niente soluzioni affrettate. &#200; la classica identit&#224; di servizio, a cui si stanno costruendo le deleghe necessarie al proprio funzionamento.</p><p>Poi si arriva alla parte operativa pi&#249; delicata: i permessi minimi su Active Directory.</p><p>Sul server vengono installati gli RSAT, si apre la console Active Directory Users and Computers (<strong>ADUC)</strong> direttamente da l&#236;, e il consulente inizia a configurare le deleghe necessarie.</p><p>Fin qui tutto lineare: il gMSA &#232; un normale domain user, &#232; local admin solo su quel server, e l&#8217;obiettivo &#232; assegnargli qualche permesso mirato su specifiche OU.</p><p>In ambito POLP ogni delega va per&#242; certificata sul campo.</p><p>Si passa quindi a verificare quali permessi effettivi riceva quell&#8217;account sull&#8217;alberatura di Active Directory, &#232; a quel punto che succede qualcosa che non dovrebbe succedere: il gMSA sembra avere diritti ben oltre la delega appena impostata.</p><p><span>Si apre una Organizational Unit &gt; Properties &gt; Security &gt; Advanced &gt; Effective Access.</span></p><p>Si osservano i permessi ricevuti dal gMSA, ed &#232; tutto veramente strano: l&#8217;interfaccia dice che l&#8217;account ha permessi &#8220;quasi totali&#8221; su tutta l&#8217;alberatura!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dk8Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f6dc1f-b0c3-4fd5-bc70-5a9ddff86caf_767x520.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dk8Q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f6dc1f-b0c3-4fd5-bc70-5a9ddff86caf_767x520.png 424w, https://substackcdn.com/image/fetch/$s_!dk8Q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f6dc1f-b0c3-4fd5-bc70-5a9ddff86caf_767x520.png 848w, https://substackcdn.com/image/fetch/$s_!dk8Q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f6dc1f-b0c3-4fd5-bc70-5a9ddff86caf_767x520.png 1272w, https://substackcdn.com/image/fetch/$s_!dk8Q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f6dc1f-b0c3-4fd5-bc70-5a9ddff86caf_767x520.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dk8Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f6dc1f-b0c3-4fd5-bc70-5a9ddff86caf_767x520.png" width="767" height="520" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e1f6dc1f-b0c3-4fd5-bc70-5a9ddff86caf_767x520.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:520,&quot;width&quot;:767,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23108,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/207933762?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f6dc1f-b0c3-4fd5-bc70-5a9ddff86caf_767x520.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dk8Q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f6dc1f-b0c3-4fd5-bc70-5a9ddff86caf_767x520.png 424w, https://substackcdn.com/image/fetch/$s_!dk8Q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f6dc1f-b0c3-4fd5-bc70-5a9ddff86caf_767x520.png 848w, https://substackcdn.com/image/fetch/$s_!dk8Q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f6dc1f-b0c3-4fd5-bc70-5a9ddff86caf_767x520.png 1272w, https://substackcdn.com/image/fetch/$s_!dk8Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f6dc1f-b0c3-4fd5-bc70-5a9ddff86caf_767x520.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Si ri-verifica l&#8217;account: &#232; membro solamente dei Domain Users.</p><p>Al consulente viene una intuizione: e se proviamo di togliere l&#8217;account dagli amministratori locali del member server?</p><p>Detto, fatto, si procede ad una nuova verifica, ed &#232; l&#236; che la cosa si fa ancora pi&#249; strana: adesso i permessi sull&#8217;alberatura di Active Directory sono corretti.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0lGX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a5b62bd-8cfb-466b-a38f-1929488f2d17_767x520.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0lGX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a5b62bd-8cfb-466b-a38f-1929488f2d17_767x520.png 424w, https://substackcdn.com/image/fetch/$s_!0lGX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a5b62bd-8cfb-466b-a38f-1929488f2d17_767x520.png 848w, https://substackcdn.com/image/fetch/$s_!0lGX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a5b62bd-8cfb-466b-a38f-1929488f2d17_767x520.png 1272w, https://substackcdn.com/image/fetch/$s_!0lGX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a5b62bd-8cfb-466b-a38f-1929488f2d17_767x520.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0lGX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a5b62bd-8cfb-466b-a38f-1929488f2d17_767x520.png" width="767" height="520" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0a5b62bd-8cfb-466b-a38f-1929488f2d17_767x520.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:520,&quot;width&quot;:767,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23712,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/207933762?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a5b62bd-8cfb-466b-a38f-1929488f2d17_767x520.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0lGX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a5b62bd-8cfb-466b-a38f-1929488f2d17_767x520.png 424w, https://substackcdn.com/image/fetch/$s_!0lGX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a5b62bd-8cfb-466b-a38f-1929488f2d17_767x520.png 848w, https://substackcdn.com/image/fetch/$s_!0lGX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a5b62bd-8cfb-466b-a38f-1929488f2d17_767x520.png 1272w, https://substackcdn.com/image/fetch/$s_!0lGX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a5b62bd-8cfb-466b-a38f-1929488f2d17_767x520.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>&#200; a quel punto che la questione arriva sul mio tavolo, il consulente &#232; piuttosto confuso: com&#8217;&#232; possibile che una membership locale influenzi i permessi di dominio? &#200; il mondo al contrario!</p><p>Ragiono sulle informazioni che ho ricevuto e nella mente inizia a prendere forma un&#8217;idea che affonda le radici in quel lontano 1983:</p><div><hr></div><p style="text-align: center;"><em>il comportamento non &#232; reale, siamo di fronte ad una <strong>illusione</strong>!</em></p><div><hr></div><h2>L&#8217;illusione svelata</h2><p>La logica comune dice che una membership locale non pu&#242; avere effetti su una directory che vive altrove. Eppure, i controlli sembrano confermarlo.</p><p>Il sistema sta dicendo che quell&#8217;identit&#224;, da quel punto di osservazione, non &#232; pi&#249; un semplice servizio con privilegi minimi. Tutto il contrario.</p><p>Ed &#232; proprio qui che l&#8217;illusione diventa interessante, perch&#233; se la realt&#224; non &#232; cambiata, allora &#232; cambiato qualcos&#8217;altro.</p><p>E come con la Statua della Libert&#224;, la domanda giusta non &#232; &#8220;cosa &#232; successo&#8221;, ma:</p><div><hr></div><p style="text-align: center;"><em>&#8220;da dove stiamo guardando&#8221;?</em></p><div><hr></div><p>L&#8217;idea nella mia testa si fa sempre pi&#249; presente e chiedo al consulente: rimetti le cose come prima, facciamo in modo che il problema sia presente, poi cambiamo punto di osservazione.</p><p>Rimesso l&#8217;utente negli amministratori locali del member server, verifichiamo che l&#8217;&#8220;effective access&#8221; mostri permessi totali.</p><p><span>A quel punto chiedo: apriamo l&#8217;ADUC da un Domain Controller e facciamo la stessa verifica da l&#236;?</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vc1k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe508cb89-e5d7-4e77-adee-08e4511c8230_767x520.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vc1k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe508cb89-e5d7-4e77-adee-08e4511c8230_767x520.png 424w, https://substackcdn.com/image/fetch/$s_!vc1k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe508cb89-e5d7-4e77-adee-08e4511c8230_767x520.png 848w, https://substackcdn.com/image/fetch/$s_!vc1k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe508cb89-e5d7-4e77-adee-08e4511c8230_767x520.png 1272w, https://substackcdn.com/image/fetch/$s_!vc1k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe508cb89-e5d7-4e77-adee-08e4511c8230_767x520.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vc1k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe508cb89-e5d7-4e77-adee-08e4511c8230_767x520.png" width="767" height="520" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e508cb89-e5d7-4e77-adee-08e4511c8230_767x520.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:520,&quot;width&quot;:767,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23712,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/207933762?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe508cb89-e5d7-4e77-adee-08e4511c8230_767x520.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vc1k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe508cb89-e5d7-4e77-adee-08e4511c8230_767x520.png 424w, https://substackcdn.com/image/fetch/$s_!vc1k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe508cb89-e5d7-4e77-adee-08e4511c8230_767x520.png 848w, https://substackcdn.com/image/fetch/$s_!vc1k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe508cb89-e5d7-4e77-adee-08e4511c8230_767x520.png 1272w, https://substackcdn.com/image/fetch/$s_!vc1k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe508cb89-e5d7-4e77-adee-08e4511c8230_767x520.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Come evidente dall&#8217;immagine, l&#8217;effective access &#232; assolutamente coerente con la delega, non vi &#232; pi&#249; traccia dei permessi quasi-totali.</p><p>Cambiando prospettiva &#232; cambiato il risultato, questo conferma l&#8217;illusione.</p><p>Ma cos&#8217;&#232; allora che sta creando questa illusione?</p><p>Guardo il consulente con un sorrisetto accennato gli dico: ho capito cosa &#232; successo, la prova che abbiamo fatto ne &#232; la conferma, &#232; una questione di Security Identifier (SID).</p><p>Chiedo di fare queste due operazioni:</p><blockquote><p><span>&#183; </span>dal member server mostrare il SID del gruppo locale Administrators</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7lTU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc99953b3-a66f-4198-b29e-a10296900f23_594x154.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7lTU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc99953b3-a66f-4198-b29e-a10296900f23_594x154.png 424w, https://substackcdn.com/image/fetch/$s_!7lTU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc99953b3-a66f-4198-b29e-a10296900f23_594x154.png 848w, https://substackcdn.com/image/fetch/$s_!7lTU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc99953b3-a66f-4198-b29e-a10296900f23_594x154.png 1272w, https://substackcdn.com/image/fetch/$s_!7lTU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc99953b3-a66f-4198-b29e-a10296900f23_594x154.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7lTU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc99953b3-a66f-4198-b29e-a10296900f23_594x154.png" width="594" height="154" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c99953b3-a66f-4198-b29e-a10296900f23_594x154.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:154,&quot;width&quot;:594,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:7086,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/207933762?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc99953b3-a66f-4198-b29e-a10296900f23_594x154.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7lTU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc99953b3-a66f-4198-b29e-a10296900f23_594x154.png 424w, https://substackcdn.com/image/fetch/$s_!7lTU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc99953b3-a66f-4198-b29e-a10296900f23_594x154.png 848w, https://substackcdn.com/image/fetch/$s_!7lTU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc99953b3-a66f-4198-b29e-a10296900f23_594x154.png 1272w, https://substackcdn.com/image/fetch/$s_!7lTU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc99953b3-a66f-4198-b29e-a10296900f23_594x154.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><blockquote><p><span>&#183; </span>dal Domain Controller mostrare il SID del gruppo locale di dominio Administrators</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SI9n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90f5c685-cebe-4907-b467-2aa12395255d_696x114.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SI9n!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90f5c685-cebe-4907-b467-2aa12395255d_696x114.png 424w, https://substackcdn.com/image/fetch/$s_!SI9n!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90f5c685-cebe-4907-b467-2aa12395255d_696x114.png 848w, https://substackcdn.com/image/fetch/$s_!SI9n!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90f5c685-cebe-4907-b467-2aa12395255d_696x114.png 1272w, https://substackcdn.com/image/fetch/$s_!SI9n!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90f5c685-cebe-4907-b467-2aa12395255d_696x114.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SI9n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90f5c685-cebe-4907-b467-2aa12395255d_696x114.png" width="696" height="114" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/90f5c685-cebe-4907-b467-2aa12395255d_696x114.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:114,&quot;width&quot;:696,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5829,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/207933762?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90f5c685-cebe-4907-b467-2aa12395255d_696x114.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SI9n!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90f5c685-cebe-4907-b467-2aa12395255d_696x114.png 424w, https://substackcdn.com/image/fetch/$s_!SI9n!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90f5c685-cebe-4907-b467-2aa12395255d_696x114.png 848w, https://substackcdn.com/image/fetch/$s_!SI9n!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90f5c685-cebe-4907-b467-2aa12395255d_696x114.png 1272w, https://substackcdn.com/image/fetch/$s_!SI9n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F90f5c685-cebe-4907-b467-2aa12395255d_696x114.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Ecco spiegata l&#8217;illusione: il SID nei due casi &#232; esattamente lo stesso!</p><p>Ecco il Legacy Things che viene a galla, siamo ancora una volta davanti ad uno di quei subdoli meccanismi di default che sono l&#236; da decenni e di cui si &#232; persa la memoria: <strong>i well-known SID.</strong></p><h2>Cosa sono e perch&#233; sono ancora l&#236;</h2><p>Il concetto di <strong>Security Identifier (SID)</strong> lo abbiamo gi&#224; affrontato nel <strong><a href="https://www.legacythings.it/p/capitolo-2-una-questione-di-fiducia?r=7oz2wp">capitolo 2</a></strong>, quindi non ci torno sopra. Quello che serve qui &#232; una loro categoria molto particolare: i <strong>well-known SID</strong>.</p><p>La stragrande maggioranza dei SID nasce &#8220;unica&#8221;: viene generata nel momento esatto in cui l&#8217;oggetto viene creato, dalla <strong>Local Security Authority (LSA)</strong> per gli oggetti locali di una macchina o dal Domain Controller per quelli di dominio, e non viene mai pi&#249; riutilizzata per identificare nessun altro. I well-known SID fanno l&#8217;esatto contrario: hanno un valore fisso, identico su qualunque sistema. Non vengono generati: esistono e basta.</p><p>C&#8217;&#232; anche una data precisa a cui far risalire il loro debutto pratico. I SID non nascono con Active Directory, e nemmeno con qualche versione intermedia di Windows: arrivano gi&#224; con <strong><a href="https://en.wikipedia.org/wiki/Windows_NT_3.1">Windows NT 3.1</a></strong>, la primissima release della famiglia NT, distribuita il <strong>27 luglio 1993</strong>.</p><p>Erano parte integrante del nuovo modello di sicurezza progettato dal team di Dave Cutler, quello fondato su access token e liste di controllo degli accessi (ACL). In altre parole, quando parliamo di well-known SID non stiamo guardando un dettaglio recente, ma un pezzo di architettura che ci accompagna, sostanzialmente immutato, da oltre trent&#8217;anni.</p><p>Ma da dove arriva la regola che impone quei valori fissi? Chi lo ha deciso, e dove sta scritto? Non &#232; una convenzione informale, n&#233; una scelta lasciata alla singola implementazione: &#232; messa nero su bianco in una <strong>specifica ufficiale</strong>. I well-known SID sono elencati, uno per uno, nel documento <strong><a href="https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-dtyp/81d92bba-d22b-4a8c-908a-554ab29148ab">[MS-DTYP] Windows Data Types</a></strong>, nella sezione dedicata alle <em>Well-Known SID Structures</em>, dove si legge esplicitamente che i loro valori &#8220;restano costanti su tutti i sistemi operativi&#8221;.</p><p>&#200; una delle <strong>Open Specifications</strong> di Microsoft, cio&#232; la documentazione di protocollo pensata perch&#233; chiunque possa implementare lo stesso modello in modo interoperabile. In altre parole, non &#232; che &#8220;Windows fa cos&#236;&#8221;: &#232; che chiunque voglia parlare la stessa lingua &#232; tenuto a usare esattamente quei numeri.</p><p>E qui si arriva a un punto che spesso sorprende: il SID non &#232; un&#8217;esclusiva del mondo Windows. La <a href="https://learn.microsoft.com/en-us/windows/win32/secauthz/well-known-sids">documentazione stessa</a> distingue due famiglie. Da un lato ci sono i well-known SID <strong>universali</strong>, che hanno senso &#8220;su tutti i sistemi sicuri che adottano questo modello di sicurezza, inclusi sistemi operativi diversi da Windows&#8221;, come <strong>Everyone</strong> / <strong>World</strong> (<em>S-1-1-0</em>) o <strong>Creator Owner</strong> (<em>S-1-3-0</em>), quest&#8217;ultimo usato come segnaposto nelle ACE ereditabili. Dall&#8217;altro ci sono quelli <strong>specifici di Windows</strong>, tra cui i gruppi <strong>BUILTIN</strong>.</p><p>Che non sia solo teoria lo conferma il campo: implementazioni come <strong>Samba</strong>, che oggi sanno fare da Domain Controller Active Directory su Linux, <a href="https://ubuntu.com/server/docs/explanation/active-directory/security-identifiers-sids/">ragionano esattamente con gli stessi SID</a>. Per loro il gruppo <strong>Administrators</strong> locale &#232; <em>S-1-5-32-544</em> identico, e componenti come <strong>winbind</strong> esistono proprio per mappare quei SID sugli UID/GID del mondo Unix.</p><p>Il modello di sicurezza, insomma, ha valicato da tempo i confini di Windows.</p><p>Torniamo al nostro caso. Il gruppo <strong>Administrators</strong> del &#8220;built-in domain&#8221; ha un well-known SID ben preciso: <strong>S-1-5-32-544</strong>. Vale la pena <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-identifiers">interpretarlo</a> pezzo per pezzo: il <strong>5</strong> &#232; l&#8217;autorit&#224; <em>NT</em>, il <strong>32</strong> identifica proprio il dominio <strong>built-in</strong>, e il <strong>544</strong> &#232; il RID del gruppo Administrators.</p><p>Sempre quello: sul member server, sul Domain Controller, sul portatile del consulente. Identico, e non per caso.</p><p>Il dettaglio che genera l&#8217;illusione &#232; tutto in quel valore condiviso. Su un member server <em>S-1-5-32-544</em> &#232; il gruppo degli amministratori <strong>locali</strong> di quella macchina, e nulla pi&#249;. Su un <strong>Domain Controller</strong>, per&#242;, il &#8220;built-in domain&#8221; coincide con il dominio stesso: lo stesso identico SID rappresenta l&#236; gli amministratori del <strong>dominio</strong>, con tutta l&#8217;autorit&#224; che ne consegue sulla directory.</p><p>Quando l&#8217;Effective Access viene calcolato <strong>dal member server</strong>, lo strumento vede che il gMSA appartiene a <em>S-1-5-32-544</em> e lo confronta con le ACL di Active Directory, dove quello stesso SID gode di permessi pieni. Il tool non sa, e non pu&#242; saperlo, che &#8220;quel 544, visto da qui, vale solo in locale&#8221;. Mette insieme due contesti diversi che condividono la stessa etichetta e restituisce una fotografia gonfiata. Basta spostare il punto di osservazione su un DC perch&#233; l&#8217;ambiguit&#224; sparisca: da l&#236; il contesto &#232; uno solo, e i conti tornano.</p><p>E allora perch&#233;, dopo decenni, sono ancora l&#236;? Per lo stesso motivo per cui non si cambia lingua a met&#224; di una conversazione. I well-known SID sono uno dei mattoni fondamentali del modello di autorizzazione: ACE ereditate, token di accesso, deleghe, permessi di default, tutto ci si appoggia. Cambiarli significherebbe rompere la compatibilit&#224; con qualunque cosa sia stata scritta negli ultimi trent&#8217;anni, e non solo lato Windows. Sono stabili <strong>by design</strong>: &#232; la stessa specifica a vincolarli a restare costanti nel tempo e tra sistemi diversi.</p><p>Non sono quindi un errore, n&#233; una svista rimasta in giro per pigrizia. Sono esattamente ci&#242; che dovevano essere. Il problema non &#232; il SID: &#232; che noi, davanti a un&#8217;interfaccia, tendiamo a leggere un&#8217;etichetta dimenticando da dove la stiamo guardando. E il punto di osservazione, come al solito, &#232; tutto.</p><h2>Cosa ci ha insegnato</h2><p>La prima lezione che questo caso ci lascia &#232; semplice solo in apparenza: lo strumento non stava mentendo. L&#8217;Effective Access ha fatto esattamente il suo mestiere, ha calcolato l&#8217;accesso a partire da ci&#242; che vedeva da quel punto, e ha risposto in modo formalmente corretto. Il problema &#232; che noi cercavamo un&#8217;altra verit&#224;, quella dei permessi reali sulla directory, e lui non aveva mai promesso di dircela. Torno allora a quel motto che ho gi&#224; usato in queste pagine, perch&#233; non c&#8217;&#232; sintesi migliore: <strong>i sistemi informatici non fanno quello che vuoi, fanno quello che gli dici di fare</strong>. A quel tool avevamo di fatto chiesto &#8220;dimmi cosa vedi da qui&#8221;, e lui, con coerenza implacabile, ci ha risposto proprio questo. L&#8217;illusione non era nel software, ma nell&#8217;aver scambiato la sua risposta per la domanda che avevamo in testa.</p><p>La seconda lezione riguarda il modo in cui reagiamo davanti a un comportamento &#8220;impossibile&#8221;. L&#8217;istinto, quasi sempre, &#232; cercare subito un colpevole: un bug, una configurazione sbagliata, una compromissione, qualcosa che si &#232; &#8220;rotto&#8221;. Ma in questo caso non si era rotto niente, e nessuna caccia al colpevole avrebbe portato da qualche parte. La svolta &#232; arrivata solo quando abbiamo smesso di chiederci &#8220;cosa &#232; successo&#8221; e abbiamo iniziato a chiederci &#8220;da dove stiamo guardando&#8221;. Spostare il punto di osservazione, dal member server al Domain Controller, ha fatto svanire l&#8217;anomalia esattamente come la Statua della Libert&#224; tornava al suo posto appena il pubblico si accorgeva di essersi mosso. Il consulente, davanti a quei permessi impossibili, aveva esclamato &#8220;&#232; il mondo al contrario!&#8221;. Ed &#232; proprio l&#236; la lezione:</p><div><hr></div><p style="text-align: center;"><em><span>Quando il mondo ti sembra assurdamente sottosopra, quasi sempre non &#232; il mondo a essersi capovolto: &#232; il tuo punto di osservazione a essere sbagliato.</span></em></p><div><hr></div><p>Prima di credere che sia la realt&#224; a girare al contrario, conviene verificare da dove la stiamo guardando.</p><p>C&#8217;&#232; infine una terza lezione, ed &#232; quella che tiene insieme l&#8217;intera serie: il legacy non &#232; un difetto, &#232; memoria persa. Il well-known SID non era un errore lasciato l&#236; per pigrizia, era esattamente ci&#242; che doveva essere, stabile <strong>by design</strong> da oltre trent&#8217;anni. Ci&#242; che mancava non era la correttezza del sistema, ma la nostra conoscenza del modello, il sapere che quel <em>32</em> significa &#8220;built-in domain&#8221; e che quel <em>544</em> vale lo stesso identico numero su mondi diversi. &#200; lo stesso filo che attraversa tutti questi capitoli. Il guardiano di AdminSDHolder che riscriveva permessi che nessuno gli chiedeva pi&#249;, le trust nate per dare forma alla fiducia e diventate un vincolo invisibile, il Domain Controller che sembrava mentire mentre diceva la verit&#224;. Ogni volta il punto non era che il sistema fosse rotto. Il punto era che il sistema continuava a fare ci&#242; per cui era stato progettato, mentre noi avevamo perso parte della memoria di quel progetto.</p><p>Forse &#232; questa la vera illusione dei sistemi legacy: non ci ingannano nascondendosi, ci ingannano restando in piena vista, cos&#236; ovvi e silenziosi che smettiamo di guardarli davvero. Continuano a rispondere con precisione, ma noi abbiamo dimenticato la domanda a cui rispondevano. E allora, come davanti alla Statua della Libert&#224;, l&#8217;unico modo per riconoscere il trucco non &#232; fissare pi&#249; intensamente lo stesso punto, ma avere l&#8217;umilt&#224; di spostarci e chiederci da dove stiamo guardando.</p><p>Ed &#232; esattamente da qui che <em>Legacy Things</em> continua il suo cammino: riportare alla luce quei meccanismi silenziosi che, pur nati decenni fa, continuano a governare il comportamento delle infrastrutture moderne. Non per nostalgia, ma perch&#233; ignorarli non li rende innocui. Li rende solo pi&#249; bravi a farci vedere cose che non esistono.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Grazie per aver letto Legacy Things! Iscriviti gratuitamente per supportare il mio lavoro.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Chapter #5 - Illusion]]></title><description><![CDATA[Reality does not change, only the point of observation does]]></description><link>https://www.legacythings.it/p/chapter-5-illusion</link><guid isPermaLink="false">https://www.legacythings.it/p/chapter-5-illusion</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Tue, 28 Jul 2026 07:20:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!fTB1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84681ad3-d4c7-4b05-82f0-0432cc1920b3_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Versione italiana disponibile qui &#8594;</em><a href="https://www.legacythings.it/p/capitolo-1-adminsdholder-il-guardiano"> </a><em><a href="https://www.legacythings.it/p/capitolo-5-illusione">[IT]</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fTB1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84681ad3-d4c7-4b05-82f0-0432cc1920b3_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fTB1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84681ad3-d4c7-4b05-82f0-0432cc1920b3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!fTB1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84681ad3-d4c7-4b05-82f0-0432cc1920b3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!fTB1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84681ad3-d4c7-4b05-82f0-0432cc1920b3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!fTB1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84681ad3-d4c7-4b05-82f0-0432cc1920b3_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fTB1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84681ad3-d4c7-4b05-82f0-0432cc1920b3_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/84681ad3-d4c7-4b05-82f0-0432cc1920b3_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2891642,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/207931410?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84681ad3-d4c7-4b05-82f0-0432cc1920b3_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fTB1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84681ad3-d4c7-4b05-82f0-0432cc1920b3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!fTB1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84681ad3-d4c7-4b05-82f0-0432cc1920b3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!fTB1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84681ad3-d4c7-4b05-82f0-0432cc1920b3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!fTB1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84681ad3-d4c7-4b05-82f0-0432cc1920b3_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><span>April 1983</span></strong><span>. A year earlier, Imagination had been playing </span><em><span>&#8220;Just an Illusion&#8221;</span></em><span>, and without knowing it they were giving the perfect title to what would become a milestone in entertainment.</span></p><p><span>I do not remember what I was doing. I was six years old and certainly did not yet have a keyboard in my hands. But that feeling I remember well, because when the brain realizes it has been fooled, it makes a note of it for later.</span></p><p><span>We are in New York City, on Liberty Island. The show is ready, the lights are on, and thousands of people are about to witness something impossible. The world-famous </span><strong><span>David Copperfield</span></strong><span> has a very ambitious act in store: </span><em><strong><span>making the Statue of Liberty disappear live</span></strong></em><span>.</span></p><p><span>The show begins, tension builds, a large curtain drops and the &#8220;magic&#8221; happens. A few minutes pass, the curtain slides to the ground and&#8230; the statue is gone!</span></p><p><strong><span>The illusion has taken place.</span></strong><span> Or at least it has for the audience. Those who know what happens behind the scenes know that the statue has not moved, it is the audience that has been moved.</span></p><div><hr></div><p style="text-align: center;"><em><span>Reality does not change, what changes is the point from which you observe it.</span></em></p><div><hr></div><p><span>Turning the spotlight on the IT world, 1983 was a year full of ferment. On January 1st </span><strong><span>Arpanet</span></strong><span>, which would later become the Internet, adopts the </span><strong><span>TCP/IP</span></strong><span> protocol. At Microsoft, </span><strong><span>MS-DOS 2.0</span></strong><span> is released and, at the end of the year, </span><strong><span>Windows</span></strong><span> is announced, long before the world would actually see it.</span></p><p><span>So many small seeds that would put down deep roots in modern IT. And that, in that moment, gave the </span><strong><span>illusion</span></strong><span> of already holding the future in one&#8217;s hands.</span></p><p><span>Forty years later, illusions are still with us, only more sophisticated. Today&#8217;s case does not show up as a clear error, but as a &#8220;strange&#8221; behaviour that seems to turn logic upside down&#8230; until we decide to change perspective.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.legacythings.it/subscribe?"><span>Iscriviti ora</span></a></p><h2><span>The &#8220;strange&#8221; case</span></h2><p><strong><span>2026.</span></strong><span> A customer, a member server, an apparently ordinary need.</span></p><p><span>On that machine a software module needs to be installed which, in order to do its job, requires two things:</span></p><blockquote><p><span>&#183; </span>being a local administrator</p><p><span>&#183; being able to perform some operations on Active Directory through the Remote Server Administration Tools (RSAT)</span></p></blockquote><p><span>It is a request that anyone working in IT has seen dozens of times. Nothing that requires particular attention, apart from defining the precise delegation on Active Directory.</span></p><p><span>We proceed following the </span><strong><span>Principle of Least Privilege (POLP)</span></strong><span>:</span></p><blockquote><p><span>&#183; </span>a <strong>gMSA</strong> is created</p><p><span>&#183; it is configured to run the service</span></p><p><span>&#183; for the &#8220;local&#8221; operations it is added to the </span><strong><span>Administrators</span></strong><span> of the member server</span></p></blockquote><p><span>Not a Domain Admin, not a personal account, no rushed solutions. It is the classic service identity, for which we are building the delegations needed to make it work.</span></p><p><span>Then we get to the most delicate operational part: the minimum permissions on Active Directory.</span></p><p><span>The RSAT are installed on the server, the Active Directory Users and Computers (</span><strong><span>ADUC</span></strong><span>) console is opened directly from there, and the consultant starts configuring the necessary delegations.</span></p><p><span>So far everything is straightforward: the gMSA is a normal domain user, it is a local admin only on that server, and the goal is to assign it a few targeted permissions on specific OUs.</span></p><p><span>In a POLP context, however, every delegation must be certified in the field.</span></p><p><span>So we move on to checking which effective permissions that account receives on the Active Directory tree, and it is at that point that something happens that should not happen: the gMSA seems to have rights well beyond the delegation just set.</span></p><p><span>We open an Organizational Unit &gt; Properties &gt; Security &gt; Advanced &gt; Effective Access.</span></p><p><span>We look at the permissions received by the gMSA, and it is all really strange: the interface says the account has &#8220;almost-full&#8221; permissions over the entire tree!</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lIXP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff265f31a-a8ff-48a0-9777-906f1e714bd0_767x520.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lIXP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff265f31a-a8ff-48a0-9777-906f1e714bd0_767x520.png 424w, https://substackcdn.com/image/fetch/$s_!lIXP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff265f31a-a8ff-48a0-9777-906f1e714bd0_767x520.png 848w, https://substackcdn.com/image/fetch/$s_!lIXP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff265f31a-a8ff-48a0-9777-906f1e714bd0_767x520.png 1272w, https://substackcdn.com/image/fetch/$s_!lIXP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff265f31a-a8ff-48a0-9777-906f1e714bd0_767x520.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lIXP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff265f31a-a8ff-48a0-9777-906f1e714bd0_767x520.png" width="767" height="520" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f265f31a-a8ff-48a0-9777-906f1e714bd0_767x520.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:520,&quot;width&quot;:767,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23108,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/207931410?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff265f31a-a8ff-48a0-9777-906f1e714bd0_767x520.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lIXP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff265f31a-a8ff-48a0-9777-906f1e714bd0_767x520.png 424w, https://substackcdn.com/image/fetch/$s_!lIXP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff265f31a-a8ff-48a0-9777-906f1e714bd0_767x520.png 848w, https://substackcdn.com/image/fetch/$s_!lIXP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff265f31a-a8ff-48a0-9777-906f1e714bd0_767x520.png 1272w, https://substackcdn.com/image/fetch/$s_!lIXP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff265f31a-a8ff-48a0-9777-906f1e714bd0_767x520.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>We re-check the account: it is a member only of the Domain Users.</span></p><p><span>The consultant has an intuition: what if we try removing the account from the local administrators of the member server?</span></p><p><span>No sooner said than done, we run a new check, and that is where things get even stranger: now the permissions on the Active Directory tree are correct.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eurU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14a0576-e8ff-471f-994d-32ad2a2ec84b_767x520.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eurU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14a0576-e8ff-471f-994d-32ad2a2ec84b_767x520.png 424w, https://substackcdn.com/image/fetch/$s_!eurU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14a0576-e8ff-471f-994d-32ad2a2ec84b_767x520.png 848w, https://substackcdn.com/image/fetch/$s_!eurU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14a0576-e8ff-471f-994d-32ad2a2ec84b_767x520.png 1272w, https://substackcdn.com/image/fetch/$s_!eurU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14a0576-e8ff-471f-994d-32ad2a2ec84b_767x520.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eurU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14a0576-e8ff-471f-994d-32ad2a2ec84b_767x520.png" width="767" height="520" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d14a0576-e8ff-471f-994d-32ad2a2ec84b_767x520.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:520,&quot;width&quot;:767,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23712,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/207931410?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14a0576-e8ff-471f-994d-32ad2a2ec84b_767x520.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eurU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14a0576-e8ff-471f-994d-32ad2a2ec84b_767x520.png 424w, https://substackcdn.com/image/fetch/$s_!eurU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14a0576-e8ff-471f-994d-32ad2a2ec84b_767x520.png 848w, https://substackcdn.com/image/fetch/$s_!eurU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14a0576-e8ff-471f-994d-32ad2a2ec84b_767x520.png 1272w, https://substackcdn.com/image/fetch/$s_!eurU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd14a0576-e8ff-471f-994d-32ad2a2ec84b_767x520.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>That is when the matter lands on my desk. The consultant is rather confused: how can a local membership influence domain permissions? It is the world turned upside down!</span></p><p><span>I think over the information I have received, and in my mind an idea begins to take shape, one whose roots reach back to that distant 1983:</span></p><div><hr></div><p style="text-align: center;"><em><span>the behaviour is not real, we are facing an </span><strong><span>illusion</span></strong><span>!</span></em></p><div><hr></div><h2><span>The illusion revealed</span></h2><p><span>Common logic says that a local membership cannot have effects on a directory that lives elsewhere. And yet, the checks seem to confirm it.</span></p><p><span>The system is saying that that identity, from that point of observation, is no longer a simple service with minimal privileges. Quite the opposite.</span></p><p><span>And this is exactly where the illusion becomes interesting, because if reality has not changed, then something else has.</span></p><p><span>And, as with the Statue of Liberty, the right question is not &#8220;what happened&#8221;, but:</span></p><div><hr></div><p style="text-align: center;"><em><span>&#8220;where are we looking from&#8221;?</span></em></p><div><hr></div><p><span>The idea in my head becomes more and more present, and I ask the consultant: put things back the way they were, let us make sure the problem is present, then let us change our point of observation.</span></p><p><span>With the user put back into the local administrators of the member server, we verify that the &#8220;effective access&#8221; shows full permissions.</span></p><p><span>At that point I ask: shall we open the ADUC from a Domain Controller and run the same check from there?</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!36Jz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08dc8f72-8cc8-4a21-b1f9-5cc2140c0771_767x520.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!36Jz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08dc8f72-8cc8-4a21-b1f9-5cc2140c0771_767x520.png 424w, https://substackcdn.com/image/fetch/$s_!36Jz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08dc8f72-8cc8-4a21-b1f9-5cc2140c0771_767x520.png 848w, https://substackcdn.com/image/fetch/$s_!36Jz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08dc8f72-8cc8-4a21-b1f9-5cc2140c0771_767x520.png 1272w, https://substackcdn.com/image/fetch/$s_!36Jz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08dc8f72-8cc8-4a21-b1f9-5cc2140c0771_767x520.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!36Jz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08dc8f72-8cc8-4a21-b1f9-5cc2140c0771_767x520.png" width="767" height="520" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/08dc8f72-8cc8-4a21-b1f9-5cc2140c0771_767x520.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:520,&quot;width&quot;:767,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23712,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/207931410?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08dc8f72-8cc8-4a21-b1f9-5cc2140c0771_767x520.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!36Jz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08dc8f72-8cc8-4a21-b1f9-5cc2140c0771_767x520.png 424w, https://substackcdn.com/image/fetch/$s_!36Jz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08dc8f72-8cc8-4a21-b1f9-5cc2140c0771_767x520.png 848w, https://substackcdn.com/image/fetch/$s_!36Jz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08dc8f72-8cc8-4a21-b1f9-5cc2140c0771_767x520.png 1272w, https://substackcdn.com/image/fetch/$s_!36Jz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F08dc8f72-8cc8-4a21-b1f9-5cc2140c0771_767x520.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>As is clear from the image, the effective access is absolutely consistent with the delegation, there is no longer any trace of the almost-full permissions.</span></p><p><span>By changing perspective, the result changed, and this confirms the illusion.</span></p><p><span>But what, then, is creating this illusion?</span></p><p><span>I look at the consultant with a slight smile and tell him: I understand what happened, the test we just ran is the confirmation, it is a matter of Security Identifiers (SID).</span></p><p><span>I ask him to perform these two operations:</span></p><blockquote><p><span>&#183; from the member server, show the SID of the local Administrators group</span></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SRvg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337973b4-bb4e-4a0c-9cd5-6d44200cea6c_594x154.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SRvg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337973b4-bb4e-4a0c-9cd5-6d44200cea6c_594x154.png 424w, https://substackcdn.com/image/fetch/$s_!SRvg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337973b4-bb4e-4a0c-9cd5-6d44200cea6c_594x154.png 848w, https://substackcdn.com/image/fetch/$s_!SRvg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337973b4-bb4e-4a0c-9cd5-6d44200cea6c_594x154.png 1272w, https://substackcdn.com/image/fetch/$s_!SRvg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337973b4-bb4e-4a0c-9cd5-6d44200cea6c_594x154.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SRvg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337973b4-bb4e-4a0c-9cd5-6d44200cea6c_594x154.png" width="594" height="154" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/337973b4-bb4e-4a0c-9cd5-6d44200cea6c_594x154.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:154,&quot;width&quot;:594,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:7086,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/207931410?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337973b4-bb4e-4a0c-9cd5-6d44200cea6c_594x154.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SRvg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337973b4-bb4e-4a0c-9cd5-6d44200cea6c_594x154.png 424w, https://substackcdn.com/image/fetch/$s_!SRvg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337973b4-bb4e-4a0c-9cd5-6d44200cea6c_594x154.png 848w, https://substackcdn.com/image/fetch/$s_!SRvg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337973b4-bb4e-4a0c-9cd5-6d44200cea6c_594x154.png 1272w, https://substackcdn.com/image/fetch/$s_!SRvg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F337973b4-bb4e-4a0c-9cd5-6d44200cea6c_594x154.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><blockquote><p><span>&#183; from the Domain Controller, show the SID of the built-in domain local Administrators group</span></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OyJl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcb0c0eb-83c8-42f8-91fe-b7a3f8c9935a_696x114.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OyJl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcb0c0eb-83c8-42f8-91fe-b7a3f8c9935a_696x114.png 424w, https://substackcdn.com/image/fetch/$s_!OyJl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcb0c0eb-83c8-42f8-91fe-b7a3f8c9935a_696x114.png 848w, https://substackcdn.com/image/fetch/$s_!OyJl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcb0c0eb-83c8-42f8-91fe-b7a3f8c9935a_696x114.png 1272w, https://substackcdn.com/image/fetch/$s_!OyJl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcb0c0eb-83c8-42f8-91fe-b7a3f8c9935a_696x114.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OyJl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcb0c0eb-83c8-42f8-91fe-b7a3f8c9935a_696x114.png" width="696" height="114" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fcb0c0eb-83c8-42f8-91fe-b7a3f8c9935a_696x114.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:114,&quot;width&quot;:696,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5829,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/207931410?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcb0c0eb-83c8-42f8-91fe-b7a3f8c9935a_696x114.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OyJl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcb0c0eb-83c8-42f8-91fe-b7a3f8c9935a_696x114.png 424w, https://substackcdn.com/image/fetch/$s_!OyJl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcb0c0eb-83c8-42f8-91fe-b7a3f8c9935a_696x114.png 848w, https://substackcdn.com/image/fetch/$s_!OyJl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcb0c0eb-83c8-42f8-91fe-b7a3f8c9935a_696x114.png 1272w, https://substackcdn.com/image/fetch/$s_!OyJl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcb0c0eb-83c8-42f8-91fe-b7a3f8c9935a_696x114.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><span>And there is the illusion explained: the SID in the two cases is exactly the same!</span></p><p><span>Here is the Legacy Thing coming to the surface, once again we are facing one of those subtle default mechanisms that have been there for decades and whose memory has been lost: the </span><strong><span>well-known SIDs</span></strong><span>.</span></p><h2><span>What they are and why they are still there</span></h2><p><span>We already dealt with the concept of the </span><strong><span>Security Identifier (SID)</span></strong><span> in </span><strong><a href="https://www.legacythings.it/p/chapter-2-a-matter-of-trust?r=7oz2wp"><span>chapter 2</span></a></strong><span>, so I will not go back over it. What matters here is a very particular category of them: the </span><strong><span>well-known SIDs</span></strong><span>.</span></p><p><span>The vast majority of SIDs are born &#8220;unique&#8221;: they are generated at the exact moment the object is created, by the </span><strong><span>Local Security Authority (LSA)</span></strong><span> for the local objects of a machine or by the Domain Controller for domain objects, and are never reused to identify anyone else. The well-known SIDs do exactly the opposite: they have a fixed value, identical on any system. They are not generated: they simply exist.</span></p><p><span>There is even a precise date to which their practical debut can be traced. SIDs are not born with Active Directory, nor with some intermediate version of Windows: they arrive already with </span><strong><a href="https://en.wikipedia.org/wiki/Windows_NT_3.1"><span>Windows NT 3.1</span></a></strong><span>, the very first release of the NT family, shipped on </span><strong><span>July 27, 1993</span></strong><span>.</span></p><p><span>They were an integral part of the new security model designed by Dave Cutler&#8217;s team, the one built on access tokens and access control lists (ACL). In other words, when we talk about well-known SIDs we are not looking at a recent detail, but at a piece of architecture that has been with us, substantially unchanged, for over thirty years.</span></p><p><span>But where does the rule that imposes those fixed values come from? Who decided it, and where is it written? It is not an informal convention, nor a choice left to the individual implementation: it is set down in black and white in an </span><strong><span>official specification</span></strong><span>. The well-known SIDs are listed, one by one, in the </span><strong><a href="https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-dtyp/81d92bba-d22b-4a8c-908a-554ab29148ab"><span>[MS-DTYP] Windows Data Types</span></a></strong><span> document, in the section dedicated to the </span><em><span>Well-Known SID Structures</span></em><span>, where it is explicitly stated that their values &#8220;remain constant across all operating systems&#8221;.</span></p><p><span>It is one of Microsoft&#8217;s </span><strong><span>Open Specifications</span></strong><span>, that is, the protocol documentation designed so that anyone can implement the same model in an interoperable way. In other words, it is not that &#8220;Windows does it this way&#8221;: it is that anyone who wants to speak the same language is required to use exactly those numbers.</span></p><p><span>And here we come to a point that often surprises: the SID is not exclusive to the Windows world. The </span><a href="https://learn.microsoft.com/en-us/windows/win32/secauthz/well-known-sids"><span>documentation itself</span></a><span> distinguishes two families. On one side there are the </span><strong><span>universal</span></strong><span> well-known SIDs, which are meaningful &#8220;on all secure systems that adopt this security model, including operating systems other than Windows&#8221;, such as </span><strong><span>Everyone</span></strong><span> / </span><strong><span>World</span></strong><span> (</span><em><span>S-1-1-0</span></em><span>) or </span><strong><span>Creator Owner</span></strong><span> (</span><em><span>S-1-3-0</span></em><span>), the latter used as a placeholder in inheritable ACEs. On the other side there are the </span><strong><span>Windows-specific</span></strong><span> ones, including the </span><strong><span>BUILTIN</span></strong><span> groups.</span></p><p><span>That this is not just theory is confirmed in the field: implementations such as </span><strong><span>Samba</span></strong><span>, which today can act as an Active Directory Domain Controller on Linux, </span><a href="https://ubuntu.com/server/docs/explanation/active-directory/security-identifiers-sids/"><span>reason with exactly the same SIDs</span></a><span>. For them the local </span><strong><span>Administrators</span></strong><span> group is the identical </span><em><span>S-1-5-32-544</span></em><span>, and components like </span><strong><span>winbind</span></strong><span> exist precisely to map those SIDs onto the UID/GID of the Unix world.</span></p><p><span>The security model, in short, crossed the boundaries of Windows long ago.</span></p><p><span>Let us go back to our case. The </span><strong><span>Administrators</span></strong><span> group of the &#8220;built-in domain&#8221; has a very specific well-known SID: </span><strong><span>S-1-5-32-544</span></strong><span>. It is worth </span><a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-identifiers"><span>reading it</span></a><span> piece by piece: the </span><strong><span>5</span></strong><span> is the </span><em><span>NT</span></em><span> authority, the </span><strong><span>32</span></strong><span> identifies precisely the </span><strong><span>built-in</span></strong><span> domain, and the </span><strong><span>544</span></strong><span> is the RID of the Administrators group.</span></p><p><span>Always that one: on the member server, on the Domain Controller, on the consultant&#8217;s laptop. Identical, and not by chance.</span></p><p><span>The detail that generates the illusion lies entirely in that shared value. On a member server, </span><em><span>S-1-5-32-544</span></em><span> is the group of the </span><strong><span>local</span></strong><span> administrators of that machine, and nothing more. On a </span><strong><span>Domain Controller</span></strong><span>, however, the &#8220;built-in domain&#8221; coincides with the domain itself: that same identical SID represents there the administrators of the </span><strong><span>domain</span></strong><span>, with all the authority over the directory that comes with it.</span></p><p><span>When the Effective Access is calculated </span><strong><span>from the member server</span></strong><span>, the tool sees that the gMSA belongs to </span><em><span>S-1-5-32-544</span></em><span> and compares it with the ACLs of Active Directory, where that same SID enjoys full permissions. The tool does not know, and cannot know, that &#8220;that 544, seen from here, is only valid locally&#8221;. It puts together two different contexts that share the same label and returns an inflated picture. It is enough to move the point of observation to a DC for the ambiguity to disappear: from there the context is only one, and the numbers add up.</span></p><p><span>So why, after decades, are they still there? For the same reason you do not switch language halfway through a conversation. The well-known SIDs are one of the fundamental bricks of the authorization model: inherited ACEs, access tokens, delegations, default permissions, everything rests on them. Changing them would mean breaking compatibility with anything written in the last thirty years, and not only on the Windows side. They are stable </span><strong><span>by design</span></strong><span>: it is the specification itself that binds them to remain constant over time and across different systems.</span></p><p><span>They are not, therefore, an error, nor an oversight left lying around out of laziness. They are exactly what they were meant to be. The problem is not the SID: it is that we, faced with an interface, tend to read a label while forgetting where we are looking at it from. And the point of observation, as usual, is everything.</span></p><h2><span>What it taught us</span></h2><p><span>The first lesson this case leaves us is only simple in appearance: the tool was not lying. The Effective Access did exactly its job, it calculated the access starting from what it saw from that point, and it answered in a formally correct way. The problem is that we were looking for another truth, that of the real permissions on the directory, and it had never promised to tell us that one. So I come back to that motto I have already used in these pages, because there is no better summary: </span><strong><span>IT systems do not do what you want, they do what you tell them to do</span></strong><span>. We had effectively asked that tool &#8220;tell me what you see from here&#8221;, and it, with implacable consistency, answered exactly that. The illusion was not in the software, but in having mistaken its answer for the question we had in our heads.</span></p><p><span>The second lesson concerns the way we react when facing an &#8220;impossible&#8221; behaviour. The instinct, almost always, is to immediately look for a culprit: a bug, a wrong configuration, a compromise, something that &#8220;broke&#8221;. But in this case nothing had broken, and no hunt for a culprit would have led anywhere. The turning point came only when we stopped asking ourselves &#8220;what happened&#8221; and started asking &#8220;where are we looking from&#8221;. Moving the point of observation, from the member server to the Domain Controller, made the anomaly vanish exactly as the Statue of Liberty returned to its place the moment the audience realized it had moved. The consultant, faced with those impossible permissions, had exclaimed &#8220;it is the world turned upside down!&#8221;. And that is precisely where the lesson lies:</span></p><div><hr></div><p style="text-align: center;"><em><span>When the world seems absurdly upside down, almost always it is not the world that has flipped over: it is your point of observation that is wrong.</span></em></p><div><hr></div><p><span>Before believing that it is reality spinning the wrong way, it is worth checking where we are looking at it from.</span></p><p><span>There is, finally, a third lesson, and it is the one that holds the entire series together: legacy is not a defect, it is lost memory. The well-known SID was not an error left there out of laziness, it was exactly what it was meant to be, stable </span><strong><span>by design</span></strong><span> for over thirty years. What was missing was not the correctness of the system, but our knowledge of the model, knowing that that </span><em><span>32</span></em><span> means &#8220;built-in domain&#8221; and that that </span><em><span>544</span></em><span> is worth the exact same number in different worlds. It is the same thread that runs through all these chapters. The guardian of AdminSDHolder rewriting permissions no one was asking for anymore, the trusts born to give shape to trust and turned into an invisible constraint, the Domain Controller that seemed to lie while it was telling the truth. Every time, the point was not that the system was broken. The point was that the system kept doing what it had been designed to do, while we had lost part of the memory of that design.</span></p><p><span>Perhaps this is the real illusion of legacy systems: they do not deceive us by hiding, they deceive us by staying in plain sight, so obvious and silent that we stop really looking at them. They keep answering with precision, but we have forgotten the question they were answering. And so, as in front of the Statue of Liberty, the only way to recognize the trick is not to stare more intensely at the same spot, but to have the humility to move and ask ourselves where we are looking from.</span></p><p><span>And it is exactly from here that </span><em><span>Legacy Things</span></em><span> continues its journey: bringing back to light those silent mechanisms that, although born decades ago, still govern the behaviour of modern infrastructures. Not out of nostalgia, but because ignoring them does not make them harmless. It only makes them better at showing us things that do not exist.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Legacy Things! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Capitolo #4 - RC4, verso il tramonto?]]></title><description><![CDATA[Troppo bello per restare segreto, troppo utile per sparire subito]]></description><link>https://www.legacythings.it/p/capitolo-4-rc4-verso-il-tramonto</link><guid isPermaLink="false">https://www.legacythings.it/p/capitolo-4-rc4-verso-il-tramonto</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Tue, 30 Jun 2026 07:31:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mxtD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8cabac-da00-4df8-9df5-52d1cdc63e03_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>English version available here &#8594;<a href="https://www.legacythings.it/p/chapter-4-rc4-heading-toward-sunset"> [EN]</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mxtD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8cabac-da00-4df8-9df5-52d1cdc63e03_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mxtD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8cabac-da00-4df8-9df5-52d1cdc63e03_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!mxtD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8cabac-da00-4df8-9df5-52d1cdc63e03_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!mxtD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8cabac-da00-4df8-9df5-52d1cdc63e03_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!mxtD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8cabac-da00-4df8-9df5-52d1cdc63e03_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mxtD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8cabac-da00-4df8-9df5-52d1cdc63e03_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b8cabac-da00-4df8-9df5-52d1cdc63e03_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3237604,&quot;alt&quot;:&quot;Copertina di Legacy Things #4. Un lungo muro in cemento coperto da graffiti si estende verso l'orizzonte al tramonto. Sulla parete &#232; visibile la scritta RC4 in grandi lettere. Sullo sfondo si intravede lo skyline di Berlino illuminato dalla luce del sole al tramonto, mentre una strada costeggia il muro conducendo verso l'orizzonte. Il titolo &#8220;Legacy Things #4&#8221; compare nella parte superiore dell'immagine.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/203921803?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8cabac-da00-4df8-9df5-52d1cdc63e03_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Copertina di Legacy Things #4. Un lungo muro in cemento coperto da graffiti si estende verso l'orizzonte al tramonto. Sulla parete &#232; visibile la scritta RC4 in grandi lettere. Sullo sfondo si intravede lo skyline di Berlino illuminato dalla luce del sole al tramonto, mentre una strada costeggia il muro conducendo verso l'orizzonte. Il titolo &#8220;Legacy Things #4&#8221; compare nella parte superiore dell'immagine." title="Copertina di Legacy Things #4. Un lungo muro in cemento coperto da graffiti si estende verso l'orizzonte al tramonto. Sulla parete &#232; visibile la scritta RC4 in grandi lettere. Sullo sfondo si intravede lo skyline di Berlino illuminato dalla luce del sole al tramonto, mentre una strada costeggia il muro conducendo verso l'orizzonte. Il titolo &#8220;Legacy Things #4&#8221; compare nella parte superiore dell'immagine." srcset="https://substackcdn.com/image/fetch/$s_!mxtD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8cabac-da00-4df8-9df5-52d1cdc63e03_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!mxtD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8cabac-da00-4df8-9df5-52d1cdc63e03_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!mxtD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8cabac-da00-4df8-9df5-52d1cdc63e03_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!mxtD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8cabac-da00-4df8-9df5-52d1cdc63e03_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><span>1987</span></strong><span>. Il mondo ragionava per blocchi, confini e recinti. L&#8217;esempio pi&#249; eclatante: la guerra fredda tra USA e Unione Sovietica.</span></p><p>Berlino ne era il simbolo pi&#249; evidente e il Muro era ancora in piedi a ricordarlo a tutti. Il 12 giugno di quell&#8217;anno il presidente USA di allora, Ronald Reagan, davanti alla Porta di Brandeburgo, pronunciava una frase destinata a restare nella storia come una provocazione e una speranza insieme:</p><div><hr></div><p style="text-align: center;"><em><span>&#8220;Mr. Gorbachev, tear down this wall!&#8221;</span></em></p><div><hr></div><p>Pochi mesi dopo, l&#8217;8 dicembre, Stati Uniti e Unione Sovietica firmavano il <a href="https://it.wikipedia.org/wiki/Trattato_INF">trattato INF</a>, primo segnale concreto di un equilibrio che iniziava lentamente a incrinarsi. Fuori c&#8217;erano ancora i muri, ma da qualche parte si iniziava gi&#224; a parlare di futuro.</p><p>&#200; in quella strana sospensione, tra muri ancora intatti e crepe gi&#224; visibili, che nasceva un algoritmo di cifratura destinato a durare a lungo: <strong>RC4.</strong></p><p>Non come standard aperto, non come bene comune, ma come segreto industriale. In quell&#8217;anno infatti <strong>Ron Rivest</strong>, uno dei fondatori di <strong>RSA Data Security,</strong> progetta l&#8217;algoritmo come componente della libreria crittografica proprietaria RSA.</p><p>La sigla viene comunemente tradotta in<strong> &#8220;Rivest Cipher 4</strong>&#8221;, anche se secondo <strong>Ron Rivest </strong>stesso le lettere RC stavano per <strong>&#8220;Ron&#8217;s Code&#8221;.</strong></p><p>Quando penso a quel 1987, per&#242;, non riesco a sentirci solo la geopolitica o la tensione della Guerra Fredda. Ci sento anche altro.</p><p>Nei club la musica House vive la sua epoca d&#8217;oro, e il sottoscritto ne rimane ammaliato, muovendo i primi passi tra vinili, mixer e dei fidatissimi Technics SL-1210 MK2. La cosa curiosa &#232; che, come l&#8217;RC4, anche la tecnologia musicale di allora era progettata per durare. Ancora oggi posso accendere lo stesso impianto e suonare gli stessi vinili senza alcun problema.</p><p>Ma parlando di vinili, se ne devo scegliere uno per fare da cornice al contesto storico, il primo che mi viene in mente &#232; <strong>Promised Land</strong> di <strong>Joe Smooth</strong>. Perch&#233; mentre fuori il mondo era ancora fatto di separazioni, dentro quel suono girava gi&#224; un&#8217;idea opposta:</p><div><hr></div><p style="text-align: center;"><em><strong><span>&#8220;brothers and sisters, one day we will be free&#8221;</span></strong></em></p><p style="text-align: center;"><em>non pi&#249; divisione, non pi&#249; conflitto, ma l&#8217;idea che si possa finalmente camminare nella stessa direzione.</em></p><div><hr></div><p>Poi arriv&#242; il <strong>9 novembre 1989</strong>, e il Muro di Berlino cadde davvero. Con lui non venne gi&#249; soltanto una barriera di cemento, ma l&#8217;idea stessa che certi recinti fossero naturali, inevitabili o destinati a durare per sempre. Da l&#236; in avanti il cambiamento non fu solo politico. Fu culturale. Cambi&#242; il modo di guardare ai confini, alla circolazione delle idee, alla pretesa che alcune cose dovessero restare chiuse in eterno, creando un effetto domino che si diffuse ovunque negli anni seguenti.</p><p>Cinque anni dopo, <strong>1994</strong>, quel mondo non &#232; ancora finito del tutto, ma ha gi&#224; perso la sua rigidit&#224; originaria. E infatti, in un modo perfettamente anni Novanta, anche RC4 esce dal recinto con un leak dalla grande risonanza mediatica: una descrizione dell&#8217;algoritmo viene pubblicata anonimamente sulla mailing list dei cypherpunks e poi rilanciata su sci.crypt. Il segreto smette di essere tale e comincia la sua divulgazione.</p><p>Il caso finisce anche su TIME con un articolo dal nome &#8220;The Secret&#8217;s Out&#8221;. Segno che il leak non &#232; pi&#249; solo materia da addetti ai lavori.</p><p>Ma invece di decretarne la fine, quel leak ne inaugur&#242; una seconda vita: da segreto industriale RC4 divent&#242; oggetto di circolazione, implementazione e discussione sempre pi&#249; ampia.</p><p>Passano altri cinque anni, <strong>1999</strong>, anche <strong>Microsoft</strong> decide di adottare <strong>RC4</strong> come algoritmo di cifratura standard per la propria implementazione <strong>Kerberos</strong>, usandolo come ponte di compatibilit&#224; per accompagnare la transizione dagli ambienti <strong>Windows NT</strong> esistenti e contribuendo a farlo diventare uno dei pilastri delle autenticazioni Windows per i decenni a venire.</p><p>La cosa curiosa &#232; che nemmeno allora la storia si considera davvero completa, bisogna aspettare addirittura <strong>dicembre 2006</strong> perch&#233; questa parte della sua vita venga formalizzata in un RFC (4757) che documenta i tipi di cifratura RC4-HMAC usati da Microsoft in Windows.</p><p>Pi&#249; di dieci anni dopo la sua rivelazione pubblica, quasi vent&#8217;anni dopo la sua nascita. Come se la burocrazia, ancora una volta, si limitasse a registrare qualcosa che la pratica aveva gi&#224; accettato da tempo.</p><p>E proprio qui, tra un segreto troppo bello per restare tale e un&#8217;idea troppo utile per sparire subito, comincia davvero la storia del suo declino.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.legacythings.it/subscribe?"><span>Iscriviti ora</span></a></p><h2>Perch&#233; RC4 &#232; arrivato davvero al tramonto</h2><p>Prima di raccontare perch&#233; RC4 sia arrivato al tramonto, vale la pena ricordare perch&#233; abbia avuto cos&#236; tanta fortuna. Non si &#232; diffuso per caso, n&#233; soltanto perch&#233; era disponibile. Per il mondo degli anni Novanta era quasi perfetto: era veloce, semplice da implementare, leggero per l&#8217;hardware dell&#8217;epoca e abbastanza flessibile da infilarsi in contesti molto diversi tra loro. Non richiedeva strutture particolarmente complesse, lavorava bene in software e poteva essere adottato in protocolli che avevano bisogno di cifrare flussi di dati in modo pratico, senza appesantire troppo sistemi e applicazioni.</p><p>Per questo fin&#236; ovunque: nelle prime versioni di SSL e TLS, nelle reti Wi&#8209;Fi con WEP, poi WPA/TKIP, e infine come gi&#224; visto dentro Kerberos in ambiente Windows. In altre parole, RC4 non era solo un algoritmo: era una soluzione pratica a un problema molto concreto, quello di portare un po&#8217; di cifratura in un mondo che stava diventando sempre pi&#249; connesso, ma che non poteva ancora permettersi di cambiare tutto insieme.</p><p>Ma quindi, cosa ne sta decretando la fine?</p><p>RC4 non esce di scena perch&#233; qualcuno ha deciso, all&#8217;improvviso, che fosse soltanto &#8220;vecchio&#8221;. Esce di scena perch&#233; il mondo che lo aveva reso una buona idea &#232; cambiato. Per anni &#232; stato il compromesso perfetto: solido quanto bastava per sembrare moderno, flessibile quanto serviva per accompagnare sistemi che dovevano evolvere senza potersi permettere di buttare via tutto ci&#242; che c&#8217;era prima.</p><p>Il punto &#232; che i compromessi tecnici invecchiano male quando il contesto smette di proteggerli. Ed &#232; esattamente quello che &#232; successo a RC4. Con il tempo sono emerse debolezze crittografiche sempre pi&#249; difficili da ignorare, mentre intorno crescevano attacchi pi&#249; pratici, pi&#249; accessibili e alternative pi&#249; solide. Non &#232; un caso se RC4 ha iniziato a uscire di scena in pi&#249; ambiti: nel <strong>2015</strong> l&#8217;<strong>IETF</strong> ne <a href="https://datatracker.ietf.org/doc/html/rfc7465">vieta l&#8217;uso in TLS</a>, nel <strong>2020</strong> ne <a href="https://www.ietf.org/rfc/rfc8758.html">depreca formalmente l&#8217;uso in SSH</a>, e nel mondo <strong>Wi&#8209;Fi</strong> il settore spinge da anni verso <strong>WPA2</strong> con <strong>AES</strong>, lasciandosi alle spalle le soluzioni transitorie che ancora si appoggiavano allo stesso cipher di fondo.</p><p><span>Questo introduce il caso Microsoft, che non va letto come un&#8217;eccezione, ma come uno degli ultimi capitoli di una storia gi&#224; iniziata altrove. Nel post ufficiale </span><em><a href="https://www.microsoft.com/en-us/windows-server/blog/2025/12/03/beyond-rc4-for-windows-authentication/"><span>Beyond RC4 for Windows authentication</span></a></em><span>, Microsoft dice apertamente che RC4 &#232; suscettibile ad attacchi come il Kerberoasting e che un&#8217;autenticazione Windows sicura non ha pi&#249; bisogno di lui, perch&#233; AES &#232; disponibile da anni su tutte le versioni supportate. In altre parole, RC4 non smette di funzionare: arriva al tramonto quando il presente smette di avere buone ragioni per continuare a farne uso.</span></p><h2>Come Microsoft sta accompagnando RC4 fuori scena</h2><p>A guardarla bene, questa storia non comincia quest&#8217;anno. Microsoft aveva gi&#224; iniziato a spostare il baricentro lontano da RC4 almeno dal <strong>2022</strong>, quando gli aggiornamenti legati a <strong><a href="https://support.microsoft.com/en-us/topic/kb5021131-how-to-manage-the-kerberos-protocol-changes-related-to-cve-2022-37966-fd837ac3-cdec-4e76-a6ec-86e67501407d">CVE-2022-37966</a></strong> hanno portato <strong>AES</strong> a diventare il default per le session keys sugli account senza impostazioni esplicite. Non era ancora una dismissione finale, ma il segnale era gi&#224; chiaro: il vecchio compromesso stava perdendo terreno. Anche la documentazione pi&#249; recente lo riconosce apertamente, spiegando che quel cambio ha gi&#224; ridotto in modo significativo l&#8217;uso di RC4, pur senza eliminarlo del tutto.</p><p>Il 2025 e soprattutto il 2026, per&#242;, cambiano il tono della musica. Non siamo pi&#249; nel campo dell&#8217;hardening progressivo o del dettaglio tecnico che passa quasi inosservato in una cumulative update. Siamo nel momento in cui Microsoft decide di rendere esplicita la traiettoria e di <a href="https://support.microsoft.com/en-us/topic/how-to-manage-kerberos-kdc-usage-of-rc4-for-service-account-ticket-issuance-changes-related-to-cve-2026-20833-1ebcda33-720a-4da8-93c1-b0496e1910dc">scandirla in fasi molto leggibili</a>: prima l&#8217;audit, poi il cambio di comportamento di default, infine la chiusura della tolleranza implicita. &#200; come se per anni ci fosse stato un cartello &#8220;lavori in corso&#8221; all&#8217;ingresso, e solo quest&#8217;anno qualcuno avesse cominciato davvero a chiudere la strada.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZrMy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3d20721-d66d-4f3b-bf86-86afb17a4ae3_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZrMy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3d20721-d66d-4f3b-bf86-86afb17a4ae3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ZrMy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3d20721-d66d-4f3b-bf86-86afb17a4ae3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ZrMy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3d20721-d66d-4f3b-bf86-86afb17a4ae3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ZrMy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3d20721-d66d-4f3b-bf86-86afb17a4ae3_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZrMy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3d20721-d66d-4f3b-bf86-86afb17a4ae3_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3d20721-d66d-4f3b-bf86-86afb17a4ae3_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3269500,&quot;alt&quot;:&quot;Spiaggia tropicale al tramonto con quattro cartelli lungo la riva che riportano le tappe 2022 AES default, 2025 Guidance, 2026 Remediation e July 2026 Sunset. Decine di lanterne galleggianti illuminate con la scritta RC4 si allontanano verso l'orizzonte seguendo il mare al tramonto.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/203921803?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3d20721-d66d-4f3b-bf86-86afb17a4ae3_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Spiaggia tropicale al tramonto con quattro cartelli lungo la riva che riportano le tappe 2022 AES default, 2025 Guidance, 2026 Remediation e July 2026 Sunset. Decine di lanterne galleggianti illuminate con la scritta RC4 si allontanano verso l'orizzonte seguendo il mare al tramonto." title="Spiaggia tropicale al tramonto con quattro cartelli lungo la riva che riportano le tappe 2022 AES default, 2025 Guidance, 2026 Remediation e July 2026 Sunset. Decine di lanterne galleggianti illuminate con la scritta RC4 si allontanano verso l'orizzonte seguendo il mare al tramonto." srcset="https://substackcdn.com/image/fetch/$s_!ZrMy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3d20721-d66d-4f3b-bf86-86afb17a4ae3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ZrMy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3d20721-d66d-4f3b-bf86-86afb17a4ae3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ZrMy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3d20721-d66d-4f3b-bf86-86afb17a4ae3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ZrMy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3d20721-d66d-4f3b-bf86-86afb17a4ae3_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">RC4 non sta sparendo. Lo stiamo accompagnando verso il tramonto.</figcaption></figure></div><p>Il punto di svolta, a quel punto, diventa <strong>luglio 2026</strong>. Perch&#233; &#232; l&#236; che la timeline smette di essere una successione di avvisi e diventa scadenza vera. <strong>KB5073381</strong> dice che gli aggiornamenti rilasciati in quel periodo abiliteranno programmaticamente la <strong>Enforcement Phase</strong>; la procedura operativa che stiamo usando sul campo lo traduce in maniera ancora pi&#249; netta: niente rollback comodo, niente ritorno al passato per inerzia, niente fallback implicito lasciato l&#236; a proteggere ci&#242; che nessuno ha ancora messo in ordine. Da quel momento RC4 continua a vivere solo dove qualcuno lo avr&#224; mantenuto in modo esplicito, account per account, eccezione per eccezione.</p><p>Ed &#232; proprio qui che la faccenda si fa interessante. Perch&#233; Microsoft mette a disposizione strumenti ufficiali per affrontare il problema: pi&#249; visibilit&#224; nei log, una pagina di guidance su come rilevare e correggere l&#8217;uso di RC4, e degli script PowerShell di auditing richiamati nella documentazione ufficiale. Ma la realt&#224; &#232; che questi strumenti, da soli, rischiano di restituire una fotografia piena di rumore.</p><p>La documentazione Microsoft stessa spiega che RC4 continua a comparire per ragioni diverse: sistemi legacy, account senza impostazioni esplicite, configurazioni incomplete. E l&#8217;esperienza sul campo aggiunge un dettaglio ancora pi&#249; concreto: i grandi numeri grezzi possono essere fuorvianti, l&#8217;assenza di traffico RC4 rilevato non &#232; sempre conclusiva, e certe categorie, come gli account &#8220;senza AES keys&#8221; letti in modo superficiale, rischiano di allargare il problema pi&#249; di quanto serva davvero.</p><p>Per questo il passaggio successivo non pu&#242; essere solo tecnico. Serve un approccio ampio, s&#236;, ma soprattutto pragmatico: abbastanza esteso da non perdere i segnali deboli, abbastanza lucido da non farsi travolgere dal rumore di fondo.</p><p>Perch&#233; nei sistemi enterprise il passato non si presenta quasi mai in modo ordinato. Si annida nelle abitudini, nelle impostazioni ereditarie, nei default lasciati l&#236; per anni, nei comportamenti che sembrano normali solo perch&#233; nessuno li guardava pi&#249; da vicino.</p><p>Ed &#232; da l&#236; che bisogna partire, se davvero si vuole arrivare ai nodi chiave e iniziare a sbrogliare la matassa.</p><h2>Cosa sta emergendo dalle analisi che stiamo facendo</h2><p>Quando si passa dalla teoria ai sistemi veri, la faccenda smette subito di sembrare lineare. Sulla carta il problema potrebbe apparire quasi banale: Microsoft cambia un default, RC4 esce di scena e chi &#232; rimasto indietro si adegua.</p><p>Mi &#232; capitato pi&#249; volte di sentire frasi del tipo: &#8220;sono abbastanza sicuro che da noi non avr&#224; impatti&#8221;. E ogni volta mi sono chiesto da dove arrivasse tutta quella sicurezza.</p><p>Nella pratica, infatti, i sistemi enterprise non ragionano mai in modo cos&#236; pulito. Ragionano per abitudini, per stratificazioni, per impostazioni ereditate che continuano a produrre effetti molto tempo dopo che ci si &#232; dimenticati perfino il motivo per cui erano state messe l&#236;. Ed &#232; proprio in questa zona grigia che RC4 continua a lasciare tracce.</p><p>Guardando i dati emersi sul campo, la prima cosa che si capisce &#232; che i numeri grezzi aiutano fino a un certo punto.</p><p>Partendo da uno sguardo d&#8217;insieme, il quadro tende quasi sempre a restringersi attorno agli stessi punti sensibili. Non tanto i grandi volumi indistinti, ma una manciata di account di servizio con SPN, password storiche mai ruotate, qualche sistema non Windows o non chiaramente AES-capable, e tutti quei pezzi d&#8217;infrastruttura che vivono tranquilli da anni proprio perch&#233; nessuno ha pi&#249; avuto motivo di toccarli.</p><p>A contorno centinaia o migliaia di oggetti utente e computer che si sistemano con un approccio pragmatico, ma che nascondono alla vista i nodi focali.</p><p>Nei report che stiamo producendo la logica torna spesso la stessa: il lavoro vero non sta nei grandi numeri che fanno impressione in una tabella, ma in pochi oggetti che tengono ancora in piedi dipendenze pesanti e poco visibili.</p><p>C&#8217;&#232; poi un altro aspetto, forse il pi&#249; insidioso: l&#8217;assenza di evidenze forti non coincide automaticamente con l&#8217;assenza di problemi.</p><p>In pi&#249; di un caso la raccolta eventi &#232; risultata limitata o parziale, e la raccomandazione &#232; quella di impostare una finestra di audit abbastanza ampia quando i dati non bastano a chiudere il quadro.</p><p>Anche qui torna il solito paradosso dei sistemi legacy: il passato non fa rumore quando &#232; davvero presente, anzi spesso resta tranquillo finch&#233; qualcuno non decide di guardarlo meglio.</p><p>Per questo, pi&#249; andiamo avanti, pi&#249; il punto mi sembra chiaro: affrontare RC4 non significa semplicemente &#8220;cercare dove appare&#8221; e spegnerlo ovunque. Significa leggere i sistemi con una lente abbastanza larga da non perdere il contesto, ma abbastanza pragmatica da individuare i nodi che contano davvero.</p><p>Non serve inseguire ogni riflesso. Serve capire quali segnali portano a dipendenze reali, quali sono solo rumore di fondo e dove conviene intervenire senza farsi travolgere dal groviglio.</p><p>Ed &#232; proprio qui che l&#8217;esperienza sul campo diventa vitale: perch&#233; nei sistemi legacy il problema raramente &#232; dove lo vedi subito. Pi&#249; spesso &#232; dove nessuno pensava pi&#249; di dover guardare.</p><h3>Note pratiche dal campo</h3><p>A questo punto vale la pena scendere ancora di un livello. Perch&#233; i dati aiutano, ma sono gli esempi concreti a far capire dove il passato continua davvero a pesare. In questo caso ho chiesto aiuto al collega <strong><a href="https://www.linkedin.com/in/mattiagrandi">Mattia Grandi</a></strong>, che ha riassunto bene gli aspetti pi&#249; tecnici in questo <a href="https://www.mgworkplace.it/field-guides/rc4-deprecation-active-directory">articolo</a>.</p><p>Parlando di casi emblematici il primo che mi viene in mente &#232; <strong>Kemp Loadmaster</strong>, molto spesso usato per fare ripubblicazioni con <strong>Kerberos Constrained Delegation (KCD).</strong></p><p>Questo &#232; uno di quei casi in cui l&#8217;implementazione Kerberos non &#232; &#8220;Windows native&#8221;. Di conseguenza il cambio di algoritmo va effettuato con cautela, identificando bene la sequenza operativa e una finestra manutentiva dedicata. &#200; un pattern comune nelle implementazioni Kerberos di terze parti.</p><p>Guardando poi &#8220;verso il cielo&#8221; ci possiamo trovare a dover gestire lo storico account <strong>AZUREADSSOACC$,</strong> utilizzato per la funzionalit&#224; di <strong>Seamless Single Sign-On </strong>per <strong>Entra ID</strong>.</p><p>&#200; un classico esempio di implementazione cloud-driven che, proprio perch&#233; nata con un default storico su RC4, oggi mostra tutti i limiti di quella scelta.</p><p>Bisogna poi ricordarsi che il Kerberos per sua natura non &#232; confinato a un solo dominio, ma spesso esce dai confini attraverso le <strong>Trust</strong>.</p><p>Queste ultime sono altrettanto suscettibili rispetto all&#8217;algoritmo di funzionamento impostato: se ho una Trust che non supporta AES, o che non ha AES configurato, la chiusura del RC4 la &#8220;romper&#224;&#8221; come se fosse un PC qualsiasi, ma con effetti molto pi&#249; diffusi.</p><p>Parliamo infine di <strong>sistemi legacy</strong>, che siano dei <strong>Windows Server 2003</strong> sopravvissuti ai decenni o implementazioni di terze parti che non supportano AES, ad esempio gli immortali sistemi<strong> AS/400</strong>.</p><p>In questi casi non sempre sar&#224; possibile chiudere RC4 in modo netto e immediato.</p><p>Sar&#224; invece necessario indagare in maniera puntuale quale sia l&#8217;utilizzo effettivo che viene fatto del Kerberos. Questo per poter gestire esclusioni mirate e consapevoli.</p><p>Come vedete, lo spettro d&#8217;azione si allarga in fretta. Il rischio non &#232; solo rompere qualcosa, ma perdere il controllo della situazione o concentrare gli sforzi dove non serve davvero.</p><h2>Cosa ci ha insegnato il tramonto di RC4</h2><p>La prima lezione che il tramonto di RC4 ci lascia &#232; semplice solo in apparenza: i compromessi tecnici pi&#249; riusciti sono anche quelli pi&#249; difficili da mandare in pensione. RC4 &#232; sopravvissuto cos&#236; a lungo non perch&#233; fosse perfetto, ma perch&#233; per anni &#232; stato veloce, pratico, compatibile e sufficientemente leggero da diventare invisibile. E quando una tecnologia diventa invisibile, smette di essere discussa molto prima di smettere di produrre effetti reali.</p><p>La seconda lezione riguarda il modo in cui trattiamo il passato nei sistemi enterprise. Ignorarlo non lo rende innocuo. Lo rende solo pi&#249; difficile da riconoscere quando torna a presentare il conto. Nel caso di RC4 quel conto ha anche una data abbastanza precisa: <strong>luglio 2026</strong>. Chi arriver&#224; a quel punto ancora dipendente da questo vecchio compromesso non si trover&#224; davanti a un mistero, ma a fallimenti di autenticazione ampiamente prevedibili.</p><p>Questo non significa affrontare il tema in modo ideologico. Nei sistemi reali esistono sempre eccezioni, dipendenze, appliance che non seguono i tempi del resto dell&#8217;infrastruttura, sistemi davvero non AES-capable e integrazioni che richiedono una transizione pi&#249; lenta. Ma proprio perch&#233; queste eccezioni esistono, devono restare quello che sono: eccezioni vere, documentate, approvate e riesaminate. Non una nuova normalit&#224; dietro cui continuare a nascondere l&#8217;inerzia.</p><p>Perch&#233; compatibilit&#224; e inerzia non sono la stessa cosa. La compatibilit&#224; &#232; una scelta progettuale consapevole: serve a far evolvere un sistema senza spezzarlo. L&#8217;inerzia, invece, &#232; quello che rimane quando quella scelta smette di essere governata. &#200; il default lasciato l&#236; troppo a lungo, l&#8217;account di servizio mai rivisto, la trust che nessuno tocca pi&#249;, il sistema legacy che continua a funzionare non perch&#233; sia stato compreso, ma perch&#233; nessuno ha ancora avuto il coraggio o il tempo di guardarci dentro.</p><p>In fondo &#232; lo stesso filo che attraversa tutti questi capitoli. Il guardiano di AdminSDHolder, le trust nate per dare forma alla fiducia, il Domain Controller che sembrava mentire: ogni volta il punto non era che il sistema fosse rotto. Il punto era che il sistema continuava a fare quello per cui era stato progettato, mentre noi avevamo perso parte della memoria di quel progetto.</p><p><strong>RC4</strong> racconta la stessa cosa da un&#8217;altra angolazione. Non &#232; il mostro da cancellare dalla storia, e nemmeno il simbolo di un errore clamoroso. &#200; stato una buona risposta a un problema del suo tempo. Solo che il tempo, a un certo punto, cambia domanda. E quando cambia domanda, continuare a dare la stessa risposta non &#232; pi&#249; compatibilit&#224;: &#232; ostinazione.</p><p>Forse &#232; questa la lezione pi&#249; importante del suo tramonto: non possiamo pretendere che i sistemi legacy spariscano da soli, n&#233; che smettano spontaneamente di influenzare il presente. Dobbiamo guardarli, capirli, decidere cosa salvare e cosa accompagnare fuori scena. Senza nostalgia, ma anche senza arroganza. Perch&#233; molte delle cose che oggi chiamiamo legacy sono state, nel loro momento, ottime soluzioni.</p><p>Il problema nasce quando continuiamo a trattarle come se il mondo intorno non fosse cambiato.</p><p>RC4 ha avuto una vita lunga, utile e per certi versi sorprendente. Adesso per&#242; il tramonto non &#232; pi&#249; una metafora: &#232; una deadline. E, come spesso accade nelle infrastrutture enterprise, la differenza tra una transizione ordinata e un incidente evitabile sta tutta nel decidere se occuparsene quando c&#8217;&#232; ancora luce, oppure aspettare il buio.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Grazie per aver letto Legacy Things! Iscriviti gratuitamente per supportare il mio lavoro.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Chapter #4 - RC4, heading toward sunset?]]></title><description><![CDATA[Too good to remain secret, too useful to disappear at once]]></description><link>https://www.legacythings.it/p/chapter-4-rc4-heading-toward-sunset</link><guid isPermaLink="false">https://www.legacythings.it/p/chapter-4-rc4-heading-toward-sunset</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Tue, 30 Jun 2026 07:20:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!uPSv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dded8eb-0431-4954-b884-d0a3c87b8679_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Versione italiana disponibile qui &#8594;</em><a href="https://www.legacythings.it/p/capitolo-1-adminsdholder-il-guardiano"> </a><em><a href="https://www.legacythings.it/p/capitolo-4-rc4-verso-il-tramonto">[IT]</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uPSv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dded8eb-0431-4954-b884-d0a3c87b8679_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uPSv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dded8eb-0431-4954-b884-d0a3c87b8679_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!uPSv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dded8eb-0431-4954-b884-d0a3c87b8679_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!uPSv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dded8eb-0431-4954-b884-d0a3c87b8679_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!uPSv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dded8eb-0431-4954-b884-d0a3c87b8679_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uPSv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dded8eb-0431-4954-b884-d0a3c87b8679_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6dded8eb-0431-4954-b884-d0a3c87b8679_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3237604,&quot;alt&quot;:&quot;Legacy Things #4 cover image. A long concrete wall covered with graffiti stretches toward the horizon at sunset. The text &#8220;RC4&#8221; is painted in large letters on the wall. In the background, the Berlin skyline is visible against the setting sun, while a road runs alongside the wall toward the horizon. The title &#8220;Legacy Things #4&#8221; appears at the top of the image.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/203923381?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dded8eb-0431-4954-b884-d0a3c87b8679_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Legacy Things #4 cover image. A long concrete wall covered with graffiti stretches toward the horizon at sunset. The text &#8220;RC4&#8221; is painted in large letters on the wall. In the background, the Berlin skyline is visible against the setting sun, while a road runs alongside the wall toward the horizon. The title &#8220;Legacy Things #4&#8221; appears at the top of the image." title="Legacy Things #4 cover image. A long concrete wall covered with graffiti stretches toward the horizon at sunset. The text &#8220;RC4&#8221; is painted in large letters on the wall. In the background, the Berlin skyline is visible against the setting sun, while a road runs alongside the wall toward the horizon. The title &#8220;Legacy Things #4&#8221; appears at the top of the image." srcset="https://substackcdn.com/image/fetch/$s_!uPSv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dded8eb-0431-4954-b884-d0a3c87b8679_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!uPSv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dded8eb-0431-4954-b884-d0a3c87b8679_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!uPSv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dded8eb-0431-4954-b884-d0a3c87b8679_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!uPSv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6dded8eb-0431-4954-b884-d0a3c87b8679_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><span>1987</span></strong><span>. The world still thought in blocs, borders and enclosures. The clearest example was the Cold War between the United States and the Soviet Union.</span></p><p><span>Berlin was its most visible symbol, and the Wall was still standing there to remind everyone of it. On June 12 of that year, the then President of the United States, Ronald Reagan, stood in front of the Brandenburg Gate and spoke a sentence that would remain in history as both a provocation and a hope:</span></p><div><hr></div><p style="text-align: center;"><em><span>&#8220;Mr. Gorbachev, tear down this wall!&#8221;</span></em></p><div><hr></div><p><span>A few months later, on December 8, the United States and the Soviet Union signed the </span><a href="https://en.wikipedia.org/wiki/Intermediate-Range_Nuclear_Forces_Treaty"><span>INF Treaty</span></a><span>, the first concrete sign of a balance that was slowly beginning to crack. Outside, the walls were still there, but somewhere people had already started talking about the future.</span></p><p><span>It was in that strange suspension, between walls still intact and cracks already visible, that an encryption algorithm destined to last for a very long time was born: </span><strong><span>RC4</span></strong><span>.</span></p><p><span>Not as an open standard, not as a common good, but as an industrial secret. In that same year, </span><strong><span>Ron Rivest</span></strong><span>, one of the founders of </span><strong><span>RSA Data Security</span></strong><span>, designed the algorithm as part of RSA&#8217;s proprietary cryptographic library.</span></p><p><span>The acronym is commonly expanded as </span><strong><span>&#8220;Rivest Cipher 4&#8221;</span></strong><span>, although according to </span><strong><span>Ron Rivest</span></strong><span> himself, the letters RC stood for </span><strong><span>&#8220;Ron&#8217;s Code&#8221;</span></strong><span>.</span></p><p><span>When I think about that 1987, though, I cannot hear only geopolitics or the tension of the Cold War. I hear something else too.</span></p><p><span>In the clubs, House music was living its golden age, and I was completely fascinated by it, taking my first steps among vinyl records, mixers and a pair of faithful Technics SL-1210 MK2 turntables. The curious thing is that, just like RC4, the musical technology of that time had been built to last. Even today I can switch on the same system and play the same records without any problem.</span></p><p><span>But speaking of vinyl, if I had to choose one record to frame that historical moment, the first one that comes to mind is </span><strong><span>Promised Land</span></strong><span> by </span><strong><span>Joe Smooth</span></strong><span>. Because while the world outside was still made of separations, inside that sound there was already the opposite idea:</span></p><div><hr></div><p style="text-align: center;"><em><strong><span>&#8220;brothers and sisters, one day we will be free&#8221;</span></strong></em></p><p style="text-align: center;"><em><span>no more division, no more conflict, but the idea that one day we might finally walk in the same direction.</span></em></p><div><hr></div><p><span>Then November 9, 1989, arrived, and the Berlin Wall really fell. What came down with it was not only a concrete barrier, but the very idea that some fences were natural, inevitable or meant to last forever. From that moment on, the change was not only political. It was cultural. It changed the way people looked at borders, at the circulation of ideas, at the assumption that some things should remain closed forever, creating a domino effect that spread everywhere in the following years.</span></p><p><span>Five years later, in </span><strong><span>1994</span></strong><span>, that world had not completely ended yet, but it had already lost its original rigidity. And, in a very Nineties kind of way, RC4 also escaped its enclosure through a leak that gained significant public attention: a description of the algorithm was anonymously posted to the cypherpunks mailing list and then reposted on sci.crypt. The secret stopped being a secret and began to circulate.</span></p><p><span>The story even appeared in TIME with an article titled &#8220;The Secret&#8217;s Out&#8221;. A sign that the leak was no longer only a matter for specialists.</span></p><p><span>But instead of marking its end, that leak opened a second life for RC4: from an industrial secret it became something that could be shared, implemented and discussed more and more widely.</span></p><p><span>Another five years passed and, in </span><strong><span>1999</span></strong><span>, </span><strong><span>Microsoft</span></strong><span> also decided to adopt </span><strong><span>RC4</span></strong><span> as the standard encryption algorithm for its </span><strong><span>Kerberos</span></strong><span> implementation, using it as a compatibility bridge to accompany the transition from existing </span><strong><span>Windows NT</span></strong><span> environments and helping it become one of the pillars of Windows authentication for decades to come.</span></p><p><span>The curious thing is that even then the story was not really considered complete. It would take until </span><strong><span>December 2006</span></strong><span> for this part of its life to be formalized in an RFC, number 4757, documenting the RC4-HMAC encryption types used by Microsoft in Windows.</span></p><p><span>More than ten years after its public disclosure, almost twenty years after its birth. As if bureaucracy, once again, were simply recording something that practice had already accepted long before.</span></p><p><span>And right there, between a secret too good to remain hidden and an idea too useful to disappear at once, the story of its decline truly begins.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.legacythings.it/subscribe?"><span>Iscriviti ora</span></a></p><h2><span>Why RC4 has really reached sunset</span></h2><p><span>Before explaining why RC4 has reached sunset, it is worth remembering why it was so successful in the first place. It did not spread by chance, nor simply because it was available. For the world of the Nineties, it was almost perfect: fast, simple to implement, light for the hardware of the time and flexible enough to fit into very different contexts. It did not require particularly complex structures, worked well in software and could be adopted in protocols that needed to encrypt data streams in a practical way, without making systems and applications too heavy.</span></p><p><span>That is why it ended up almost everywhere: in the early versions of SSL and TLS, in Wi-Fi networks with WEP, then WPA and TKIP, and finally, as we have already seen, inside Kerberos in Windows environments. In other words, RC4 was not just an algorithm: it was a practical answer to a very concrete problem, bringing some encryption into a world that was becoming more and more connected, but still could not afford to change everything at once.</span></p><p><span>So what is really bringing it to an end?</span></p><p><span>RC4 is not leaving the stage because someone suddenly decided it was simply &#8220;old&#8221;. It is leaving because the world that had made it a good idea has changed. For years it was the perfect compromise: solid enough to look modern, flexible enough to accompany systems that needed to evolve without throwing away everything that already existed.</span></p><p><span>The point is that technical compromises age badly when the context stops protecting them. And that is exactly what happened to RC4. Over time, cryptographic weaknesses emerged that became harder to ignore, while attacks around them became more practical, more accessible and better alternatives became available. It is no coincidence that RC4 began to leave the stage in several areas: in </span><strong><span>2015</span></strong><span> the </span><strong><span>IETF</span></strong><span> </span><a href="https://datatracker.ietf.org/doc/html/rfc7465"><span>banned its use in TLS</span></a><span>, in </span><strong><span>2020</span></strong><span> its use in SSH </span><a href="https://www.ietf.org/rfc/rfc8758.html"><span>was formally deprecated</span></a><span>, and in the </span><strong><span>Wi-Fi</span></strong><span> world the industry had long been moving toward </span><strong><span>WPA2</span></strong><span> with </span><strong><span>AES</span></strong><span>, leaving behind the transitional solutions that still relied on the same underlying cipher.</span></p><p><span>This brings us to the Microsoft case, which should not be read as an exception, but as one of the last chapters of a story that had already started elsewhere. In the official post </span><em><a href="https://www.microsoft.com/en-us/windows-server/blog/2025/12/03/beyond-rc4-for-windows-authentication/"><span>Beyond RC4 for Windows authentication</span></a></em><span>, Microsoft openly states that RC4 is susceptible to attacks such as Kerberoasting and that secure Windows authentication no longer needs it, because AES has been available for years on all supported versions. In other words, RC4 does not stop working: it reaches sunset when the present no longer has good reasons to keep using it.</span></p><h2><span>How Microsoft is accompanying RC4 off stage</span></h2><p><span>If we look closely, this story does not begin this year. Microsoft had already started moving the center of gravity away from RC4 at least in </span><strong><span>2022</span></strong><span>, when the updates related to </span><strong><a href="https://support.microsoft.com/en-us/topic/kb5021131-how-to-manage-the-kerberos-protocol-changes-related-to-cve-2022-37966-fd837ac3-cdec-4e76-a6ec-86e67501407d"><span>CVE-2022-37966</span></a></strong><span> made </span><strong><span>AES</span></strong><span> the default for session keys on accounts without explicit settings. It was not the final retirement yet, but the signal was already clear: the old compromise was losing ground. The most recent documentation also recognizes this openly, explaining that the change has already significantly reduced the use of RC4, although without eliminating it completely.</span></p><p><span>2025 and especially 2026, however, change the music. We are no longer around progressive hardening or of a technical detail that almost disappears inside a cumulative update. We are at the point where Microsoft decides to make the direction explicit and to </span><a href="https://support.microsoft.com/en-us/topic/how-to-manage-kerberos-kdc-usage-of-rc4-for-service-account-ticket-issuance-changes-related-to-cve-2026-20833-1ebcda33-720a-4da8-93c1-b0496e1910dc"><span>mark it in very readable phases</span></a><span>: first audit, then a change in default behavior, and finally the end of implicit tolerance. It is as if for years there had been a &#8220;work in progress&#8221; sign at the entrance, and only this year someone had really started closing the road.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_NoL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9fac0a-8af6-4c97-aa87-f17e828af7c3_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_NoL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9fac0a-8af6-4c97-aa87-f17e828af7c3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!_NoL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9fac0a-8af6-4c97-aa87-f17e828af7c3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!_NoL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9fac0a-8af6-4c97-aa87-f17e828af7c3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!_NoL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9fac0a-8af6-4c97-aa87-f17e828af7c3_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_NoL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9fac0a-8af6-4c97-aa87-f17e828af7c3_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9e9fac0a-8af6-4c97-aa87-f17e828af7c3_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3269500,&quot;alt&quot;:&quot;Tropical beach at sunset with four signs along the shoreline showing the milestones 2022 AES default, 2025 Guidance, 2026 Remediation and July 2026 Sunset. Dozens of illuminated floating lanterns labeled RC4 drift toward the horizon across the ocean.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/203923381?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9fac0a-8af6-4c97-aa87-f17e828af7c3_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Tropical beach at sunset with four signs along the shoreline showing the milestones 2022 AES default, 2025 Guidance, 2026 Remediation and July 2026 Sunset. Dozens of illuminated floating lanterns labeled RC4 drift toward the horizon across the ocean." title="Tropical beach at sunset with four signs along the shoreline showing the milestones 2022 AES default, 2025 Guidance, 2026 Remediation and July 2026 Sunset. Dozens of illuminated floating lanterns labeled RC4 drift toward the horizon across the ocean." srcset="https://substackcdn.com/image/fetch/$s_!_NoL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9fac0a-8af6-4c97-aa87-f17e828af7c3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!_NoL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9fac0a-8af6-4c97-aa87-f17e828af7c3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!_NoL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9fac0a-8af6-4c97-aa87-f17e828af7c3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!_NoL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9fac0a-8af6-4c97-aa87-f17e828af7c3_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">RC4 is not disappearing. We are simply accompanying it into the sunset.</figcaption></figure></div><p><span>At that point, the turning point becomes </span><strong><span>July 2026</span></strong><span>. Because that is when the timeline stops being a sequence of warnings and becomes a real deadline. </span><strong><span>KB5073381</span></strong><span> says that the updates released in that period will programmatically enable the </span><strong><span>Enforcement Phase</span></strong><span>; the operating procedure we are using in the field translates it even more clearly: no comfortable rollback, no return to the past by inertia, no implicit fallback left there to protect what no one has yet put in order. From that moment on, RC4 continues to live only where someone has kept it explicitly, account by account, exception by exception.</span></p><p><span>And this is exactly where things become interesting. Microsoft provides official tools to address the problem: more visibility in the logs, guidance on how to detect and remediate RC4 usage, and PowerShell auditing scripts referenced in the official documentation. But the reality is that these tools, on their own, risk returning a very noisy picture.</span></p><p><span>Microsoft&#8217;s own documentation explains that RC4 can still appear for different reasons: legacy systems, accounts without explicit settings, incomplete configurations. And field experience adds an even more concrete detail: raw large numbers can be misleading, the absence of detected RC4 traffic is not always conclusive, and some categories, such as accounts &#8220;without AES keys&#8221; read too superficially, risk making the problem look larger than it really is.</span></p><p><span>That is why the next step cannot be only technical. The approach must be broad, yes, but above all pragmatic: wide enough not to miss the weak signals, lucid enough not to be overwhelmed by background noise.</span></p><p><span>Because in enterprise systems the past almost never presents itself in an orderly way. It hides in habits, inherited settings, defaults left there for years, behaviours that seem normal only because no one had looked at them closely anymore.</span></p><p><span>And that is where we need to start, if we really want to reach the key knots and begin untangling the thread.</span></p><h2><span>What is emerging from the analyses we are doing</span></h2><p><span>When you move from theory to real systems, the matter immediately stops looking linear. On paper, the problem may almost seem trivial: Microsoft changes a default, RC4 leaves the stage, and whoever is left behind adapts.</span></p><p><span>More than once, I have heard sentences like: &#8220;I am pretty sure this will not impact us&#8221;. And every time I wondered where all that certainty came from.</span></p><p><span>In practice, enterprise systems never think that cleanly. They think through habits, layers, inherited settings that keep producing effects long after everyone has forgotten why they were put there in the first place. And it is precisely in this gray area that RC4 continues to leave traces.</span></p><p><span>Looking at the data emerging in the field, the first thing you understand is that raw numbers only help up to a point.</span></p><p><span>Starting from the big picture, the view almost always narrows around the same sensitive points. Not so much the large indistinct volumes, but a handful of service accounts with SPNs, historical passwords that were never rotated, some non-Windows or not clearly AES capable systems, and all those pieces of infrastructure that have been living quietly for years precisely because no one had a reason to touch them anymore.</span></p><p><span>Around them, hundreds or thousands of user and computer objects that can be handled with a pragmatic approach, but that tend to hide the focal knots from view.</span></p><p><span>In the reports we are producing, the logic often comes back to the same point: the real work is not in the big numbers that look impressive in a table, but in a few objects that still hold heavy and poorly visible dependencies together.</span></p><p><span>Then there is another aspect, perhaps the most insidious one: the absence of strong evidence does not automatically mean the absence of problems.</span></p><p><span>In more than one case, event collection turned out to be limited or partial, and the recommendation is to set a sufficiently wide audit window when the available data is not enough to close the picture.</span></p><p><span>Here too the usual paradox of legacy systems comes back: the past does not make noise when it is truly present. In fact, it often stays quiet until someone decides to look more carefully.</span></p><p><span>That is why, the further we move on, the clearer the point seems to me: addressing RC4 does not simply mean &#8220;looking for where it appears&#8221; and turning it off everywhere. It means reading systems through a lens wide enough not to lose context, but pragmatic enough to identify the knots that really matter.</span></p><p><span>There is no need to chase every reflection. What matters is understanding which signals lead to real dependencies, which ones are only background noise, and where it makes sense to intervene without being swallowed by the tangle.</span></p><p><span>And this is exactly where field experience becomes vital: because in legacy systems, the problem is rarely where you see it immediately. More often, it is where no one thought they still needed to look.</span></p><h3><span>Practical notes from the field</span></h3><p><span>At this point it is worth going down one more level. Because data helps, but concrete examples are what make it clear where the past is still carrying weight. In this case I asked my colleague </span><strong><a href="https://www.linkedin.com/in/mattiagrandi"><span>Mattia Grandi</span></a></strong><span> for help, and he summarized the most technical aspects well in </span><a href="https://www.mgworkplace.it/field-guides/rc4-deprecation-active-directory"><span>his article</span></a><span>.</span></p><p><span>Speaking of emblematic cases, the first one that comes to mind is </span><strong><span>Kemp Loadmaster</span></strong><span>, very often used for republishing with </span><strong><span>Kerberos Constrained Delegation</span></strong><span>, or KCD.</span></p><p><span>This is one of those cases where the Kerberos implementation is not Windows native. Therefore, the algorithm change must be handled with care, clearly identifying the operating sequence and a dedicated maintenance window. It is a common pattern in third party Kerberos implementations.</span></p><p><span>Looking then &#8220;toward the cloud&#8221;, we may have to deal with the historical </span><strong><span>AZUREADSSOACC$</span></strong><span> account, used by the </span><strong><span>Seamless Single Sign-On</span></strong><span> feature for </span><strong><span>Entra ID</span></strong><span>.</span></p><p><span>It is a classic example of a cloud driven implementation that, precisely because it was born with a historical default on RC4, now shows all the limits of that choice.</span></p><p><span>We must also remember that Kerberos, by its nature, is not confined to a single domain, but often crosses boundaries through </span><strong><span>Trusts</span></strong><span>.</span></p><p><span>These too are just as sensitive to the algorithm that has been configured for them: if I have a Trust that does not support AES, or that does not have AES configured, the closure of RC4 will &#8220;break&#8221; it as if it were any ordinary PC, but with much broader effects.</span></p><p><span>Finally, let us talk about </span><strong><span>legacy systems</span></strong><span>, whether they are </span><strong><span>Windows Server 2003</span></strong><span> machines that survived the decades or third-party implementations that do not support AES, such as the immortal </span><strong><span>AS/400</span></strong><span> systems.</span></p><p><span>In these cases, it will not always be possible to shut down RC4 cleanly and immediately.</span></p><p><span>Instead, it will be necessary to investigate precisely what Kerberos is actually being used for. This is the only way to manage targeted and conscious exclusions.</span></p><p><span>As you can see, the field of action widens quickly. The risk is not only breaking something, but losing control of the situation or focusing effort where it is not really needed.</span></p><h2><span>What we learned from the sunset of RC4</span></h2><p><span>The first lesson left by the sunset of RC4 is only apparently simple: the most successful technical compromises are also the hardest ones to retire. RC4 survived for so long not because it was perfect, but because for years it was fast, practical, compatible and light enough to become invisible. And when a technology becomes invisible, it stops being discussed long before it stops producing real effects.</span></p><p><span>The second lesson concerns the way we treat the past in enterprise systems. Ignoring it does not make it harmless. It only makes it harder to recognize when it comes back to ask for payment. In the case of RC4, that bill also has a precise date: </span><strong><span>July 2026</span></strong><span>. Anyone who reaches that point still depending on this old compromise will not be facing a mystery, but widely predictable authentication failures.</span></p><p><span>This does not mean approaching the subject ideologically. In real systems there are always exceptions, dependencies, appliances that do not follow the timing of the rest of the infrastructure, systems that are truly not AES capable and integrations that require a slower transition. But precisely because these exceptions exist, they must remain what they are: real exceptions, documented, approved and reviewed. Not a new normal behind which inertia can continue hiding.</span></p><p><span>Because compatibility and inertia are not the same thing. Compatibility is a conscious design choice: it helps a system evolve without breaking it. Inertia, instead, is what remains when that choice stops being governed. It is the default left there for too long, the service account never reviewed, the trust no one touches anymore, the legacy system that keeps working not because it has been understood, but because no one has yet had the courage or the time to look inside it.</span></p><p><span>After all, it is the same thread that runs through all these chapters. The guardian of AdminSDHolder, the trusts created to give shape to trust, the Domain Controller that seemed to lie: every time, the point was not that the system was broken. The point was that the system kept doing what it had been designed to do, while we had lost part of the memory of that design.</span></p><p><strong><span>RC4</span></strong><span> tells the same story from another angle. It is not the monster to erase from history, nor the symbol of a catastrophic mistake. It was a good answer to a problem of its time. Only time, at some point, changes the question. And when the question changes, continuing to give the same answer is no longer compatibility: it is stubbornness.</span></p><p><span>Maybe this is the most important lesson of its sunset: we cannot expect legacy systems to disappear on their own, nor to spontaneously stop influencing the present. We need to look at them, understand them, decide what to preserve and what to accompany off stage. Without nostalgia, but also without arrogance. Because many of the things we call legacy today were, in their moment, excellent solutions.</span></p><p><span>The problem begins when we keep treating them as if the world around them had not changed.</span></p><p><span>RC4 had a long, useful and in some ways surprising life. Now, however, sunset is no longer a metaphor: it is a deadline. And as often happens in enterprise infrastructures, the difference between an orderly transition and an avoidable incident lies entirely in deciding whether to deal with it while there is still light, or wait for the dark.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Legacy Things! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Capitolo #3 - Il Domain Controller che diceva il falso]]></title><description><![CDATA[La fonte autorevole di una verit&#224; distorta]]></description><link>https://www.legacythings.it/p/capitolo-3-il-domain-controller-che</link><guid isPermaLink="false">https://www.legacythings.it/p/capitolo-3-il-domain-controller-che</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Thu, 28 May 2026 07:01:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!OH7c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F059fb944-e706-4bdc-8c1d-1c6d403f6bc8_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>English version available here &#8594;<a href="https://www.legacythings.it/p/chapter-3-the-domain-controller-that"> [EN]</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OH7c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F059fb944-e706-4bdc-8c1d-1c6d403f6bc8_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OH7c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F059fb944-e706-4bdc-8c1d-1c6d403f6bc8_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!OH7c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F059fb944-e706-4bdc-8c1d-1c6d403f6bc8_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!OH7c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F059fb944-e706-4bdc-8c1d-1c6d403f6bc8_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!OH7c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F059fb944-e706-4bdc-8c1d-1c6d403f6bc8_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OH7c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F059fb944-e706-4bdc-8c1d-1c6d403f6bc8_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/059fb944-e706-4bdc-8c1d-1c6d403f6bc8_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4701061,&quot;alt&quot;:&quot;Illustrazione concettuale sul tema della verit&#224; distorta e delle fonti autorevoli nel troubleshooting.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/199052394?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F059fb944-e706-4bdc-8c1d-1c6d403f6bc8_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustrazione concettuale sul tema della verit&#224; distorta e delle fonti autorevoli nel troubleshooting." title="Illustrazione concettuale sul tema della verit&#224; distorta e delle fonti autorevoli nel troubleshooting." srcset="https://substackcdn.com/image/fetch/$s_!OH7c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F059fb944-e706-4bdc-8c1d-1c6d403f6bc8_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!OH7c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F059fb944-e706-4bdc-8c1d-1c6d403f6bc8_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!OH7c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F059fb944-e706-4bdc-8c1d-1c6d403f6bc8_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!OH7c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F059fb944-e706-4bdc-8c1d-1c6d403f6bc8_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Estate 1998</strong>, primo vero lavoro: sottomano mi passano centinaia di Motorola 8700, il telefono con il flip che tutti volevano. Nel giro di poco riesco a connettere i sistemi in un dominio Windows NT, trasformando il modo di lavorare disconnesso degli operatori in qualcosa di moderno.</p><p>Fuori da quella stanza, il mondo stava vivendo un&#8217;estate intensa.</p><p>Nelle sale italiane <strong>The Truman Show</strong> teneva banco: un uomo che viveva una vita perfetta, ignaro del fatto che ogni dettaglio intorno a lui era costruito a tavolino. Una realt&#224; impeccabile nella forma, falsa nella sostanza. Nei <strong>Mondiali di calcio in Francia</strong> si consumava invece un altro piccolo mistero: si diceva che il sorteggio del girone, presieduto da <strong>Platini</strong>, non fosse poi cos&#236; casuale come appariva. La distinta ufficiale parlava chiaro, i numeri erano l&#236; a disposizione, eppure il risultato sembrava scritto prima ancora di iniziare. Qualcosa non tornava e l&#8217;ammissione arriver&#224; solo 20 anni dopo. E mentre i ragazzi consumavano le ore su <strong>FIFA Road to World Cup 98</strong> con <strong>Song 2</strong> dei <strong>Blur</strong> nelle orecchie, dall&#8217;altra parte dell&#8217;Atlantico <strong>Bill Clinton,</strong> a gennaio, guardava dritto in camera e dichiarava al mondo intero di non aver avuto alcuna relazione con <strong>Monica Lewinsky</strong>. Verr&#224; smentito il 17 agosto.</p><p>Tre storie diverse, un unico filo: una fonte attendibile che restituisce <em><strong>una risposta che non corrisponde alla realt&#224;</strong></em>.</p><p>In quegli stessi giorni, in un datacenter Microsoft, veniva rilasciato silenziosamente Windows NT 4.0 Terminal Server Edition, nome in codice <strong>Hydra</strong>. Con lui nasceva quello che tutti avrebbero chiamato <strong>Terminal Services</strong>, e che il mondo conosce oggi come <strong>RDP</strong>.</p><p>Quasi ventisette anni dopo, su un sistema protetto da una delle piattaforme di sicurezza pi&#249; avanzate al mondo, un utente prova ad aprire una sessione RDP e si trova davanti un messaggio inequivocabile: <strong>&#8220;A user account restriction is preventing you from logging on.&#8221;</strong></p><p>Il Domain Controller ha parlato, l&#8217;IP &#232; quello giusto, la fonte &#232; attendibile.</p><p>Eppure anche qui, qualcosa non tornava.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.legacythings.it/subscribe?"><span>Iscriviti ora</span></a></p><h2>Lo scenario</h2><p>A differenza dei capitoli precedenti, in questo articolo non parleremo della tecnologia in s&#233;, il protocollo RDP &#232; solamente l&#8217;innesco di una situazione pi&#249; intrecciata, per questo motivo andremo invece ad approfondire lo specifico scenario che si &#232; rivelato essere molto interessante.</p><p>Iniziamo descrivendo il contesto che, a una prima occhiata, non ha legami con tecnologie cloud, risulta essere molto comune, quasi banale.</p><p>&#200; uno di quegli ambienti che chi lavora con Active Directory incontra spesso, soprattutto nel mondo enterprise:</p><p>Una filiale italiana di una multinazionale, forte focus <strong>on&#8209;premise</strong>, con un&#8217;infrastruttura Active Directory stratificata nel tempo. Le linee guida arrivano dall&#8217;HQ.<br>Un <strong>child domain</strong>, eredit&#224; di una riorganizzazione avvenuta anni prima, e una manciata di <strong>Domain Controller distribuiti su pi&#249; siti</strong>: alcuni fisicamente in sede, altri ospitati su infrastruttura cloud, integrati nel disegno come semplice estensione del perimetro aziendale.</p><p>Niente di particolare. Niente che, sulla carta, faccia pensare a problemi imminenti.</p><p>Sembra quasi l&#8217;incipit di &#8220;<em>Un giorno di ordinaria follia</em>&#8221;, ma quello &#232; un altro film&#8230;</p><p>Da anni, per le attivit&#224; operative quotidiane sull&#8217;applicativo <em><strong>XYZ</strong></em>, viene utilizzato un <strong>account amministrativo generico</strong>, condiviso tra pi&#249; persone: <em><strong>XYZ-admin</strong></em>.<br>Una scelta che oggi farebbe storcere il naso a chiunque parli di Identity governance o Zero Trust, ma che nel tempo aveva sempre fatto il suo lavoro e per la logica del <em>&#8220;funziona = non si tocca&#8221; </em>&#232; rimasto come eredit&#224;.<br>Accessi RDP, attivit&#224; di manutenzione, interventi urgenti: tutto &#232; passato di l&#236; per anni, senza intoppi.</p><p>Finch&#233;, un giorno, <strong>smette di funzionare</strong>.</p><p>Non gradualmente. Non &#8220;a volte s&#236;, a volte no&#8221;. Improvvisamente non si accede pi&#249;.</p><p>Ogni tentativo di accesso RDP con quell&#8217;account restituisce lo stesso risultato:</p><p><em><strong>&#8220;A user account restriction is preventing you from logging on.&#8221;</strong></em></p><p>Nessun cambiamento apparente, nessuna modifica dichiarata, nessun alert che indichi cosa stia succedendo.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gHN2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a497d5a-e2f9-44b6-ac11-f92d5a2eb46f_603x401.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gHN2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a497d5a-e2f9-44b6-ac11-f92d5a2eb46f_603x401.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gHN2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a497d5a-e2f9-44b6-ac11-f92d5a2eb46f_603x401.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gHN2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a497d5a-e2f9-44b6-ac11-f92d5a2eb46f_603x401.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gHN2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a497d5a-e2f9-44b6-ac11-f92d5a2eb46f_603x401.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gHN2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a497d5a-e2f9-44b6-ac11-f92d5a2eb46f_603x401.jpeg" width="603" height="401" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3a497d5a-e2f9-44b6-ac11-f92d5a2eb46f_603x401.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:401,&quot;width&quot;:603,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31781,&quot;alt&quot;:&quot;Schermata di errore RDP con il messaggio &#8220;A user account restriction is preventing you from logging on.&#8221;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/199052394?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a497d5a-e2f9-44b6-ac11-f92d5a2eb46f_603x401.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Schermata di errore RDP con il messaggio &#8220;A user account restriction is preventing you from logging on.&#8221;" title="Schermata di errore RDP con il messaggio &#8220;A user account restriction is preventing you from logging on.&#8221;" srcset="https://substackcdn.com/image/fetch/$s_!gHN2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a497d5a-e2f9-44b6-ac11-f92d5a2eb46f_603x401.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gHN2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a497d5a-e2f9-44b6-ac11-f92d5a2eb46f_603x401.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gHN2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a497d5a-e2f9-44b6-ac11-f92d5a2eb46f_603x401.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gHN2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a497d5a-e2f9-44b6-ac11-f92d5a2eb46f_603x401.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Un errore RDP apparentemente chiaro pu&#242; essere solo il primo livello del problema.</strong></figcaption></figure></div><p>La problematica scala al personale IT del cliente che inizia un primo troubleshooting. Il primo istinto &#232; quello pi&#249; naturale: <strong>provare a cambiare Domain Controller</strong>.<br>Forzare l&#8217;autenticazione verso DC diversi, magari su site differenti, per escludere un problema puntuale.<br>Ma il risultato non cambia, stessa risposta, stesso errore.</p><p>Nel frattempo, emerge una coincidenza temporale difficile da ignorare: <strong>nei giorni precedenti &#232; stato eseguito un ciclo di patching sui Domain Controller</strong>.<br>La pista sembra promettente.<br>Il cliente controlla gli aggiornamenti installati, si cercano articoli su internet, si confrontano versioni, si ipotizzano bug diffusi spulciando i forum IT.<br>&#200; una spiegazione logica e rassicurante: qualcosa &#232; cambiato, quindi qualcosa si &#232; &#8220;rotto&#8221;.</p><p>Il problema &#232; che, anche scavando, <strong>non emerge nulla</strong>:</p><p>&#183; Le patch sui DC sono allineate</p><p>&#183; Non ci sono altri utenti che si lamentano di mancato accesso</p><p>&#183; Non ci sono errori evidenti nei log che giustifichino un comportamento cos&#236; selettivo</p><p>A questo punto le idee del cliente iniziano ad esaurirsi.<br>Le ipotesi pi&#249; ovvie sono state esplorate, le verifiche standard eseguite, non sono emerse soluzioni rapide.</p><p>&#200; solo allora che il cliente decide di aprire il ticket verso il nostro supporto.</p><p>Ed &#232; proprio qui che la situazione diventa interessante.</p><h2>L&#8217;analisi</h2><p>La problematica viene quindi assegnata ad uno dei consulenti del mio team, che inizia ad approfondire. Come prima cosa ri-verifica il percorso fatto dal cliente, per la logica del &#8220;fidarsi &#232; bene ma non fidarsi &#232; meglio&#8221;. Nulla di nuovo.</p><p>Passa quindi ad analizzare in dettaglio il messaggio di errore: <em><strong>&#8220;A user account restriction is preventing you from logging on.&#8221;</strong></em></p><p>Le &#8220;<em>user account restriction</em>&#8221; sono impostazioni che arrivano da lontano, dai tempi di <strong>Windows NT 4</strong>, quelle che hanno un effetto diretto sulle sessioni RDP di solito sono: <em>Logon Time Restriction</em> e <em>Workstation Restriction</em>.</p><p>Viene controllato l&#8217;utente ma nessuna traccia di quelle impostazioni, sembra tutto in ordine, idem per le GPO applicate allo stesso.</p><p>Si controllano quindi gli eventi sul <em>Target System</em>, ma anche l&#236; nulla.</p><p>Si cambia quindi prospettiva passando a prove empiriche con altri account, scoprendo comportamenti curiosi:</p><p>&#183; Provando ad accedere in RDP allo stesso server <em><strong>con l&#8217;utente del consulente</strong></em>, l&#8217;accesso <strong>va a buon fine</strong></p><p>&#183; Provando a creare <em><strong>un nuovo utente</strong></em> e ad accedere con questo in RDP, si ottiene lo <strong>stesso errore</strong></p><p>&#183; Provando a usare <em><strong>un Source System differente</strong></em> e l&#8217;utente <em><strong>XYZ-admin </strong></em>l&#8217;accesso <strong>va a buon fine</strong></p><p>Non &#232; quindi una questione di solo utente, ma una combinazione di: <strong>utente + Source System + Target System</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T3kp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9009fb14-ea36-4087-8666-d708df4504cb_541x471.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T3kp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9009fb14-ea36-4087-8666-d708df4504cb_541x471.jpeg 424w, https://substackcdn.com/image/fetch/$s_!T3kp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9009fb14-ea36-4087-8666-d708df4504cb_541x471.jpeg 848w, https://substackcdn.com/image/fetch/$s_!T3kp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9009fb14-ea36-4087-8666-d708df4504cb_541x471.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!T3kp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9009fb14-ea36-4087-8666-d708df4504cb_541x471.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T3kp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9009fb14-ea36-4087-8666-d708df4504cb_541x471.jpeg" width="541" height="471" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9009fb14-ea36-4087-8666-d708df4504cb_541x471.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:471,&quot;width&quot;:541,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:38022,&quot;alt&quot;:&quot;Schema della relazione tra utente, Source System e Target System nel flusso di accesso RDP.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/199052394?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9009fb14-ea36-4087-8666-d708df4504cb_541x471.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Schema della relazione tra utente, Source System e Target System nel flusso di accesso RDP." title="Schema della relazione tra utente, Source System e Target System nel flusso di accesso RDP." srcset="https://substackcdn.com/image/fetch/$s_!T3kp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9009fb14-ea36-4087-8666-d708df4504cb_541x471.jpeg 424w, https://substackcdn.com/image/fetch/$s_!T3kp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9009fb14-ea36-4087-8666-d708df4504cb_541x471.jpeg 848w, https://substackcdn.com/image/fetch/$s_!T3kp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9009fb14-ea36-4087-8666-d708df4504cb_541x471.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!T3kp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9009fb14-ea36-4087-8666-d708df4504cb_541x471.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Quando l&#8217;errore dipende dalla combinazione tra utente, sistema sorgente e sistema di destinazione, il troubleshooting cambia scala.</figcaption></figure></div><p>Anche in questo caso la questione arriva sul mio tavolo per un parere. Iniziamo ad andare a fondo, partendo da quelle che considero <em>le tavole della legge</em> del troubleshooting:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LMAR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16b0071e-3702-4796-903e-9da366d90586_261x340.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LMAR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16b0071e-3702-4796-903e-9da366d90586_261x340.png 424w, https://substackcdn.com/image/fetch/$s_!LMAR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16b0071e-3702-4796-903e-9da366d90586_261x340.png 848w, https://substackcdn.com/image/fetch/$s_!LMAR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16b0071e-3702-4796-903e-9da366d90586_261x340.png 1272w, https://substackcdn.com/image/fetch/$s_!LMAR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16b0071e-3702-4796-903e-9da366d90586_261x340.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LMAR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16b0071e-3702-4796-903e-9da366d90586_261x340.png" width="261" height="340" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/16b0071e-3702-4796-903e-9da366d90586_261x340.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:340,&quot;width&quot;:261,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:170762,&quot;alt&quot;:&quot;Immagine simbolica delle tavole della legge usata come metafora del metodo di troubleshooting.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/199052394?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16b0071e-3702-4796-903e-9da366d90586_261x340.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Immagine simbolica delle tavole della legge usata come metafora del metodo di troubleshooting." title="Immagine simbolica delle tavole della legge usata come metafora del metodo di troubleshooting." srcset="https://substackcdn.com/image/fetch/$s_!LMAR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16b0071e-3702-4796-903e-9da366d90586_261x340.png 424w, https://substackcdn.com/image/fetch/$s_!LMAR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16b0071e-3702-4796-903e-9da366d90586_261x340.png 848w, https://substackcdn.com/image/fetch/$s_!LMAR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16b0071e-3702-4796-903e-9da366d90586_261x340.png 1272w, https://substackcdn.com/image/fetch/$s_!LMAR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16b0071e-3702-4796-903e-9da366d90586_261x340.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Le tavole della legge del troubleshooting</figcaption></figure></div><p>Si passa quindi a fare una traccia di rete sul Source System, iniziando a scoprire cose interessanti:</p><p>&#183; La sessione RDP non arriva a dialogare con il <em>Target System</em>, il blocco avviene prima</p><p>&#183; Viene individuata la corrispondenza con il messaggio di errore:</p><blockquote><p>o Il <em>Source System</em> inizia una sessione RDP verso il <em>Target System</em></p><p>o il <em>Source System</em> dialoga quindi con un <em>Domain Controller</em> chiedendo autorizzazione all&#8217;accesso <strong>RDP</strong> per l&#8217;utente <em>XYZ-admin@domain.xyz </em>verso il<em> Target System</em></p><p>o A quel punto il <em>Domain Controller</em> risponde con un errore Kerberos: <strong>KDC_ERR_POLICY</strong></p></blockquote><p>&#183; Quando la connessione avviene dal <em>Source System 2</em>, non vi &#232; traccia dell&#8217;errore Kerberos</p><p>&#183; Quando la connessione avviene dal <em>Source System</em>, ma con l&#8217;utente del consulente non si ottiene alcun errore Kerberos</p><p>Si passa quindi a verificare cosa succede sul <em>Domain Controller</em> in questione, analizzandone i log in dettaglio. Qui succede una cosa incomprensibile: viene tracciato un evento che corrisponde in maniera precisa, per data, ora e ambito, a quello presente nella traccia di rete, peccato che abbia esito affermativo: <em><strong>&#232; un&#8217;autorizzazione lecita all&#8217;accesso!</strong></em></p><p>Il <em>Domain Controller</em> &#232; quindi convinto di aver rilasciato un <strong>OK</strong>, mentre il <em>Source System</em> riceve in risposta un <strong>KO</strong>. Chi o cosa nel mezzo sta mentendo???</p><p>L&#8217;analisi prosegue e facendo altre tracce di rete si scoprono altre cose curiose:</p><p>&#183; Tutte le chiamate che vanno a buon fine dal <em>Source System 2</em> richiedono <em>sempre autorizzazione ad uno specifico <strong>Domain Controller.</strong></em></p><p>&#183; Tutte le chiamate che vanno in errore dal <em>Source System</em> non chiedono mai autorizzazione al Domain Controller con cui dialoga il <em>Source System 2</em>, anzi <em>vengono contattati <strong>Domain Controller</strong> a caso nel mondo.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lJKl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e2ebdb4-5847-425d-a592-82b4628b4287_602x365.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lJKl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e2ebdb4-5847-425d-a592-82b4628b4287_602x365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lJKl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e2ebdb4-5847-425d-a592-82b4628b4287_602x365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lJKl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e2ebdb4-5847-425d-a592-82b4628b4287_602x365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lJKl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e2ebdb4-5847-425d-a592-82b4628b4287_602x365.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lJKl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e2ebdb4-5847-425d-a592-82b4628b4287_602x365.jpeg" width="602" height="365" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0e2ebdb4-5847-425d-a592-82b4628b4287_602x365.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:365,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42098,&quot;alt&quot;:&quot;Schema dei Domain Controller contattati dai sistemi sorgente, con differenze tra percorso corretto e percorso in errore.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/199052394?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e2ebdb4-5847-425d-a592-82b4628b4287_602x365.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Schema dei Domain Controller contattati dai sistemi sorgente, con differenze tra percorso corretto e percorso in errore." title="Schema dei Domain Controller contattati dai sistemi sorgente, con differenze tra percorso corretto e percorso in errore." srcset="https://substackcdn.com/image/fetch/$s_!lJKl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e2ebdb4-5847-425d-a592-82b4628b4287_602x365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lJKl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e2ebdb4-5847-425d-a592-82b4628b4287_602x365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lJKl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e2ebdb4-5847-425d-a592-82b4628b4287_602x365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lJKl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e2ebdb4-5847-425d-a592-82b4628b4287_602x365.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">La differenza tra successo ed errore era nascosta nel percorso verso il Domain Controller &#8220;giusto&#8221;.</figcaption></figure></div><p>Abbiamo quindi identificato la sequenza di errore ma la causa non &#232; ancora chiara, anzi le prove non fanno altro che confondere le idee.</p><p>Con la convinzione che &#8220;ci sia qualcosa nel mezzo&#8221;, supportata dal mancato dialogo con l&#8217;unico <em>Domain Controller</em> &#8220;buono&#8221;, si torna ad indagare sulla rete aprendo questa volta un ticket al supporto network di HQ.</p><p>Rimangono comunque dubbi sul come mai l&#8217;account del consulente funzioni regolarmente.</p><p>Passa qualche giorno e da HQ arriva un messaggio interessante: <em>ho sistemato l&#8217;account, riprovate adesso.</em></p><p>Aspetta&#8230; come &#8220;ho sistemato l&#8217;account&#8221;, qual &#232; la spiegazione con tutto questo?</p><p>Ad ogni modo si procede con un nuovo test e, meraviglia, tutto funziona!</p><p>Vengono quindi richiesti maggiori chiarimenti, dopo tutta questa fatica abbiamo bisogno di capire.</p><p>La risposta &#232; disarmante: &#232; colpa di <strong>CrowdStrike</strong>, che aveva marcato l&#8217;utente come &#8220;non umano&#8221;.</p><p>Quindi avevamo ragione, c&#8217;era veramente qualcosa nel mezzo! Solo che nessuno aveva visibilit&#224; su cosa.</p><p>Ma andiamo con ordine e ricostruiamo quello che &#232; successo, perch&#233; &#232; una di quelle situazioni interessanti dove il caos e le incomprensioni la fanno da padrona:</p><p>&#183; CrowdStrike ha un modulo che si chiama &#8220;<a href="https://www.crowdstrike.com/products/identity-protection/">Identity Protection</a>&#8221;</p><p>&#183; HQ ha distribuito l&#8217;agente di CrowdStrike sui Domain Controller, tutti tranne quello con cui parlava <em>Source System 2</em></p><p>&#183; CrowdStrike ha fatto una scansione e ha identificato XYZ-admin come Non-Human Identity</p><p>&#183; L&#8217;agente sui Domain Controller ha preso il controllo delle risposte Kerberos, modificandole in corsa secondo i propri parametri</p><p>&#183; I Domain Controller erano quindi convinti di avere risposto OK, ma l&#8217;agente lo convertiva in KO</p><p>&#183; A complicare tutto c&#8217;&#232; stato effettivamente un problema di rete, il Source System aveva la strada bloccata verso il Domain Controller &#8220;buono&#8221; ottenendo un regolare KO per le sessioni RDP di XYZ-admin</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zK5z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37382298-2bb8-4573-918f-403bcceaef24_602x365.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zK5z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37382298-2bb8-4573-918f-403bcceaef24_602x365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zK5z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37382298-2bb8-4573-918f-403bcceaef24_602x365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zK5z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37382298-2bb8-4573-918f-403bcceaef24_602x365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zK5z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37382298-2bb8-4573-918f-403bcceaef24_602x365.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zK5z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37382298-2bb8-4573-918f-403bcceaef24_602x365.jpeg" width="602" height="365" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/37382298-2bb8-4573-918f-403bcceaef24_602x365.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:365,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:47638,&quot;alt&quot;:&quot;Schema finale del caso con interazione tra rete, Domain Controller, Kerberos e controllo delle risposte da parte dell&#8217;agente.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/199052394?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37382298-2bb8-4573-918f-403bcceaef24_602x365.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Schema finale del caso con interazione tra rete, Domain Controller, Kerberos e controllo delle risposte da parte dell&#8217;agente." title="Schema finale del caso con interazione tra rete, Domain Controller, Kerberos e controllo delle risposte da parte dell&#8217;agente." srcset="https://substackcdn.com/image/fetch/$s_!zK5z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37382298-2bb8-4573-918f-403bcceaef24_602x365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zK5z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37382298-2bb8-4573-918f-403bcceaef24_602x365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zK5z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37382298-2bb8-4573-918f-403bcceaef24_602x365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zK5z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37382298-2bb8-4573-918f-403bcceaef24_602x365.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">La verit&#224; era nel mezzo: rete, Kerberos e controllo delle risposte si erano intrecciati nello stesso errore.</figcaption></figure></div><p>La cosa che pi&#249; mi ha colpito di questo strano caso &#232; questa: siamo di fronte ad una tecnologia Cloud moderna (<strong>CrowdStrike</strong>) che governa tecnologie legacy senza tenere conto dei reali effetti sulle stesse, generando comportamenti strani ed errori fuorvianti.</p><p>Entra inoltre nell&#8217;equazione il concetto di <strong>Non-Human Identity</strong>, che ha radici profonde negli ambienti legacy, ma &#232; diventato attualissimo sotto la spinta dei sistemi <strong>AI</strong>.</p><p>E per la cronaca, il povero Domain Controller non aveva colpe: lui la verit&#224; stava provando a dirla veramente&#8230;</p><h2>Cosa ci ha insegnato</h2><p>La prima lezione che questo caso ci lascia &#232; semplice solo in apparenza: anche le fonti pi&#249; autorevoli possono raccontare una verit&#224; distorta. E dietro non c&#8217;&#232; sempre un bug o una cattiva configurazione, ma spesso c&#8217;&#232; il fatto che il contesto in cui operano &#232; cambiato, mentre loro continuano a svolgere il proprio lavoro con coerenza implacabile.</p><p>Il povero Domain Controller non era guasto o &#8220;bugiardo&#8221;.<br>Stava facendo il proprio mestiere rispondendo con sicurezza.<br>Eppure la risposta che arrivava non era quella utile. Era formalmente corretta, sostanzialmente sbagliata.</p><p>La seconda lezione riguarda il modo in cui interpretiamo gli errori.<br>Messaggi fuorvianti, log senza errori, comportamenti incoerenti tra sistemi identici: il troubleshooting moderno a volte non offre indizi diretti. I meccanismi legacy si intrecciano con livelli di protezione sempre pi&#249; sofisticati e &#8220;governati dall&#8217;alto&#8221;, creando scenari in cui ogni pezzo della catena sembra funzionare&#8230; ma il risultato continua a non tornare.</p><p>Infine, riagganciandoci al <a href="https://www.legacythings.it/p/capitolo-2-una-questione-di-fiducia?r=7oz2wp">capitolo 2</a>, c&#8217;&#232; un insegnamento pi&#249; grande: <strong>la fiducia nel sistema</strong> &#232; spesso data per scontata.<br>Ci fidiamo del Domain Controller, del DNS, del network, degli agent, dei layer di protezione cloud. Ma ogni elemento introduce il proprio modello di verit&#224;, costruito nel proprio perimetro. Quando questi modelli non sono allineati o non dialogano tra di loro in maniera coerente, ci&#242; che riceviamo non &#232; un errore esplicito, ma una risposta &#8220;corretta&#8221; che non rappresenta pi&#249; la realt&#224;.</p><p>E questo vale non solo per gli account umani.<br>Sempre pi&#249; spesso, nelle infrastrutture moderne, le identit&#224; realmente critiche non sono quelle delle persone, ma quelle dei processi, dei servizi, dei connettori, dei job schedulati. Le <strong>Non&#8209;Human Identities</strong> operano sottotraccia, con privilegi spesso invisibili, e prendono decisioni in autonomia. Sarebbe ingenuo pensare che non possano incappare negli stessi paradossi, o crearne di nuovi.<br><a href="https://www.microsoft.com/en-us/security/business/security-101/what-are-non-human-identities">What Are Non-human Identities? | Microsoft Security</a></p><p>Per ora, la lezione resta chiara:<br>nei sistemi complessi la verit&#224; non sparisce in maniera netta. Si nasconde in silenzio, finch&#233; qualcuno non decide di guardare nel posto giusto.</p><p>Questo capitolo &#232; per <strong>Denys</strong>, che ha trovato la verit&#224; nel posto giusto. Spero che anche ora sia nel posto giusto.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Grazie per aver letto Legacy Things! Iscriviti gratuitamente per supportare il mio lavoro.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p></p>]]></content:encoded></item><item><title><![CDATA[Chapter #3 - The Domain Controller That Lied]]></title><description><![CDATA[The authoritative source of a distorted truth]]></description><link>https://www.legacythings.it/p/chapter-3-the-domain-controller-that</link><guid isPermaLink="false">https://www.legacythings.it/p/chapter-3-the-domain-controller-that</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Thu, 28 May 2026 06:50:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZXrJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f42e45c-b9be-4d34-869e-555d448405bb_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Versione italiana disponibile qui &#8594;</em><a href="https://www.legacythings.it/p/capitolo-1-adminsdholder-il-guardiano"> </a><em><a href="https://www.legacythings.it/p/capitolo-3-il-domain-controller-che">[IT]</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZXrJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f42e45c-b9be-4d34-869e-555d448405bb_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZXrJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f42e45c-b9be-4d34-869e-555d448405bb_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ZXrJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f42e45c-b9be-4d34-869e-555d448405bb_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ZXrJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f42e45c-b9be-4d34-869e-555d448405bb_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ZXrJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f42e45c-b9be-4d34-869e-555d448405bb_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZXrJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f42e45c-b9be-4d34-869e-555d448405bb_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f42e45c-b9be-4d34-869e-555d448405bb_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4701061,&quot;alt&quot;:&quot;Conceptual illustration about distorted truth and authoritative sources in troubleshooting.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/199053556?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f42e45c-b9be-4d34-869e-555d448405bb_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Conceptual illustration about distorted truth and authoritative sources in troubleshooting." title="Conceptual illustration about distorted truth and authoritative sources in troubleshooting." srcset="https://substackcdn.com/image/fetch/$s_!ZXrJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f42e45c-b9be-4d34-869e-555d448405bb_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ZXrJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f42e45c-b9be-4d34-869e-555d448405bb_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ZXrJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f42e45c-b9be-4d34-869e-555d448405bb_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ZXrJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f42e45c-b9be-4d34-869e-555d448405bb_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Summer 1998</strong>, my first real job: I find myself handling hundreds of Motorola 8700s, the flip phone everybody wanted. Before long, I manage to connect the systems into a Windows NT domain, transforming the operators&#8217; disconnected way of working into something modern.</p><p>Outside that room, the world was living through an intense summer.</p><p>In Italian cinemas, <strong>The Truman Show</strong> was all anyone talked about: a man living a perfect life, unaware that every detail around him had been carefully constructed. A reality flawless in form, false in substance. In the <strong>1998 World Cup in France</strong>, another small mystery was unfolding: people said the group-stage draw, presided over by <strong>Platini</strong>, was not as random as it looked. The official sheet was crystal clear, the numbers were there for everyone to see, and yet the outcome seemed written before it had even begun. Something did not add up, and the admission would only come 20 years later. And while kids were spending hours playing <strong>FIFA Road to World Cup 98</strong> with <strong>Song 2</strong> by <strong>Blur</strong> in their ears, on the other side of the Atlantic <strong>Bill Clinton</strong>, in January, looked straight into the camera and told the whole world that he had not had any relationship with <strong>Monica Lewinsky</strong>. He would be contradicted on August 17.</p><p>Three different stories, one common thread: a trustworthy source returning <em><strong>an answer that does not match reality.</strong></em></p><p>In those same days, in a Microsoft datacenter, Windows NT 4.0 Terminal Server Edition, codenamed <strong>Hydra</strong>, was quietly released. With it, what everyone would later call <strong>Terminal Services</strong> was born, and what the world now knows as <strong>RDP</strong>.</p><p>Almost twenty seven years later, on a system protected by one of the most advanced security platforms in the world, a user tries to open an RDP session and is met with an unmistakable message: <strong>&#8220;A user account restriction is preventing you from logging on.&#8221;</strong></p><p>The Domain Controller has spoken, the IP is the right one, the source is trustworthy.</p><p>And yet here too, something did not add up.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.legacythings.it/subscribe?"><span>Iscriviti ora</span></a></p><h2>The scenario</h2><p>Unlike the previous chapters, in this article we will not be talking about the technology itself, the RDP protocol is only the trigger for a more tangled situation, which is why we will instead dig into the specific scenario, one that turned out to be very interesting.</p><p>Let us begin by describing the context which, at first glance, has no connection with cloud technologies and appears to be very common, almost ordinary.</p><p>It is one of those environments that anyone working with Active Directory encounters often, especially in the enterprise world:</p><p>An Italian branch of a multinational company, with a strong <strong>on premises</strong> focus, and an Active Directory infrastructure layered over time. The guidelines come from HQ.<br>A <strong>child domain</strong>, inherited from a reorganization that took place years earlier, and a handful of <strong>Domain Controllers distributed across multiple sites</strong>: some physically on premises, others hosted on cloud infrastructure, integrated into the design as a simple extension of the corporate perimeter.</p><p>Nothing unusual. Nothing that, on paper, would suggest imminent problems.</p><p>It almost sounds like the opening of <em>Falling Down</em>, but that is another film entirely&#8230;</p><p>For years, the daily operational work on the <em><strong>XYZ</strong></em> application had been carried out using a shared <strong>generic administrative account</strong>: <em><strong>XYZ-admin</strong></em>.<br>A choice that today would make anyone who talks about Identity governance or Zero Trust wince, but which had always done its job over time and, by the logic of <em>&#8220;if it works, do not touch it&#8221;</em>, remained there as a legacy inheritance.<br>RDP access, maintenance activities, urgent interventions: everything had gone through that account for years, without issues.</p><p>Until one day, <strong>it stops working</strong>.</p><p>Not gradually. Not &#8220;sometimes yes, sometimes no&#8221;. Suddenly, access is gone.</p><p>Every RDP logon attempt with that account returns the same result:</p><p><em><strong>&#8220;A user account restriction is preventing you from logging on.&#8221;</strong></em></p><p>No apparent change, no declared modification, no alert explaining what is happening.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0LaC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F536dbed8-40fe-462d-99c1-e614391ff3e5_603x401.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0LaC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F536dbed8-40fe-462d-99c1-e614391ff3e5_603x401.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0LaC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F536dbed8-40fe-462d-99c1-e614391ff3e5_603x401.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0LaC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F536dbed8-40fe-462d-99c1-e614391ff3e5_603x401.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0LaC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F536dbed8-40fe-462d-99c1-e614391ff3e5_603x401.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0LaC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F536dbed8-40fe-462d-99c1-e614391ff3e5_603x401.jpeg" width="603" height="401" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/536dbed8-40fe-462d-99c1-e614391ff3e5_603x401.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:401,&quot;width&quot;:603,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31781,&quot;alt&quot;:&quot;RDP error screen showing the message &#8220;A user account restriction is preventing you from logging on.&#8221;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/199053556?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F536dbed8-40fe-462d-99c1-e614391ff3e5_603x401.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="RDP error screen showing the message &#8220;A user account restriction is preventing you from logging on.&#8221;" title="RDP error screen showing the message &#8220;A user account restriction is preventing you from logging on.&#8221;" srcset="https://substackcdn.com/image/fetch/$s_!0LaC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F536dbed8-40fe-462d-99c1-e614391ff3e5_603x401.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0LaC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F536dbed8-40fe-462d-99c1-e614391ff3e5_603x401.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0LaC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F536dbed8-40fe-462d-99c1-e614391ff3e5_603x401.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0LaC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F536dbed8-40fe-462d-99c1-e614391ff3e5_603x401.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">An apparently clear RDP error can be only the first layer of the problem.</figcaption></figure></div><p>The issue escalates to the customer&#8217;s IT staff, who begin an initial round of troubleshooting. The first instinct is the most natural one: <strong>try a different Domain Controller</strong>.<br>Force authentication toward different DCs, perhaps in different sites, to rule out a localized problem.<br>But the result does not change, same answer, same error.</p><p>Meanwhile, a timing coincidence emerges that is hard to ignore: <strong>in the previous days a patching cycle had been carried out on the Domain Controllers</strong>.<br>The lead seems promising.<br>The customer checks the installed updates, looks for articles on the internet, compares versions, and starts to suspect widespread bugs by digging through IT forums.<br>It is a logical and reassuring explanation: something changed, therefore something &#8220;broke&#8221;.</p><p>The problem is that, even after digging, <strong>nothing emerges</strong>:</p><p>&#183; The patches on the DCs are aligned</p><p>&#183; No other users are complaining about access failures</p><p>&#183; There are no obvious errors in the logs that would justify such selective behaviour</p><p>At this point the customer&#8217;s ideas begin to run out.<br>The most obvious hypotheses have been explored, the standard checks completed, and no quick solutions have emerged.</p><p>Only then does the customer decide to open a ticket with our support team.</p><p>And that is exactly where the situation becomes interesting.</p><h2>The analysis</h2><p>The issue is then assigned to one of the consultants on my team, who starts digging deeper. The first thing he does is retrace the path already taken by the customer, following the old logic that &#8220;trust is good, not trusting is better&#8221;. Nothing new.</p><p>He then turns to a detailed analysis of the error message: <em><strong>&#8220;A user account restriction is preventing you from logging on.&#8221;</strong></em></p><p>These &#8220;<em>user account restrictions</em>&#8221; are settings that come from far away, from the days of <strong>Windows NT 4</strong>. The ones that usually have a direct effect on RDP sessions are <em>Logon Time Restriction</em> and <em>Workstation Restriction</em>.</p><p>The user is checked, but there is no trace of those settings, everything seems in order, and the same goes for the GPOs applied to it.</p><p>The events on the <em>Target System</em> are then checked, but again, nothing.</p><p>The perspective then shifts to empirical testing with other accounts, revealing some curious behaviour:</p><p>&#183; Trying to log on through RDP to the same server <em><strong>with the consultant&#8217;s user account</strong></em>, access <strong>succeeds</strong></p><p>&#183; Trying to create<em><strong> a new user </strong></em>and log on through RDP with it results in the <strong>same error</strong></p><p>&#183; Trying to use <em><strong>a different Source System</strong></em> and the user <em><strong>XYZ-admin</strong></em>, access <strong>succeeds</strong></p><p>So, it is not just a user issue, but a combination of: <strong>user + Source System + Target System</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Lnrt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c0c2907-70fd-49d5-bba2-67f0d7617dfb_541x471.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Lnrt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c0c2907-70fd-49d5-bba2-67f0d7617dfb_541x471.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Lnrt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c0c2907-70fd-49d5-bba2-67f0d7617dfb_541x471.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Lnrt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c0c2907-70fd-49d5-bba2-67f0d7617dfb_541x471.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Lnrt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c0c2907-70fd-49d5-bba2-67f0d7617dfb_541x471.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Lnrt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c0c2907-70fd-49d5-bba2-67f0d7617dfb_541x471.jpeg" width="541" height="471" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9c0c2907-70fd-49d5-bba2-67f0d7617dfb_541x471.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:471,&quot;width&quot;:541,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:38022,&quot;alt&quot;:&quot;Diagram showing the relationship between user, Source System and Target System in the RDP access flow.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/199053556?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c0c2907-70fd-49d5-bba2-67f0d7617dfb_541x471.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram showing the relationship between user, Source System and Target System in the RDP access flow." title="Diagram showing the relationship between user, Source System and Target System in the RDP access flow." srcset="https://substackcdn.com/image/fetch/$s_!Lnrt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c0c2907-70fd-49d5-bba2-67f0d7617dfb_541x471.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Lnrt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c0c2907-70fd-49d5-bba2-67f0d7617dfb_541x471.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Lnrt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c0c2907-70fd-49d5-bba2-67f0d7617dfb_541x471.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Lnrt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c0c2907-70fd-49d5-bba2-67f0d7617dfb_541x471.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">When the error depends on the combination of user, source system and target system, troubleshooting changes scale.</figcaption></figure></div><p>In this case as well, the matter ends up on my desk for an opinion. We begin to dig deeper, starting from what I consider <em>the tablets of the law</em> of troubleshooting:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vXOr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4520275-5918-47e9-96c8-55c15ff8bac4_261x340.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vXOr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4520275-5918-47e9-96c8-55c15ff8bac4_261x340.png 424w, https://substackcdn.com/image/fetch/$s_!vXOr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4520275-5918-47e9-96c8-55c15ff8bac4_261x340.png 848w, https://substackcdn.com/image/fetch/$s_!vXOr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4520275-5918-47e9-96c8-55c15ff8bac4_261x340.png 1272w, https://substackcdn.com/image/fetch/$s_!vXOr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4520275-5918-47e9-96c8-55c15ff8bac4_261x340.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vXOr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4520275-5918-47e9-96c8-55c15ff8bac4_261x340.png" width="261" height="340" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b4520275-5918-47e9-96c8-55c15ff8bac4_261x340.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:340,&quot;width&quot;:261,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:170762,&quot;alt&quot;:&quot;Symbolic image of stone tablets used as a metaphor for the troubleshooting method.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/199053556?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4520275-5918-47e9-96c8-55c15ff8bac4_261x340.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Symbolic image of stone tablets used as a metaphor for the troubleshooting method." title="Symbolic image of stone tablets used as a metaphor for the troubleshooting method." srcset="https://substackcdn.com/image/fetch/$s_!vXOr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4520275-5918-47e9-96c8-55c15ff8bac4_261x340.png 424w, https://substackcdn.com/image/fetch/$s_!vXOr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4520275-5918-47e9-96c8-55c15ff8bac4_261x340.png 848w, https://substackcdn.com/image/fetch/$s_!vXOr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4520275-5918-47e9-96c8-55c15ff8bac4_261x340.png 1272w, https://substackcdn.com/image/fetch/$s_!vXOr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4520275-5918-47e9-96c8-55c15ff8bac4_261x340.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The tablets of the law of troubleshooting</figcaption></figure></div><p>A network trace is then taken on the Source System, and interesting things start to emerge:</p><p>&#183; The RDP session never gets to talk to the <em>Target System</em>, the block happens earlier</p><p>&#183; A correlation with the error message is found:</p><blockquote><p>o The <em>Source System</em> starts an RDP session toward the <em>Target System</em></p><p>o The <em>Source System</em> then talks to a <em>Domain Controller</em>, asking for authorization for <strong>RDP</strong> access for user <em>XYZ-admin@domain.xyz</em> toward the <em>Target System</em></p><p>o At that point the <em>Domain Controller</em> responds with a Kerberos error: <strong>KDC_ERR_POLICY</strong></p></blockquote><p>&#183; When the connection comes from <em>Source System 2</em>, there is no trace of the Kerberos error</p><p>&#183; When the connection comes from the <em>Source System</em>, but using the consultant&#8217;s user account, no Kerberos error is returned</p><p>Attention then shifts to what is happening on the specific <em>Domain Controller</em>, by analyzing its logs in detail. And here something incomprehensible happens: an event is recorded that matches precisely, by date, time and scope, the one seen in the network trace, except that it has a positive outcome: <em><strong>it is a legitimate authorization to access!</strong></em></p><p>So, the <em>Domain Controller</em> is convinced it returned an <strong>OK</strong>, while the <em>Source System</em> receives a <strong>KO</strong> in response. Who or what in the middle is lying???</p><p>The analysis continues and, with more network traces, other curious things come to light:</p><p>&#183; All the successful calls from <em>Source System 2</em> <em>always request authorization from one specific<strong> Domain Controller.</strong></em></p><p>&#183; All the failing calls from the <em>Source System</em> never request authorization from the Domain Controller that <em>Source System 2</em> talks to, in fact <em>they contact random <strong>Domain Controllers</strong> around the world.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tapt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6806672-60c7-45e5-9bef-fee2d3300fc0_602x365.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tapt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6806672-60c7-45e5-9bef-fee2d3300fc0_602x365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tapt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6806672-60c7-45e5-9bef-fee2d3300fc0_602x365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tapt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6806672-60c7-45e5-9bef-fee2d3300fc0_602x365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tapt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6806672-60c7-45e5-9bef-fee2d3300fc0_602x365.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tapt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6806672-60c7-45e5-9bef-fee2d3300fc0_602x365.jpeg" width="602" height="365" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f6806672-60c7-45e5-9bef-fee2d3300fc0_602x365.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:365,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42098,&quot;alt&quot;:&quot;Diagram of the Domain Controllers contacted by the source systems, highlighting the difference between successful and failing paths.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/199053556?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6806672-60c7-45e5-9bef-fee2d3300fc0_602x365.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram of the Domain Controllers contacted by the source systems, highlighting the difference between successful and failing paths." title="Diagram of the Domain Controllers contacted by the source systems, highlighting the difference between successful and failing paths." srcset="https://substackcdn.com/image/fetch/$s_!tapt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6806672-60c7-45e5-9bef-fee2d3300fc0_602x365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tapt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6806672-60c7-45e5-9bef-fee2d3300fc0_602x365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tapt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6806672-60c7-45e5-9bef-fee2d3300fc0_602x365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tapt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff6806672-60c7-45e5-9bef-fee2d3300fc0_602x365.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The difference between success and failure was hidden in the path to the &#8220;right&#8221; Domain Controller.</figcaption></figure></div><p>We have therefore identified the error sequence, but the cause is still not clear. If anything, the evidence only makes things more confusing.</p><p>With the conviction that &#8220;there is something in the middle&#8221;, supported by the lack of dialogue with the only &#8220;good&#8221; <em>Domain Controller</em>, the investigation turns back to the network, and this time a ticket is opened with HQ network support.</p><p>There is still, however, the question of why the consultant&#8217;s account works normally.</p><p>A few days go by, and an interesting message arrives from HQ: <em>I fixed the account, try again now.</em></p><p>Wait&#8230; what do you mean by &#8220;I fixed the account&#8221;, what is the explanation behind all this?</p><p>In any case, a new test is run and, wonder of wonders, everything works!</p><p>Further clarification is then requested, after all this effort we need to understand.</p><p>The answer is disarming: it is <strong>CrowdStrike</strong>&#8217;s fault, which had marked the user as &#8220;non-human&#8221;.</p><p>So, we were right, there really was something in the middle. Only no one had visibility into what it was.</p><p>But let us go in order and reconstruct what happened, because this is one of those interesting situations where chaos and misunderstandings rule the scene:</p><p>&#183; CrowdStrike has a module called &#8220;<a href="https://www.crowdstrike.com/products/identity-protection/">Identity Protection</a>&#8221;</p><p>&#183; HQ deployed the CrowdStrike agent on the Domain Controllers, all except the one that <em>Source System 2</em> was talking to</p><p>&#183; CrowdStrike ran a scan and identified XYZ-admin as a Non-Human Identity</p><p>&#183; The agent on the Domain Controllers took control of the Kerberos responses, modifying them on the fly according to its own parameters</p><p>&#183; The Domain Controllers were therefore convinced they had answered OK, but the agent converted that into KO</p><p>&#183; To make matters worse, there really was a network problem: the Source System had its path blocked toward the &#8220;good&#8221; Domain Controller, obtaining a regular KO for the RDP sessions of XYZ-admin</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!75uq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74aa452c-8db6-4ecf-8c36-d48e4d24679b_602x365.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!75uq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74aa452c-8db6-4ecf-8c36-d48e4d24679b_602x365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!75uq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74aa452c-8db6-4ecf-8c36-d48e4d24679b_602x365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!75uq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74aa452c-8db6-4ecf-8c36-d48e4d24679b_602x365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!75uq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74aa452c-8db6-4ecf-8c36-d48e4d24679b_602x365.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!75uq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74aa452c-8db6-4ecf-8c36-d48e4d24679b_602x365.jpeg" width="602" height="365" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/74aa452c-8db6-4ecf-8c36-d48e4d24679b_602x365.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:365,&quot;width&quot;:602,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:47638,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/199053556?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74aa452c-8db6-4ecf-8c36-d48e4d24679b_602x365.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!75uq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74aa452c-8db6-4ecf-8c36-d48e4d24679b_602x365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!75uq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74aa452c-8db6-4ecf-8c36-d48e4d24679b_602x365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!75uq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74aa452c-8db6-4ecf-8c36-d48e4d24679b_602x365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!75uq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74aa452c-8db6-4ecf-8c36-d48e4d24679b_602x365.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The truth was in the middle: network, Kerberos and response control had become entangled in the same error.</figcaption></figure></div><p>The thing that struck me most about this strange case is this: we are facing a modern cloud technology, <strong>CrowdStrike</strong>, governing legacy technologies without taking their real effects into account, generating strange behavior and misleading errors.</p><p>The concept of <strong>Non-Human Identity</strong> also enters the equation, something with deep roots in legacy environments, yet one that has become extremely current under the pressure of <strong>AI</strong> systems.</p><p>And for the record, the poor Domain Controller was not to blame: it really was trying to tell the truth&#8230;</p><h2>Lessons learned</h2><p>The first lesson this case leaves us is only simple in appearance: even the most authoritative sources can tell a distorted truth. And behind it there is not always a bug or a bad configuration, but often the fact that the context in which they operate has changed, while they continue to do their job with implacable consistency.</p><p>The poor Domain Controller was not broken or &#8220;a liar&#8221;.<br>It was doing its job, answering with confidence.<br>And yet the answer that arrived was not the useful one. It was formally correct, substantially wrong.</p><p>The second lesson concerns the way we interpret errors.<br>Misleading messages, logs without errors, inconsistent behaviour across identical systems: modern troubleshooting sometimes offers no direct clues. Legacy mechanisms become intertwined with ever more sophisticated layers of protection, &#8220;governed from above&#8221;, creating scenarios where every piece of the chain seems to be working&#8230; but the result still does not add up.</p><p>Finally, reconnecting with <a href="https://www.legacythings.it/p/chapter-2-a-matter-of-trust?r=7oz2wp">chapter 2</a>, there is a larger lesson: <strong>trust in the system</strong> is often taken for granted.<br>We trust the Domain Controller, DNS, the network, the agents, the cloud protection layers. But every element introduces its own model of truth, built within its own perimeter. When those models are not aligned or do not talk to one another coherently, what we receive is not an explicit error, but a &#8220;correct&#8221; answer that no longer represents reality.</p><p>And this applies not only to human accounts.<br>More and more often, in modern infrastructures, the truly critical identities are not those of people, but those of processes, services, connectors and scheduled jobs. <strong>Non-Human Identities</strong> operate under the surface, often with privileges that remain invisible, and they make decisions on their own. It would be naive to think they cannot run into the same paradoxes or create new ones.<br><a href="https://www.microsoft.com/en-us/security/business/security-101/what-are-non-human-identities">What Are Non-human Identities? | Microsoft Security</a></p><p>For now, the lesson remains clear:<br>in complex systems, truth does not disappear cleanly. It hides in silence, until someone decides to look in the right place.</p><p>This chapter is for <strong>Denys</strong>, who found the truth in the right place. I hope that even now he is in the right place.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Legacy Things! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Legacy MCP: La scommessa]]></title><description><![CDATA[Cosa pu&#242; realizzare un vecchio sistemista con 20 euro in un mese?]]></description><link>https://www.legacythings.it/p/legacy-mcp-la-scommessa</link><guid isPermaLink="false">https://www.legacythings.it/p/legacy-mcp-la-scommessa</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Tue, 28 Apr 2026 16:31:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DQjm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826f9dc1-beac-4ce7-97b4-15ef155d6b3e_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>English version available here &#8594;<a href="https://www.legacythings.it/p/legacy-mcp-the-bet"> [EN]</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DQjm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826f9dc1-beac-4ce7-97b4-15ef155d6b3e_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DQjm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826f9dc1-beac-4ce7-97b4-15ef155d6b3e_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!DQjm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826f9dc1-beac-4ce7-97b4-15ef155d6b3e_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!DQjm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826f9dc1-beac-4ce7-97b4-15ef155d6b3e_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!DQjm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826f9dc1-beac-4ce7-97b4-15ef155d6b3e_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DQjm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826f9dc1-beac-4ce7-97b4-15ef155d6b3e_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/826f9dc1-beac-4ce7-97b4-15ef155d6b3e_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3186187,&quot;alt&quot;:&quot;Immagine con il titolo &#8220;LEGACY MCP&#8221; in stile neon rosso su uno sfondo verde sfocato. Al centro della scena cresce una giovane pianta con due foglie. La parte superiore &#232; visibile in superficie, mentre sotto il terreno &#232; mostrato un apparato radicale luminoso e ramificato.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/194906792?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826f9dc1-beac-4ce7-97b4-15ef155d6b3e_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Immagine con il titolo &#8220;LEGACY MCP&#8221; in stile neon rosso su uno sfondo verde sfocato. Al centro della scena cresce una giovane pianta con due foglie. La parte superiore &#232; visibile in superficie, mentre sotto il terreno &#232; mostrato un apparato radicale luminoso e ramificato." title="Immagine con il titolo &#8220;LEGACY MCP&#8221; in stile neon rosso su uno sfondo verde sfocato. Al centro della scena cresce una giovane pianta con due foglie. La parte superiore &#232; visibile in superficie, mentre sotto il terreno &#232; mostrato un apparato radicale luminoso e ramificato." srcset="https://substackcdn.com/image/fetch/$s_!DQjm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826f9dc1-beac-4ce7-97b4-15ef155d6b3e_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!DQjm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826f9dc1-beac-4ce7-97b4-15ef155d6b3e_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!DQjm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826f9dc1-beac-4ce7-97b4-15ef155d6b3e_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!DQjm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F826f9dc1-beac-4ce7-97b4-15ef155d6b3e_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Venerd&#236; 13 marzo 2026</strong>, una data che sembra anonima, se vista dal lato scaramantico in alcune culture c&#8217;&#232; chi crede che porti sfortuna, ma per me ha un significato particolare: mi &#232; venuta un&#8217;idea e la voglio realizzare.</p><p>In realt&#224; i semi di quell&#8217;idea arrivano da un percorso iniziato qualche tempo prima.</p><p>Il primo risale al 6 maggio 2025: European Identity Conference a Berlino, seconda sessione della giornata, tra i top trend previsti per il 2025 c&#8217;&#232; l&#8217;esplosione degli MCP Server.</p><p>Guardo in faccia il mio collega e ci facciamo la stessa domanda: cosa diavolo &#232; un MCP Server? Dobbiamo assolutamente approfondire!</p><p>Passano mesi e come da perfetta profezia gli MCP Server iniziano a spuntare come funghi.</p><p>Il secondo seme risale al 25 febbraio 2026: &#232; da un po&#8217; che sento l&#8217;esigenza di scrivere su &#8220;roba legacy&#8221;, parlo con un collega e finalmente trovo la &#8220;casa&#8221; giusta per il mio progetto. Immediatamente decido di aprire questo blog su Substack e nel giro di una settimana pubblico il primo articolo. &#200; il 1&#176; marzo 2026.</p><p>L&#8217;essere su questa piattaforma mi ha per&#242; dato la possibilit&#224; di leggere cose molto interessanti negli altri blog della piattaforma. Molto spesso sono argomenti distanti tecnicamente dal mio lavoro, ma che risuonano bene con il mio modo di vedere le cose.</p><p>Ma torniamo al 13 marzo 2026, leggo un post dove si parla dell&#8217;evoluzione di Claude.ai. Parla di quanto i suoi nuovi modelli siano potenti e di un esperimento di Vibe Coding estremo.</p><p>Ecco, quello &#232; l&#8217;ultimo seme&#8230;</p><p>L&#8217;idea inizia a germogliarmi in testa, arrivato a sera inizio la mia prima chiacchierata con l&#8217;app Claude, breve botta e risposta ed ecco che trova la sua forma:</p><div><hr></div><p style="text-align: center;">E se volessi scrivere una interfaccia MCP per Active Directory?</p><div><hr></div><p>Ci dormo sopra (si fa per dire) e mi sveglio con un disegno piuttosto chiaro in testa.</p><p>Dopo colazione inizio a bombardare l&#8217;AI facendo un &#8220;dump&#8221; della mia memoria e lei tiene il ritmo. Arriviamo ad una prima bozza, ma c&#8217;&#232; un bel sole e l&#8217;erba alta mi chiama, &#232; tempo di uscire.</p><p>Taglio, medito, scarico, taglio, medito, scarico e cos&#236; via&#8230;</p><p>Pomeriggio secondo round con l&#8217;AI, altro dump massivo ed arriviamo ad un disegno molto chiaro, decido che &#232; ora da fare una <strong>scommessa</strong>:</p><p><em><strong>pu&#242; un vecchio sistemista, con un passato di programmazione che si &#232; fermato a Visual Basic 6, ma che conosce bene i sistemi, creare da zero un progetto per un MCP Server open source?</strong></em></p><p>&#200; in quel momento che investo 20 euro per accedere a Claude Code e <strong>ufficialmente nasce il progetto Legacy MCP.</strong></p><p>Domenica 15 marzo 2026, mi sveglio e mi dedico alla mia passione per la Formula 1, e faccio bene.</p><p>Una giovane promessa dell&#8217;automobilismo italiano, a soli 19 anni, parte dalla pole position, domina la gara e ottiene la sua prima vittoria, centrando una <strong>scommessa</strong> fatta dalla Mercedes quando aveva solo 11 anni. &#200; Andrea Kimi Antonelli.</p><p>Sono euforico e penso che sar&#224; una grande giornata, mi metto quindi all&#8217;opera per impostare i lavori e dopo pranzo &#8220;accendo le macchine&#8221;, tempo un paio d&#8217;ore ed ho il primo prototipo funzionante.</p><p>Quando vedo che posso interrogare i dati esattamente come mi ero immaginato mi casca la mascella e rimango letteralmente a bocca aperta, pensando: s&#236; questa &#232; una <strong>scommessa</strong> che va portata a termine!</p><p>Questo articolo non nasce per spiegare una tecnologia, ma per raccontare un percorso.<br>&#200; il racconto di cosa succede quando un&#8217;idea legacy incontra strumenti nuovi, e qualcuno decide <strong>di provarci davvero</strong>, mettendo in contatto i due mondi.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.legacythings.it/subscribe?"><span>Iscriviti ora</span></a></p><h2>Perch&#233; serviva farlo</h2><p>Se avete letto i miei articoli precedenti (<a href="https://www.legacythings.it/p/capitolo-1-adminsdholder-il-guardiano">Capitolo 1</a>, <a href="https://www.legacythings.it/p/capitolo-2-una-questione-di-fiducia">Capitolo 2</a> ) saprete gi&#224; il mio punto di vista, per i nuovi lettori lo riassumo brevemente: nonostante la spinta al cloud, le tecnologie legacy continuano a sopravvivere. Solo che, col tempo, stanno iniziando a diventare misteriose e quindi serve un modo per tramandarle.</p><p>Ogni progetto che viene avviato dal mio team parte sempre dallo stesso punto: dobbiamo fare un assessment e produrre un documento.</p><p>E nella stragrande maggioranza dei casi, il cuore dell&#8217;assessment &#232; sempre lui: <strong>Active Directory</strong>.</p><p>Per anni ci si &#232; affidati alla fedele <strong>PowerShell</strong> con soluzioni scripting pi&#249; o meno standard, ma con un punto fermo: l&#8217;uso dell&#8217;ottimo <a href="https://github.com/CarlWebster/Active-Directory-V3">ADDS_Inventory_V3.ps1</a> del mitico Carl Webster.</p><p>Il problema &#232; che lo sviluppo e la manutenzione di questi script stanno diventando sempre pi&#249; onerosi, mentre fuori il mondo surfa veloce sull&#8217;onda dell&#8217;AI.</p><p>Non volevo buttare via quel patrimonio: volevo renderlo interrogabile, modulare e riutilizzabile.</p><p>E allora mi sono fatto una domanda semplice: <em>perch&#233; non provare a mettere in contatto questi due mondi?</em></p><p>La chiave di volta l&#8217;ho trovata nel protocollo <strong>MCP</strong>. Molto spesso viene descritto come &#8220;la porta USB per l&#8217;AI&#8221;: uno standard aperto che permette di &#8220;connettere&#8221; i sistemi di AI a moduli esterni di qualsiasi tipo.</p><p>Per chi vuole approfondire rimando alla documentazione ufficiale: <a href="https://modelcontextprotocol.io/docs/getting-started/intro">What is the Model Context Protocol (MCP)? - Model Context Protocol</a></p><p>Da qui nasce l&#8217;idea di realizzare un <strong>Server MCP</strong> che faccia da ponte tra il mondo <strong>Active Directory</strong> e i sistemi di <strong>AI</strong>: <a href="https://github.com/Marco-Lelli/legacy-mcp">Legacy MCP</a>.</p><p>In pratica: un modo standard per interrogare AD usando strumenti AI, spostando il focus dal <em><strong>come</strong></em> al <em><strong>cosa</strong></em>.</p><p>Come anticipato, durante i primi due giorni ho avuto intense sessioni con Claude Chat: ho definito principi e linee guida che mi hanno permesso di vedere risultati tangibili in meno di 48 ore.</p><p>Tra questi c&#8217;&#232; la distinzione netta tra progetto <strong>open core</strong> ed <strong>enterprise</strong>: va bene che sono &#8220;solo&#8221; 20 euro, ma fare le cose bene richiede tempo, quindi serve anche darsi un limite.<br>La scelta &#232; stata piuttosto semplice, naturale e coerente:</p><div><hr></div><p style="text-align: center;">se il progetto prende spunto dal grande lavoro di Carl Webster, allora l&#8217;open core deve coprire tutto quello che per anni ha coperto lo script ADDS_Inventory_V3.ps1.</p><div><hr></div><p>&#200; un modo per restituire alla community una parte di quello che ho ricevuto, ma portandolo al passo con le tecnologie attuali.</p><p>Su queste basi, verr&#224; poi portato avanti uno strato enterprise che richiede sforzi ed investimenti differenti, e che coprir&#224; funzionalit&#224; pi&#249; avanzate e sofisticate:</p><p>&#183; <strong>open core</strong> = inventario e interrogazioni fondamentali</p><p>&#183; <strong>enterprise</strong> = analisi avanzate / report / integrazioni</p><h2>Cosa pu&#242; fare per te</h2><p>Legacy MCP nasce per un obiettivo semplice: rendere interrogabile Active Directory, permettendo correlazioni incrociate tra i dati e spostando il focus sul <em><strong>che cosa mi serve capire</strong></em>.</p><p>A seconda del contesto (offline, rete locale, internet) lo stesso approccio si declina in <strong>profili di deployment</strong> diversi, pensati per bilanciare praticit&#224; e sicurezza: <strong>A / B-core / B-enterprise / C.</strong></p><p>In tutti i profili, comunque, il flusso logico &#232; lo stesso: porto i dati in un workspace, poi interrogo. Cambia solo <em><strong>dove</strong></em> girano server e dati, e <em><strong>quanto</strong></em> &#232; governato l&#8217;accesso.</p><p>Tutti i dettagli operativi li trovate nel <a href="https://github.com/Marco-Lelli/legacy-mcp">repository</a>, adesso concentriamoci su casi d&#8217;uso reali.</p><p>Tre scenari, tre livelli di fiducia: <em>file, LAN, internet.</em></p><h3>Caso d&#8217;uso #1 - Assessment remoto offline + report</h3><p><strong>Profilo:</strong> A (open core)</p><p><strong>Scenario:</strong> Un consulente deve analizzare un ambiente AD remoto, a volte pu&#242; avere accesso diretto in VPN o sessione condivisa, in altri casi la raccolta &#232; demandata al cliente.</p><p><strong>Approccio:</strong> Invece di generare un report statico, raccoglie i dati in modo standard con un collector PowerShell, o chiede al cliente di farlo. L&#8217;output &#232; un <strong>JSON</strong> con dati e metadati di sessione.</p><p><strong>Analisi:</strong> Sul proprio PC configura Legacy MCP in locale, &#8220;monta&#8221; il JSON nel workspace e interroga l&#8217;ambiente tramite Claude Desktop.</p><p><strong>Risultato.</strong> Ottiene un&#8217;analisi strutturata sulle aree di proprio interesse e, quando serve, un output documentale (nel progetto sono gi&#224; stati prodotti alcuni report DOCX su ambienti reali).</p><p>Un esempio reale, questa &#232; la risposta che LegacyMCP permette di ottenere in pochi secondi a una domanda concreta sull&#8217;ambiente:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aW9_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c21a810-0bd1-4b12-8ddb-31510e25076e_940x929.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aW9_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c21a810-0bd1-4b12-8ddb-31510e25076e_940x929.png 424w, https://substackcdn.com/image/fetch/$s_!aW9_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c21a810-0bd1-4b12-8ddb-31510e25076e_940x929.png 848w, https://substackcdn.com/image/fetch/$s_!aW9_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c21a810-0bd1-4b12-8ddb-31510e25076e_940x929.png 1272w, https://substackcdn.com/image/fetch/$s_!aW9_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c21a810-0bd1-4b12-8ddb-31510e25076e_940x929.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aW9_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c21a810-0bd1-4b12-8ddb-31510e25076e_940x929.png" width="940" height="929" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9c21a810-0bd1-4b12-8ddb-31510e25076e_940x929.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:929,&quot;width&quot;:940,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:629578,&quot;alt&quot;:&quot;Screenshot di una conversazione in chat con un sistema di intelligenza artificiale. In alto &#232; mostrata una domanda sull&#8217;aggiornamento dei Domain Controller. Sotto &#232; presente una risposta strutturata che elenca i principali rischi e blocchi, inclusi sistema operativo fuori supporto, ruoli FSMO concentrati, necessit&#224; di adprep e coordinamento tra siti.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/194906792?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c21a810-0bd1-4b12-8ddb-31510e25076e_940x929.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot di una conversazione in chat con un sistema di intelligenza artificiale. In alto &#232; mostrata una domanda sull&#8217;aggiornamento dei Domain Controller. Sotto &#232; presente una risposta strutturata che elenca i principali rischi e blocchi, inclusi sistema operativo fuori supporto, ruoli FSMO concentrati, necessit&#224; di adprep e coordinamento tra siti." title="Screenshot di una conversazione in chat con un sistema di intelligenza artificiale. In alto &#232; mostrata una domanda sull&#8217;aggiornamento dei Domain Controller. Sotto &#232; presente una risposta strutturata che elenca i principali rischi e blocchi, inclusi sistema operativo fuori supporto, ruoli FSMO concentrati, necessit&#224; di adprep e coordinamento tra siti." srcset="https://substackcdn.com/image/fetch/$s_!aW9_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c21a810-0bd1-4b12-8ddb-31510e25076e_940x929.png 424w, https://substackcdn.com/image/fetch/$s_!aW9_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c21a810-0bd1-4b12-8ddb-31510e25076e_940x929.png 848w, https://substackcdn.com/image/fetch/$s_!aW9_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c21a810-0bd1-4b12-8ddb-31510e25076e_940x929.png 1272w, https://substackcdn.com/image/fetch/$s_!aW9_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c21a810-0bd1-4b12-8ddb-31510e25076e_940x929.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">L'analisi va oltre i semplici dati</figcaption></figure></div><p>Questo &#232; il profilo pi&#249; semplice: massimizza portabilit&#224; e ripetibilit&#224;, e minimizza la dipendenza dall&#8217;ambiente del cliente. Permette anche analisi incrociate tra ambienti correlati.</p><h3>Caso d&#8217;uso #2 - Dialogo interattivo live + confronto storico (snapshot)</h3><p><strong>Profilo:</strong> B-core o B-enterprise (in base al livello di sicurezza richiesto).</p><p><strong>Scenario:</strong> Team IT o consulenti vogliono interrogare l&#8217;ambiente &#8220;dal vivo&#8221;, con la comodit&#224; del dialogo in chat, senza esportare continuamente file.</p><p><strong>Approccio:</strong> Legacy MCP viene eseguito in rete locale su un server dell&#8217;ambiente Active Directory (member server). Le comunicazioni sono cifrate e il modello di autenticazione &#232; coerente con il profilo scelto.</p><p><strong>Interazione:</strong> I client (Claude Desktop) si collegano al server MCP tramite modulo bridge (mcp-remote) in LAN. Nel progetto questo pattern &#232; gi&#224; stato testato end&#8209;to&#8209;end su Profilo B-core con HTTPS e autenticazione basata su token/chiavi protette.</p><p><strong>Valore extra:</strong> Quando serve &#8220;memoria&#8221;, si generano snapshot nel tempo. Questo permette di montare snapshot e live insieme chiedendo la domanda pi&#249; semplice (e pi&#249; potente): <strong>cosa &#232; cambiato?</strong></p><p>Il profilo B, lavorando su dato live, ha requisiti di sicurezza pi&#249; stringenti (account dedicato, cifratura end-to-end e accesso governato). I dettagli sono nel <a href="https://github.com/Marco-Lelli/legacy-mcp">repository</a>.</p><p><strong>Nota importante: </strong>Legacy MCP espone funzioni di sola lettura (read-only).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!A8bt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1c4d08d-d208-4e2e-9147-98cd9a5d974e_1024x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!A8bt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1c4d08d-d208-4e2e-9147-98cd9a5d974e_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!A8bt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1c4d08d-d208-4e2e-9147-98cd9a5d974e_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!A8bt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1c4d08d-d208-4e2e-9147-98cd9a5d974e_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!A8bt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1c4d08d-d208-4e2e-9147-98cd9a5d974e_1024x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!A8bt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1c4d08d-d208-4e2e-9147-98cd9a5d974e_1024x1024.jpeg" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1c4d08d-d208-4e2e-9147-98cd9a5d974e_1024x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:157809,&quot;alt&quot;:&quot;Illustrazione con il titolo &#8220;LEGACY MCP&#8221; in stile neon rosso. Al centro &#232; rappresentato un portale in pietra diviso verticalmente. Da un lato sono visibili elementi grafici legati al codice e all&#8217;analisi dei dati, dall&#8217;altro un server e una creatura mitologica a tre teste. Alla base del portale si estende un sistema di radici luminose.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/194906792?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1c4d08d-d208-4e2e-9147-98cd9a5d974e_1024x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustrazione con il titolo &#8220;LEGACY MCP&#8221; in stile neon rosso. Al centro &#232; rappresentato un portale in pietra diviso verticalmente. Da un lato sono visibili elementi grafici legati al codice e all&#8217;analisi dei dati, dall&#8217;altro un server e una creatura mitologica a tre teste. Alla base del portale si estende un sistema di radici luminose." title="Illustrazione con il titolo &#8220;LEGACY MCP&#8221; in stile neon rosso. Al centro &#232; rappresentato un portale in pietra diviso verticalmente. Da un lato sono visibili elementi grafici legati al codice e all&#8217;analisi dei dati, dall&#8217;altro un server e una creatura mitologica a tre teste. Alla base del portale si estende un sistema di radici luminose." srcset="https://substackcdn.com/image/fetch/$s_!A8bt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1c4d08d-d208-4e2e-9147-98cd9a5d974e_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!A8bt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1c4d08d-d208-4e2e-9147-98cd9a5d974e_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!A8bt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1c4d08d-d208-4e2e-9147-98cd9a5d974e_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!A8bt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1c4d08d-d208-4e2e-9147-98cd9a5d974e_1024x1024.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Live (Kerberos) e offline (JSON) nello stesso workspace</figcaption></figure></div><h3>Caso d&#8217;uso #3 - Portale di analisi esposto su Internet</h3><p><strong>Profilo:</strong> C (solo enterprise)</p><p><strong>Scenario:</strong> si vuole rendere l&#8217;assessment scalabile e fruibile come servizio: pi&#249; team, pi&#249; clienti, accesso da ovunque, ma senza necessit&#224; di accessi live all&#8217;infrastruttura.</p><p><strong>Approccio:</strong> Si lavora solo su dati offline. &#200; possibile effettuare upload dei JSON, gestione dei workspace via web. L&#8217;analisi avviene tramite agenti che consumano MCP su endpoint pubblici.</p><p><strong>Sicurezza:</strong> Questo profilo richiede un layer di protezione su rete pubblica: API gateway (es. APIM) + WAF. L&#8217;autenticazione &#232; demandata ad un Identity Provider (tipicamente Entra ID) con MFA all&#8217;accesso ed RBAC sui dati caricati.</p><p><strong>Perch&#233; ha senso:</strong> &#200; il passo che trasforma un tool in una piattaforma, con lo stesso modello logico (profili, workspace, snapshot/offline), ma con governance e accesso enterprise.</p><p>Al momento questo &#232; solamente un caso d&#8217;uso teorico, ma con specifiche gi&#224; ben definite. Va bene il Vibe Coding, ma da solo in un mese di lavoro non sarei riuscito ad arrivare a tanto.</p><h2>Roma non &#232; stata fatta in un giorno</h2><p>Pensare al concetto di Vibe Coding mi fa andare in modalit&#224; <strong>Legacy Things</strong> e nelle orecchie mi inizia a suonare un famoso pezzo uscito nel 2000: <strong>Rome Wasn&#8217;t Built in a Day</strong> dei <strong>Morcheeba</strong>.</p><p>&#200; la colonna sonora perfetta per descrivere il percorso che ho affrontato durante il mese della scommessa.</p><p>Ovunque leggo articoli e proclami che suonano pi&#249; o meno cos&#236;:</p><div><hr></div><p style="text-align: center;">come ho creato qualcosa da zero in 35 minuti grazie all&#8217;AI e il Vibe Coding.</p><div><hr></div><p>Dal mio punto di osservazione, quella &#232; una mezza verit&#224;, fatta per catturare l&#8217;attenzione. Forse ci mettiamo anche la mia scelta di non usare un motore di coding estremo (Claude Sonnet 4.6), ma vi voglio raccontare come ho realmente vissuto l&#8217;esperienza.</p><h3>Punto primo</h3><p>&#200; sicuramente vero che una volta fornite le istruzioni il motore di coding ci mette pochi minuti a creare il risultato, ma la vera questione &#232;: quanto tempo ho impiegato tra ideare, ragionare in autonomia e conversare con una chat di AI prima di arrivare alle istruzioni?</p><p>Se prendiamo come esempio l&#8217;idea iniziale ve l&#8217;ho gi&#224; svelato: due giorni.</p><p>E ne sono serviti altri 28 per arrivare ad un risultato che mi facesse dire &#8220;ok lo possiamo pubblicare&#8221;.</p><p>Chiaro, dipende molto da &#8220;che cosa&#8221; voglio realizzare, lo sforzo &#232; proporzionale all&#8217;ambizione del progetto.</p><h3>Punto secondo</h3><p>Oltre al tempo, serve avere una direzione chiara e polso fermo, altrimenti l&#8217;AI ti porta a spasso dove vuole lei.</p><p>Per fare un esempio, durante una lunga e faticosa sessione di debug sull&#8217;autenticazione live verso i Domain Controller, l&#8217;AI ha provato di farmi semplificare l&#8217;approccio scalando dal protocollo Kerberos ad NTLM. <br>A quel punto sono rimasto fermo rimarcando i miei principi di sicurezza e alla fine siamo arrivati a farlo funzionare come volevo.</p><p>Adesso nella memoria di progetto leggo: <em><strong>NTLM must never be used</strong> &#8212; deprecated; Kerberos only for Live Mode</em></p><h3>Punto terzo</h3><p>Non sempre l&#8217;AI da sola ti trova la soluzione migliore, a volte perde di vista il dettaglio chiave.</p><p>Portando un altro esempio, durante la configurazione dell&#8217;accesso sicuro lato client MCP, mi sono scontrato su come gestire al meglio la chiave API senza esporla. La soluzione trovata &#232; stata quella di passare da un PowerShell e usare le <a href="https://learn.microsoft.com/en-us/windows/win32/seccng/cng-dpapi">DPAPI</a>.</p><p>Tutto bello fino a che l&#8217;avvio del PowerShell da Claude Chat moriva miseramente con uno strano errore. Dopo un&#8217;altra intensa sessione di troubleshooting &#232; stata mia l&#8217;intuizione di avviare il codice PowerShell dentro un caro vecchio file BAT, risolvendo immediatamente.</p><p>La sessione rimane nella memoria di progetto come &#8220;<strong>BAT is King</strong>&#8221; in perfetto stile Legacy Things, dove una tecnologia &#8220;antica&#8221; risolve un problema di AI.</p><h3>Timeline</h3><p>Di seguito vi lascio una timeline di cosa sono riuscito ad ottenere ed in che tempi, se la guardo sono veramente impressionato, ma non &#232; una roba da 35 minuti:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vek4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55289d07-9e57-4d4e-8fe0-e36b3fa6cc59_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vek4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55289d07-9e57-4d4e-8fe0-e36b3fa6cc59_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!vek4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55289d07-9e57-4d4e-8fe0-e36b3fa6cc59_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!vek4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55289d07-9e57-4d4e-8fe0-e36b3fa6cc59_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!vek4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55289d07-9e57-4d4e-8fe0-e36b3fa6cc59_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vek4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55289d07-9e57-4d4e-8fe0-e36b3fa6cc59_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/55289d07-9e57-4d4e-8fe0-e36b3fa6cc59_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2944761,&quot;alt&quot;:&quot;Infografica con il titolo &#8220;Legacy MCP &#8211; From Idea to Production in 28 Days&#8221;. In alto &#232; mostrata una timeline orizzontale con tappe e date che descrivono l&#8217;evoluzione del progetto da modalit&#224; offline a repository pubblico. In basso a sinistra &#232; presente una sezione &#8220;Key Numbers&#8221; con metriche tecniche, mentre a destra &#232; visibile il logo del progetto Legacy MCP.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/194906792?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55289d07-9e57-4d4e-8fe0-e36b3fa6cc59_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Infografica con il titolo &#8220;Legacy MCP &#8211; From Idea to Production in 28 Days&#8221;. In alto &#232; mostrata una timeline orizzontale con tappe e date che descrivono l&#8217;evoluzione del progetto da modalit&#224; offline a repository pubblico. In basso a sinistra &#232; presente una sezione &#8220;Key Numbers&#8221; con metriche tecniche, mentre a destra &#232; visibile il logo del progetto Legacy MCP." title="Infografica con il titolo &#8220;Legacy MCP &#8211; From Idea to Production in 28 Days&#8221;. In alto &#232; mostrata una timeline orizzontale con tappe e date che descrivono l&#8217;evoluzione del progetto da modalit&#224; offline a repository pubblico. In basso a sinistra &#232; presente una sezione &#8220;Key Numbers&#8221; con metriche tecniche, mentre a destra &#232; visibile il logo del progetto Legacy MCP." srcset="https://substackcdn.com/image/fetch/$s_!vek4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55289d07-9e57-4d4e-8fe0-e36b3fa6cc59_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!vek4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55289d07-9e57-4d4e-8fe0-e36b3fa6cc59_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!vek4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55289d07-9e57-4d4e-8fe0-e36b3fa6cc59_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!vek4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55289d07-9e57-4d4e-8fe0-e36b3fa6cc59_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Un mese, tante milestone</figcaption></figure></div><p>Roma non &#232; stata fatta in un giorno e nemmeno questo progetto. L&#8217;AI accelera tutto, ma senza una guida non farebbe altro che schiantarsi.</p><p>Ti permette di raggiungere vette altissime, ma una volta in cima ci dobbiamo chiedere: <strong>chi ha veramente scalato la montagna?</strong></p><h2>Chi ha veramente scalato la montagna?</h2><p>Quando l&#8217;idea ha preso forma e mi sono deciso a dedicare tempo sul serio al progetto, mi sono sentito un po&#8217; come se avessi avuto una montagna da scalare. Questo all&#8217;inizio un po&#8217; mi ha spaventato, ma non avevo nulla da perdere e sapevo di poter contare su strumenti veramente all&#8217;avanguardia in ambito AI.</p><p>Sono partito con una base standard sull&#8217;uso di AI chat, ma non sapevo nulla di coding con AI, un vero &#8220;newbie&#8221;.<br>Strada facendo mi sono per&#242; messo in gioco, mi sono documentato ed ho capito che per fare un buon lavoro, serve una buona dote di soft skill: idee chiare, forti capacit&#224; comunicative, tenacia e tanto metodo.<br>Volutamente mi sono spinto a scrivere codice in un linguaggio che non conosco (python) perch&#233; quello che mi interessava non era il codice, ma il risultato ottenuto.</p><p>Dopo le prime settimane mi sono reso conto che il limite tecnico principale era quello del &#8220;credito&#8221;, le sessioni di lavoro andavano distribuite ed ottimizzate, nel corso della giornata e della settimana. Senza una gestione oculata si rimaneva presto &#8220;senza benzina&#8221; sul pi&#249; bello.</p><p>Per tenere bassi i consumi nel credito di Claude il punto chiave &#232; stato quello di ridurre il contesto: usare la stessa chat per giorni saturava la finestra di contesto e consumava tantissimi token.</p><p>Col tempo ho quindi messo insieme un flusso di lavoro strutturato in tre livelli che vi voglio raccontare.</p><p>Strumenti utilizzati: <strong>Claude.ai</strong> (piano pro, per un mese) a cui ho aggiunto <strong>Perplexity.ai</strong>, un piano pro che con una promozione avevo in uso per un anno.</p><p>Ho poi creato un <strong>progetto</strong> dentro <strong>Claude</strong> ed uno <strong>spazio</strong> dentro <strong>Perplexity</strong>. In entrambe ho allegato un file <strong>status.md</strong> con il riepilogo totale. Il file viene allegato anche nella root di progetto ad uso di <strong>Claude Code</strong>.</p><p>Per il codice ho usato <strong>VS Code</strong> con l&#8217;estensione di <strong>Claude Code</strong>.</p><p>Il flusso in <strong>ingresso</strong> &#232; stato di questo tipo:</p><p>1. Prima <strong>bozza</strong> di ragionamento su <strong>Perplexity</strong> con motore <strong>Sonnet 4.6</strong> per coerenza con i passaggi successivi</p><p>2. La <strong>bozza</strong> di istruzioni di <strong>Perplexity</strong> viene passata a <strong>Claude Chat</strong> per una valutazione e successivo affinamento. <strong>Claude Chat</strong> apre una <strong>nuova sessione</strong> dallo <strong>status.md</strong> e genera le <strong>istruzioni</strong> per <strong>Claude Code</strong>.</p><p>3. <strong>Claude Code</strong> esegue e genera un <strong>riepilogo</strong></p><p>4. <strong>Claude Chat</strong> valuta il riepilogo e quando arrivati ad un risultato stabile <strong>chiude la sessione</strong> aggiornando il file <strong>status.md</strong></p><p>5. Il file aggiornato <strong>status.md</strong> viene allegato ovunque come nuovo riferimento univoco.</p><p>Questo il flusso in <strong>uscita</strong>:</p><p>1. Il <strong>riepilogo</strong> di <strong>Claude Chat</strong> viene passato a <strong>Perplexity</strong> come feedback</p><p>2. Vengono avviate le sessioni di <strong>test</strong> e <strong>debug</strong></p><p>3. Quando necessaria qualche <strong>variazione</strong> si torna al flusso di ingresso verso <strong>Claude Chat</strong></p><p>Come sono arrivato a questo metodo? Leggendo in giro e dialogando con l&#8217;AI. Serve molta autocritica e pensiero laterale, chiedendosi ogni tanto: posso migliorare qualcosa?</p><p>Ma torniamo alla domanda iniziale: <em><strong>chi ha veramente scalato la montagna?</strong></em></p><p>Per rispondere uso una metafora: mi sento come se avessi scalato una montagna molto alta, arrivando dove non avrei pensato, ma ero dotato di un <strong>sofisticato esoscheletro</strong> (l&#8217;AI) che ha <strong>amplificato</strong> enormemente le mie capacit&#224;.<br>Ma l&#8217;esoscheletro da solo non va da nessuna parte. E pi&#249; diventi bravo a sfruttarne le potenzialit&#224;, pi&#249; procedi spedito.</p><h2>Cosa ho osservato ed imparato</h2><p><strong>Luned&#236; 13 aprile</strong>, il repository &#232; ufficialmente pubblico, la <strong>scommessa</strong> &#232; conclusa ed &#232; ora di tracciare un bilancio.</p><p>Sono riuscito nel mio obiettivo? Decisamente s&#236;!</p><p>Ce l&#8217;avrei fatta senza l&#8217;aiuto dell&#8217;AI? Decisamente no!</p><p>Il primo aspetto chiave da evidenziare &#232; la <strong>relazione di collaborazione</strong> che si instaura tra te e l&#8217;AI.</p><p>C&#8217;&#232; di mezzo un processo di continuo apprendimento reciproco. Pi&#249; tu impari ad utilizzare lo strumento nel contesto del progetto, pi&#249; lui impara a conoscerti, con in mezzo una parola chiave: <em><strong>comunicazione</strong></em>.</p><p>L&#8217;AI applicata alla programmazione ha ribaltato un paradigma: non sei pi&#249; tu a dover imparare un linguaggio, &#232; lo strumento che ha imparato il tuo.</p><p>Questo sposta il focus dal <em><strong>come</strong></em> ottenere un risultato al <em><strong>cosa</strong></em> voglio realmente ottenere.</p><p>Perch&#233; questo meccanismo funzioni serve per&#242; che chi avvia la comunicazione (tu) sia capace di farlo nella maniera migliore.</p><p>Ho capito infatti che l&#8217;AI &#232; un potente <strong>amplificatore</strong>: se escono idee confuse il risultato sar&#224; estremamente confuso, se sono precise il risultato sar&#224; estremamente preciso.</p><p>Il secondo aspetto fondamentale su cui ragionare &#232; la <strong>conoscenza della materia</strong>: senza sapere esattamente come funzionano le cose si rischiano risultati divergenti dall&#8217;obiettivo senza rendersene conto, vedi il caso <strong>NTLM</strong> citato in precedenza.</p><p>Questo significa che con l&#8217;AI non ci si pu&#242; adagiare &#8220;tanto ci pensa lei&#8221;, anzi bisogna concentrarsi nell&#8217;imparare il pi&#249; possibile come funzionano le cose. Questo valorizzer&#224; il ruolo di <em><strong>architetto</strong></em> che sar&#224; sempre pi&#249; importante.</p><p>Il terzo aspetto su cui ragionare &#232; che i sistemi di AI sono alla fine degli <strong>strumenti</strong>, e come tali vanno impiegati al meglio.</p><p>Per questo motivo bisogna approcciarli con <strong>metodo</strong>, provando, sbagliando e mettendosi in discussione per migliorarlo. Ma attenzione, <em><strong>non esiste un solo metodo giusto</strong></em>, ognuno trover&#224; quello migliore per s&#233; stesso e per lo specifico contesto nel quale si trova ad operare.</p><p>Il mio metodo ha funzionato perch&#233; non era gi&#224; scritto in partenza, ma l&#8217;ho costruito passo-passo chiedendomi: <strong>cosa posso fare meglio?</strong></p><p>Chiudo i ragionamenti con un motto che mi porto dietro da 25 anni e che oggi trovo pi&#249; attuale che mai:</p><div><hr></div><p style="text-align: center;">i sistemi informatici non fanno quello che vuoi, ma quello che gli dici di fare.</p><div><hr></div><p>Spero che questo racconto ti abbia appassionato almeno quanto ha appassionato me realizzarlo. La storia per&#242; non finisce qui. Quando leggerai questo articolo il codice si sar&#224; gi&#224; evoluto, e non posso andare avanti da solo.</p><p>L&#224; fuori c&#8217;&#232; un <a href="https://github.com/Marco-Lelli/legacy-mcp">repository</a> che aspetta di essere provato. Mettilo alla prova e fammi sapere come ti sei trovato.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Grazie per aver letto Legacy Things! Iscriviti gratuitamente per supportare il mio lavoro.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Legacy MCP: The Bet]]></title><description><![CDATA[What can an old sysadmin build with 20 euros in one month?]]></description><link>https://www.legacythings.it/p/legacy-mcp-the-bet</link><guid isPermaLink="false">https://www.legacythings.it/p/legacy-mcp-the-bet</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Tue, 28 Apr 2026 16:20:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!McmZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d92bc64-111c-4e74-a3e7-84c8d77bcfee_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Versione italiana disponibile qui &#8594;</em><a href="https://www.legacythings.it/p/capitolo-1-adminsdholder-il-guardiano"> </a><em><a href="https://www.legacythings.it/p/legacy-mcp-la-scommessa">[IT]</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!McmZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d92bc64-111c-4e74-a3e7-84c8d77bcfee_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!McmZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d92bc64-111c-4e74-a3e7-84c8d77bcfee_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!McmZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d92bc64-111c-4e74-a3e7-84c8d77bcfee_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!McmZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d92bc64-111c-4e74-a3e7-84c8d77bcfee_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!McmZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d92bc64-111c-4e74-a3e7-84c8d77bcfee_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!McmZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d92bc64-111c-4e74-a3e7-84c8d77bcfee_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1d92bc64-111c-4e74-a3e7-84c8d77bcfee_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3186187,&quot;alt&quot;:&quot;Image showing the text &#8220;LEGACY MCP&#8221; in red neon style over a blurred green background. At the centre, a young plant with two leaves grows from the ground. Above the surface the stem and leaves are visible, while below the soil a glowing, branched root system is shown.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/194910869?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d92bc64-111c-4e74-a3e7-84c8d77bcfee_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image showing the text &#8220;LEGACY MCP&#8221; in red neon style over a blurred green background. At the centre, a young plant with two leaves grows from the ground. Above the surface the stem and leaves are visible, while below the soil a glowing, branched root system is shown." title="Image showing the text &#8220;LEGACY MCP&#8221; in red neon style over a blurred green background. At the centre, a young plant with two leaves grows from the ground. Above the surface the stem and leaves are visible, while below the soil a glowing, branched root system is shown." srcset="https://substackcdn.com/image/fetch/$s_!McmZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d92bc64-111c-4e74-a3e7-84c8d77bcfee_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!McmZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d92bc64-111c-4e74-a3e7-84c8d77bcfee_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!McmZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d92bc64-111c-4e74-a3e7-84c8d77bcfee_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!McmZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d92bc64-111c-4e74-a3e7-84c8d77bcfee_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>Friday, 13 March 2026</strong>, a date that might look ordinary. Some cultures consider it unlucky, but for me it has a very specific meaning: I had an idea, and I wanted to make it real.</p><p>In fact, the seeds of that idea came from a path that started earlier.</p><p>The first seed goes back to 6 May 2025: European Identity Conference in Berlin, second session of the day. Among the top trends expected for 2025 there was the rise of MCP Servers.</p><p>I looked at my colleague, and we asked the same question: what on earth is an MCP Server? We need to dig into this!</p><p>Months passed and exactly as predicted, MCP Servers started popping up everywhere.</p><p>The second seed goes back to 25 February 2026: for a while I had felt the need to write about &#8220;legacy stuff&#8221;, I spoke with a colleague and finally found the right home for my project. I immediately decided to open this Substack blog and, within a week, I published my first article. It was 1 March 2026.</p><p>Being on this platform also gave me the chance to read many interesting posts from other authors. Most of the time these topics are technically far from my day job, yet they resonate deeply with the way I look at things.</p><p>But let&#8217;s go back to 13 March 2026. I read a post about the evolution of Claude.ai. It talked about how powerful the new models are, and about an experiment in extreme Vibe Coding.</p><p>That was the final seed&#8230;</p><p>The idea started germinating in my head. That evening I began my first conversation with the Claude app. A short back and forth, and suddenly it had a shape:</p><div><hr></div><p style="text-align: center;">What if I tried to write an MCP interface for Active Directory?</p><div><hr></div><p>I slept on it (more or less) and woke up with a fairly clear picture in my mind.</p><p>After breakfast I started bombarding the AI with a complete memory dump, and it kept the pace. We reached an initial draft, but the sun was shining and the tall grass was calling. Time to step away.</p><p>Cut the grass, reflect, unload, cut again, reflect again, unload again, and so on&#8230;</p><p>Second round in the afternoon. Another massive dump and the design became crystal clear, so I decided it was time to place a <strong>bet</strong>:</p><p><em><strong>Can an old sysadmin, with a programming background that stopped at Visual Basic 6, but a solid understanding of systems, build an open source MCP Server project from scratch?</strong></em></p><p>Right then, I spent 20 euros to access Claude Code and <strong>the Legacy MCP project was officially born</strong>.</p><p>Sunday, 15 March 2026, I woke up and dedicated time to my passion for Formula 1, and I was right to do it.</p><p>A young Italian talent, just 19 years old, started from pole position, dominated the race and secured his first victory, confirming a <strong>bet</strong> Mercedes had made on him when he was only 11. His name is Andrea Kimi Antonelli.</p><p>I was euphoric and convinced it would be a great day. After lunch I &#8220;fired up&#8221; the machines and started working, and a couple of hours later I had my first working prototype.</p><p>When I realised I could query the data exactly the way I had imagined, my jaw dropped. I was literally staring at the screen thinking: yes, this is a <strong>bet</strong> worth bringing to the finish line!</p><p>This article is not meant to explain a technology. It is meant to tell a journey.</p><p>It is the story of what happens when a legacy idea meets new tools, and someone decides <strong>to really try</strong>, connecting two worlds.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.legacythings.it/subscribe?"><span>Iscriviti ora</span></a></p><h2>Why it was worth doing</h2><p>If you have read my previous articles (<a href="https://www.legacythings.it/p/chapter-1-adminsdholder-the-guardian">Chapter 1</a> and <a href="https://www.legacythings.it/p/chapter-2-a-matter-of-trust">Chapter 2</a>) you already know my point of view. For new readers, here is the short version: despite the push towards the cloud, legacy technologies keep surviving. Over time, however, they are becoming increasingly mysterious, and we need a way to pass that knowledge on.</p><p>Every project started by my team begins in the same way: we need to run an assessment and produce a document.</p><p>And in most cases, the heart of that assessment is always the same: <strong>Active Directory</strong>.</p><p>For years we relied on trusty <strong>PowerShell </strong>scripts, more or less standardised, but anchored to one constant: the excellent <a href="https://github.com/CarlWebster/Active-Directory-V3">ADDS_Inventory_V3.ps1</a> by the legendary Carl Webster.</p><p>The problem is that maintaining and evolving those scripts is becoming increasingly expensive, while the outside world is surfing fast on the AI wave.</p><p>I did not want to throw that heritage away. I wanted to make it queryable, modular and reusable.</p><p>So, I asked myself a simple question: <em>why not try to connect these two worlds?</em></p><p>The turning point was the <strong>MCP protocol</strong>. It is often described as &#8220;the USB port for AI&#8221;, an open standard that lets AI systems connect to external modules of any kind.</p><p>If you want to dive deeper, here is the official documentation: <a href="https://modelcontextprotocol.io/docs/getting-started/intro">What is the Model Context Protocol (MCP)?</a></p><p>That is how the idea was born: build an <strong>MCP Server</strong> acting as a bridge between the <strong>Active Directory world</strong> and <strong>AI systems</strong>: <a href="https://github.com/Marco-Lelli/legacy-mcp">Legacy MCP</a>.</p><p>In practice, a standard way to query AD using AI tools, shifting the focus from <em><strong>how</strong></em> to do things to <em><strong>what</strong></em> you want to achieve.</p><p>As mentioned earlier, during the first two days I had intense sessions with Claude Chat. I defined principles and guidelines that allowed me to see tangible results in less than 48 hours.</p><p>One of those principles was a clear boundary between <strong>open core</strong> and <strong>enterprise</strong>. Even if it starts with &#8220;just&#8221; 20 euros, doing things properly takes time, so boundaries are necessary.</p><p>The choice was natural and coherent:</p><div><hr></div><p style="text-align: center;">if the project takes inspiration from Carl Webster&#8217;s work, then the open core must cover everything ADDS_Inventory_V3.ps1 covered for years.</p><div><hr></div><p>It is a way to give something back to the community, updated to modern technologies.</p><p>On top of that, an enterprise layer will be built, requiring different investments and efforts, covering more advanced and sophisticated capabilities.</p><p>&#183; <strong>open core</strong> = inventory and core queries</p><p>&#183; <strong>enterprise</strong> = advanced analysis, reports and integrations</p><h2>What it can do for you</h2><p>Legacy MCP was born with a simple goal: make Active Directory queryable, enabling cross correlations across data and shifting the focus towards <strong>what I really need to understand</strong>.</p><p>Depending on the context (offline, local network, internet) the same approach is implemented through different <strong>deployment profiles</strong>, designed to balance usability and security: <strong>A / B core / B enterprise / C.</strong></p><p>Across all profiles, the logic stays the same: you bring data into a workspace, then you query. What changes is <em><strong>where</strong></em> servers and data live, and <em><strong>how</strong></em> access is governed.</p><p>All operational details are available in the <a href="https://github.com/Marco-Lelli/legacy-mcp">repository</a>, but here we focus on real world use cases.</p><p>Three scenarios, three trust levels: <em>file, LAN, internet.</em></p><h3>Use case 1 - Remote offline assessment and report</h3><p><strong>Profile:</strong> A (open core)</p><p><strong>Scenario:</strong> A consultant needs to analyse a remote AD environment. Sometimes they have direct access via VPN or a shared session, in other cases data collection is delegated to the customer.</p><p><strong>Approach:</strong> Instead of generating a static report, the consultant collects data in a standard way using a PowerShell collector or asks the customer to run it. The output is a <strong>JSON</strong> file with data and session metadata.</p><p><strong>Analysis:</strong> On their own PC, the consultant runs Legacy MCP locally, &#8220;mounts&#8221; the JSON into the workspace, and queries the environment through Claude Desktop.</p><p><strong>Result:</strong> A structured analysis focused on the areas that matter, and, when needed, a document style output. In this project, a few DOCX reports have already been produced and validated on real environments.</p><p>A real example follows. This is the kind of answer Legacy MCP can deliver in seconds to a concrete question about the environment:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZmAw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb908c52c-7901-4ae1-9cbb-823c086aa970_940x929.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZmAw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb908c52c-7901-4ae1-9cbb-823c086aa970_940x929.png 424w, https://substackcdn.com/image/fetch/$s_!ZmAw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb908c52c-7901-4ae1-9cbb-823c086aa970_940x929.png 848w, https://substackcdn.com/image/fetch/$s_!ZmAw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb908c52c-7901-4ae1-9cbb-823c086aa970_940x929.png 1272w, https://substackcdn.com/image/fetch/$s_!ZmAw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb908c52c-7901-4ae1-9cbb-823c086aa970_940x929.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZmAw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb908c52c-7901-4ae1-9cbb-823c086aa970_940x929.png" width="940" height="929" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b908c52c-7901-4ae1-9cbb-823c086aa970_940x929.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:929,&quot;width&quot;:940,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:629578,&quot;alt&quot;:&quot;Screenshot of an AI chat conversation. At the top there is a question about upgrading Domain Controllers. Below, a structured answer lists the main blockers and risks, including end of support operating system, concentrated FSMO roles, the need for adprep, and coordination between sites.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/194910869?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb908c52c-7901-4ae1-9cbb-823c086aa970_940x929.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot of an AI chat conversation. At the top there is a question about upgrading Domain Controllers. Below, a structured answer lists the main blockers and risks, including end of support operating system, concentrated FSMO roles, the need for adprep, and coordination between sites." title="Screenshot of an AI chat conversation. At the top there is a question about upgrading Domain Controllers. Below, a structured answer lists the main blockers and risks, including end of support operating system, concentrated FSMO roles, the need for adprep, and coordination between sites." srcset="https://substackcdn.com/image/fetch/$s_!ZmAw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb908c52c-7901-4ae1-9cbb-823c086aa970_940x929.png 424w, https://substackcdn.com/image/fetch/$s_!ZmAw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb908c52c-7901-4ae1-9cbb-823c086aa970_940x929.png 848w, https://substackcdn.com/image/fetch/$s_!ZmAw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb908c52c-7901-4ae1-9cbb-823c086aa970_940x929.png 1272w, https://substackcdn.com/image/fetch/$s_!ZmAw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb908c52c-7901-4ae1-9cbb-823c086aa970_940x929.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Analysis goes beyond data</figcaption></figure></div><p>This is the simplest profile: it maximises portability and repeatability and minimises dependence on the customer environment. It also enables cross analysis across related environments.</p><h3>Use case 2 - Interactive live dialogue and historical comparison with snapshots</h3><p><strong>Profile:</strong> B core or B enterprise (depending on the required security level).</p><p><strong>Scenario:</strong> IT teams or consultants want to query the environment &#8220;live&#8221;, with the convenience of a chat driven interaction, without constantly exporting files.</p><p><strong>Approach:</strong> Legacy MCP runs on the local network on a server inside the Active Directory environment (a member server). Communications are encrypted and the authentication model matches the chosen profile.</p><p><strong>Interaction:</strong> Clients (Claude Desktop) connect to the MCP server through a bridge module (mcp-remote) on the LAN. In this project, this pattern has been tested end to end on Profile B core with HTTPS and authentication based on protected tokens and keys.</p><p><strong>Extra value:</strong> When &#8220;memory&#8221; matters, you create snapshots over time. This lets you mount snapshots and the live view together and ask the simplest and most powerful question: <strong>what changed?</strong></p><p>Because it operates on live data, Profile B has stricter security requirements (dedicated service account, end to end encryption, governed access). Details are in the <a href="https://github.com/Marco-Lelli/legacy-mcp">repository</a>.</p><p><strong>Important note:</strong> Legacy MCP exposes read only functions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uhfr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7868916-e1c7-4dcd-9b8d-c1fee9288bd8_1024x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uhfr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7868916-e1c7-4dcd-9b8d-c1fee9288bd8_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uhfr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7868916-e1c7-4dcd-9b8d-c1fee9288bd8_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uhfr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7868916-e1c7-4dcd-9b8d-c1fee9288bd8_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uhfr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7868916-e1c7-4dcd-9b8d-c1fee9288bd8_1024x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uhfr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7868916-e1c7-4dcd-9b8d-c1fee9288bd8_1024x1024.jpeg" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a7868916-e1c7-4dcd-9b8d-c1fee9288bd8_1024x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:157809,&quot;alt&quot;:&quot;Illustration featuring the title &#8220;LEGACY MCP&#8221; in red neon style. At the centre there is a stone portal split vertically. On one side, graphical elements related to code and data analysis are shown, on the other a server and a three&#8209;headed mythological creature. Beneath the portal, a glowing root system spreads outward.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/194910869?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7868916-e1c7-4dcd-9b8d-c1fee9288bd8_1024x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustration featuring the title &#8220;LEGACY MCP&#8221; in red neon style. At the centre there is a stone portal split vertically. On one side, graphical elements related to code and data analysis are shown, on the other a server and a three&#8209;headed mythological creature. Beneath the portal, a glowing root system spreads outward." title="Illustration featuring the title &#8220;LEGACY MCP&#8221; in red neon style. At the centre there is a stone portal split vertically. On one side, graphical elements related to code and data analysis are shown, on the other a server and a three&#8209;headed mythological creature. Beneath the portal, a glowing root system spreads outward." srcset="https://substackcdn.com/image/fetch/$s_!uhfr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7868916-e1c7-4dcd-9b8d-c1fee9288bd8_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!uhfr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7868916-e1c7-4dcd-9b8d-c1fee9288bd8_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!uhfr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7868916-e1c7-4dcd-9b8d-c1fee9288bd8_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!uhfr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7868916-e1c7-4dcd-9b8d-c1fee9288bd8_1024x1024.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Live (kerberos) and offline (JSON) in one workspace</figcaption></figure></div><h3>Use case 3 - Internet exposed analysis portal</h3><p><strong>Profile:</strong> C (enterprise only)</p><p><strong>Scenario:</strong> You want to make the assessment scalable and usable as a service: multiple teams, multiple customers, access from anywhere, without requiring live access to the infrastructure.</p><p><strong>Approach:</strong> Everything stays offline. You upload JSON datasets and manage workspaces via web. Analysis happens through agents that consume MCP over public endpoints.</p><p><strong>Security:</strong> This profile requires an internet grade protection layer: API gateway (for example APIM) plus WAF. Authentication is delegated to an Identity Provider (typically Entra ID) with MFA, plus RBAC on uploaded data.</p><p><strong>Why it makes sense:</strong> It is the step that turns a tool into a platform, keeping the same logical model (profiles, workspaces, snapshots/offline), but adding governance and enterprise access.</p><p>For now, this is a theoretical use case, but the specifications are already clear. Vibe Coding is great, but there is no way I could have built all of that alone in one month.</p><h2>Rome wasn&#8217;t built in a day</h2><p>Thinking about Vibe Coding immediately switches me into <strong>Legacy Things</strong> mode, and in my head, I can hear a well-known song released in 2000: <strong>Rome Wasn&#8217;t Built in a Day</strong> by <strong>Morcheeba.</strong></p><p>It is the perfect soundtrack for the month-long journey behind this bet.</p><p>Everywhere I read articles and proclamations that sound more or less like this:</p><div><hr></div><p style="text-align: center;">how I created something from scratch in 35 minutes thanks to AI and Vibe Coding.</p><div><hr></div><p>From my point of view, that is a half-truth designed to capture attention. Maybe my choice not to use an extreme coding model (Claude Sonnet 4.6) also plays a role, but I want to tell you how I really lived the experience.</p><h3>First point</h3><p>It is true that once you provide instructions, a coding engine can produce output in minutes. The real question is this: how much time did I spend thinking, reasoning on my own, and talking with an AI chat before I even reached those instructions?</p><p>Using the initial idea as an example, I already told you: two days.</p><p>Then it took another 28 days to reach a point where I could say: &#8220;ok, we can publish this&#8221;.</p><p>Of course it depends on &#8220;what&#8221; you want to build. Effort is proportional to ambition.</p><h3>Second point</h3><p>Beyond time, you need a clear direction and a steady hand, otherwise the AI will take you for a walk wherever it wants.</p><p>For example, during a long and painful debugging session on live authentication towards Domain Controllers, the AI tried to persuade me to simplify the approach by switching from Kerberos to NTLM.</p><p>That is where I stood still and reinforced my security principles, and in the end, we made it work the way I wanted.</p><p>In the project memory, I now read: <em><strong>NTLM must never be used</strong>. Deprecated. Kerberos only for Live Mode.</em></p><h3>Third point</h3><p>AI does not always find the best solution on its own. Sometimes it loses the key detail.</p><p>Another example: while configuring secure client-side access to the MCP server, I struggled with how to handle the API key without exposing it. The solution was to use PowerShell and <a href="https://learn.microsoft.com/en-us/windows/win32/seccng/cng-dpapi">DPAPI</a>.</p><p>Everything looked great until launching PowerShell from Claude Chat crashed with a strange error. After another intense troubleshooting session, the key intuition was mine: run the PowerShell through a simple BAT file, and the problem disappeared immediately.</p><p>That session lives in the project memory as <strong>&#8220;BAT is King&#8221;</strong>, in perfect Legacy Things style, where an &#8220;old&#8221; technology fixes an AI problem.</p><h3>Timeline</h3><p>Below is a timeline of what I managed to achieve and in what time. Looking at it, I am genuinely impressed, but this is not a 35-minute story:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4qbg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f3e1c4-d24e-4b06-bc6e-fcf78a0683eb_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4qbg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f3e1c4-d24e-4b06-bc6e-fcf78a0683eb_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!4qbg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f3e1c4-d24e-4b06-bc6e-fcf78a0683eb_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!4qbg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f3e1c4-d24e-4b06-bc6e-fcf78a0683eb_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!4qbg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f3e1c4-d24e-4b06-bc6e-fcf78a0683eb_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4qbg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f3e1c4-d24e-4b06-bc6e-fcf78a0683eb_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/94f3e1c4-d24e-4b06-bc6e-fcf78a0683eb_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2944761,&quot;alt&quot;:&quot;Infographic titled &#8220;Legacy MCP &#8211; From Idea to Production in 28 Days&#8221;. At the top, a horizontal timeline shows dated milestones describing the project&#8217;s evolution from offline mode to a public repository. At the bottom left, a &#8220;Key Numbers&#8221; section lists technical metrics, while the Legacy MCP project logo appears on the right.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/194910869?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f3e1c4-d24e-4b06-bc6e-fcf78a0683eb_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Infographic titled &#8220;Legacy MCP &#8211; From Idea to Production in 28 Days&#8221;. At the top, a horizontal timeline shows dated milestones describing the project&#8217;s evolution from offline mode to a public repository. At the bottom left, a &#8220;Key Numbers&#8221; section lists technical metrics, while the Legacy MCP project logo appears on the right." title="Infographic titled &#8220;Legacy MCP &#8211; From Idea to Production in 28 Days&#8221;. At the top, a horizontal timeline shows dated milestones describing the project&#8217;s evolution from offline mode to a public repository. At the bottom left, a &#8220;Key Numbers&#8221; section lists technical metrics, while the Legacy MCP project logo appears on the right." srcset="https://substackcdn.com/image/fetch/$s_!4qbg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f3e1c4-d24e-4b06-bc6e-fcf78a0683eb_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!4qbg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f3e1c4-d24e-4b06-bc6e-fcf78a0683eb_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!4qbg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f3e1c4-d24e-4b06-bc6e-fcf78a0683eb_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!4qbg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f3e1c4-d24e-4b06-bc6e-fcf78a0683eb_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">One month, many milestones</figcaption></figure></div><p>Rome wasn&#8217;t built in a day, and neither was this project. AI accelerates everything, but without a guide it would simply crash.</p><p>It can help you reach very high peaks, but once you get there, there is one question we must ask: <strong>who really climbed the mountain?</strong></p><h2>Who really climbed the mountain?</h2><p>When the idea took shape and I decided to dedicate serious time to the project, I felt as if I had a mountain to climb. At first that scared me a bit, but I had nothing to lose, and I knew I could rely on truly cutting-edge AI tools.</p><p>I started with a standard baseline on chat-based AI and I knew nothing about AI assisted coding. I was a real &#8220;newbie&#8221;.</p><p>Over time I challenged myself, studied, and understood that to do a good job you need solid soft skills: clear ideas, strong communication skills, tenacity, and a lot of method.</p><p>I deliberately chose to write code in a language I do not really know (Python) because what mattered to me was not the code itself, but the result.</p><p>After the first few weeks I realised that the main technical limit was the &#8220;credit&#8221;. Work sessions had to be distributed and optimised across the day and the week. Without careful management, you run &#8220;out of fuel&#8221; at the worst possible time.</p><p>To keep credit consumption low, the key was to reduce context: using the same chat for days saturates the context window and consumes a huge amount of tokens.</p><p>Over time I built a structured workflow in three levels that I want to describe.</p><p>Tools used: <strong>Claude.ai</strong> (Pro plan for one month) plus <strong>Perplexity.ai</strong>, a Pro plan I already had through a yearly promotion.</p><p>I then created a <strong>project</strong> inside <strong>Claude</strong> and a <strong>space</strong> inside <strong>Perplexity</strong>. In both, I attached a <strong>status.md</strong> file with the overall summary. The same file is also placed in the project root for <strong>Claude Code</strong>.</p><p>For coding, I used <strong>VS Code</strong> with the <strong>Claude Code</strong> extension.</p><p><strong>Input </strong>flow:</p><p>1. First <strong>draft</strong> reasoning on <strong>Perplexity</strong> using <strong>Sonnet 4.6</strong> for consistency with later steps.</p><p>2. <strong>Perplexity&#8217;s</strong> instruction <strong>draft</strong> is then passed to <strong>Claude Chat</strong> for review and refinement. <strong>Claude Chat</strong> starts a <strong>new session</strong> from <strong>status.md</strong> and generates the <strong>instructions</strong> for <strong>Claude Code</strong>.</p><p>3. <strong>Claude Code</strong> executes and produces a <strong>summary</strong>.</p><p>4. <strong>Claude Chat</strong> reviews the summary and, once the result is stable, <strong>closes the session</strong> and updates <strong>status.md</strong>.</p><p>5. The updated <strong>status.md</strong> is then attached everywhere as the new single source of truth.</p><p><strong>Output </strong>flow:</p><p>1. <strong>Claude Chat&#8217;s summary</strong> is passed back to <strong>Perplexity</strong> as feedback.</p><p>2. <strong>Testing</strong> and <strong>debugging</strong> sessions start.</p><p>3. When <strong>variations</strong> are needed, the flow goes back into <strong>Claude Chat</strong>.</p><p>How did I get to this method? By reading, experimenting and talking with the AI. It takes self-criticism and lateral thinking, asking yourself from time to time: can I improve something?</p><p>But back to the original question: <em><strong>who really climbed the mountain?</strong></em></p><p>My answer is a metaphor: I feel as if I climbed a very high mountain and reached a place I would not have expected, but I had a <strong>sophisticated exoskeleton</strong> (AI) that massively <strong>amplified</strong> my capabilities.</p><p>An exoskeleton, however, does not go anywhere on its own. The better you become at exploiting its potential, the faster you move.</p><h2>What I observed and learned</h2><p>On <strong>Monday, 13 April</strong>, the repository officially became public. The <strong>bet</strong> is over, and it is time to take stock.</p><p>Did I achieve my goal? Definitely yes!<br>Could I have done it without AI? Definitely no!</p><p>The first key aspect is the <strong>collaborative relationship</strong> that emerges between you and AI.</p><p>There is a continuous process of mutual learning. The more you learn to use the tool in the context of the project, the more it learns to understand you, with one key word in the middle: <em><strong>communication</strong></em>.</p><p>AI applied to programming flipped a paradigm: you no longer must learn a language, the tool learns yours.</p><p>This shifts the focus from <em><strong>how</strong></em> to get a result to <em><strong>what</strong></em> you really want to get.</p><p>For this mechanism to work, the person starting the conversation (you) must be able to do it in the best possible way.</p><p>I realised that AI is a powerful <strong>amplifier</strong>: if your ideas are confused, the result will be extremely confused, if they are precise, the result will be extremely precise.</p><p>The second fundamental aspect is <strong>domain knowledge</strong>: without knowing exactly how things work, you risk drifting away from the goal without noticing, as in the <strong>NTLM</strong> case mentioned earlier.</p><p>This means that with AI you cannot just relax thinking &#8220;it will handle everything&#8221;. On the contrary, you should focus on learning as much as possible about how things work. This will increase the value of the <em><strong>architect</strong></em> role, which will only become more important.</p><p>The third aspect is that AI systems are <strong>tools</strong>, and like any tool they must be used well.</p><p>That is why you need <strong>method</strong>: try, fail, question yourself and improve. Be careful though, there <em><strong>is no single correct method</strong></em>. Everyone will find what works best for themselves and for their context.</p><p>My method worked because it was not written upfront. I built it step by step, constantly asking myself: <strong>what can I do better?</strong></p><p>I will close with a motto I have carried for 25 years, and today it feels more relevant than ever:</p><div><hr></div><p style="text-align: center;">IT systems do not do what you want. They do what you tell them to do.</p><div><hr></div><p>I hope this story was at least as engaging for you as it was for me to live it. But the journey does not end here. By the time you read this article, the code will already have evolved, and I cannot move forward alone.</p><p>Out there, there is a <a href="https://github.com/Marco-Lelli/legacy-mcp">repository</a> waiting to be tested. Put it to the test and tell me how it went.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Legacy Things! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Capitolo #2 – Una questione di fiducia]]></title><description><![CDATA[Oltre il limite del perimetro]]></description><link>https://www.legacythings.it/p/capitolo-2-una-questione-di-fiducia</link><guid isPermaLink="false">https://www.legacythings.it/p/capitolo-2-una-questione-di-fiducia</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Mon, 30 Mar 2026 06:15:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ekbm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd745b109-49ff-4a4b-9282-bbea9ab0fb27_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>English version available here &#8594;<a href="https://www.legacythings.it/p/chapter-2-a-matter-of-trust"> [EN]</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ekbm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd745b109-49ff-4a4b-9282-bbea9ab0fb27_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ekbm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd745b109-49ff-4a4b-9282-bbea9ab0fb27_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Ekbm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd745b109-49ff-4a4b-9282-bbea9ab0fb27_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Ekbm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd745b109-49ff-4a4b-9282-bbea9ab0fb27_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Ekbm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd745b109-49ff-4a4b-9282-bbea9ab0fb27_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ekbm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd745b109-49ff-4a4b-9282-bbea9ab0fb27_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d745b109-49ff-4a4b-9282-bbea9ab0fb27_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3021479,&quot;alt&quot;:&quot;Illustrazione di un&#8217;auto da Formula 1 in curva su pista, usata come metafora del capitolo sulla fiducia e sui limiti del perimetro di autenticazione.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/192079223?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd745b109-49ff-4a4b-9282-bbea9ab0fb27_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustrazione di un&#8217;auto da Formula 1 in curva su pista, usata come metafora del capitolo sulla fiducia e sui limiti del perimetro di autenticazione." title="Illustrazione di un&#8217;auto da Formula 1 in curva su pista, usata come metafora del capitolo sulla fiducia e sui limiti del perimetro di autenticazione." srcset="https://substackcdn.com/image/fetch/$s_!Ekbm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd745b109-49ff-4a4b-9282-bbea9ab0fb27_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Ekbm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd745b109-49ff-4a4b-9282-bbea9ab0fb27_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Ekbm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd745b109-49ff-4a4b-9282-bbea9ab0fb27_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Ekbm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd745b109-49ff-4a4b-9282-bbea9ab0fb27_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Primavera 1993</strong>, chi scrive sta ancora ultimando gli studi.</p><p>Una domenica di aprile si corre il GP di F1 a Donington, UK. Per il leggendario <strong>Ayrton Senna</strong> &#232; un anno difficile, la sua McLaren &#232; inferiore alla concorrenza ed in griglia parte quinto, ma c&#8217;&#232; un dettaglio che gioca a suo favore: <em><strong>piove!</strong> </em>E quando piove la sua <strong>fiducia</strong> nel mezzo diventa totale.</p><p>Semaforo verde, scatta come una furia e nel primo giro si porta gi&#224; in testa per un dominio assoluto, nessun altro ha la sua confidenza con la pista bagnata.</p><p>Nel resto del mondo, in quegli stessi mesi, qualcosa di altrettanto straordinario sta prendendo forma<s>,</s> cambiando radicalmente il modo in cui le persone si <strong>fidano</strong> dei sistemi informatici.</p><p>Con la diffusione del <strong>World Wide Web</strong> e la distribuzione del browser <strong>NCSA Mosaic</strong>, Internet smette di essere un ambiente riservato a pochi addetti ai lavori e diventa improvvisamente accessibile.<br>Chiunque pu&#242; collegarsi, esplorare risorse remote, interagire con sistemi che non conosce e che non controlla.</p><p>Fino a quel momento, i modelli di sicurezza erano stati costruiti attorno a confini chiari: reti aziendali, sistemi locali, domini ben definiti.<br>Con il Web, invece, ci si affida a servizi lontani, identit&#224; remote, infrastrutture che vivono fuori dal proprio controllo diretto.</p><p>&#200; una rivoluzione culturale prima ancora che tecnologica.</p><p>Nei sistemi Enterprise il tema della fiducia si gioca su due fronti contrapposti.</p><p>Da un lato, l&#8217;universo <strong>Windows</strong> si diffonde basandosi su un modello di fiducia chiuso e perimetrale, che coincide con i primi domini.<br>&#200; qui che viene introdotto per la prima volta un concetto esplicito di <strong>Trust</strong>, fondato su un protocollo proprietario: <strong>NTLM</strong>.<br>Un meccanismo pensato per ambienti controllati, dove la fiducia &#232; una configurazione statica e dichiarata.</p><p>Dall&#8217;altro, il mondo <strong>Unix</strong> e accademico utilizza da tempo modelli di autenticazione distribuita, che raggiungono una maturit&#224; significativa con <strong>Kerberos V5</strong>.<br>Qui la fiducia non &#232; solo un collegamento tra sistemi, ma un elemento progettato per ambienti aperti, interconnessi e potenzialmente eterogenei.</p><p>Sono due visioni della <strong>fiducia</strong> profondamente diverse, nate per rispondere a esigenze diverse.</p><p>Con l&#8217;introduzione di <strong>Active Directory</strong><s>,</s> Microsoft compie per&#242; una scelta fondamentale: accoglie i valori dell&#8217;altro modello e <strong>adotta Kerberos come base fondante del nuovo sistema di autenticazione</strong>, avviando un percorso di convergenza tra questi due mondi.<br>Inizialmente i modelli convivono, affiancati pi&#249; che integrati, come compromesso necessario per garantire compatibilit&#224; con il passato.</p><p>&#200; solo con <strong>Windows Server 2003</strong> che arriva una convergenza pi&#249; matura, segnando il passaggio verso un approccio <em>Kerberos-first</em>, in cui la fiducia diventa parte dell&#8217;architettura<s>,</s> e non solo un collegamento tra perimetri separati.</p><p>Eppure, nonostante questa convergenza sia avvenuta da oltre vent&#8217;anni, non sempre &#232; stata compresa fino in fondo.<br>Come se, paradossalmente, <strong>fosse mancata proprio la fiducia</strong> in quel processo che voleva riunire scuole di pensiero inizialmente molto distanti.</p><p>Questo capitolo parte da qui.<br>Da una fiducia che si &#232; evoluta tecnicamente, ma non sempre concettualmente, e dalle conseguenze di non aver davvero compreso quel cambiamento fino in fondo.</p><h2>Cos&#8217;&#232; e come funziona</h2><p>Abbiamo capito che il concetto di &#8220;Trust&#8221; arriva da lontano, proviamo adesso di declinarlo in maniera pratica nel contesto Active Directory.</p><h3>Meccanismi di base di una Trust</h3><p>Partiamo da un <s>concetto </s>principio che viene molto spesso dato per scontato: il Dominio di autenticazione.</p><p>Un Dominio &#232; un perimetro entro il quale &#232; presente una &#8220;fiducia&#8221; implicita tra gli oggetti che ne fanno parte, mediata da opportuni permessi che definiscono chi accede a cosa e con che modalit&#224; (ACL, ne abbiamo parlato nel capitolo 1). Tra perimetri differenti (Domini) non c&#8217;&#232; fiducia implicita e di conseguenza l&#8217;accesso non &#232; consentito.</p><p>L&#8217;elemento che contraddistingue tutti gli oggetti facenti parte dello stesso Dominio &#232; il <strong>Security Identifier (SID)</strong>.</p><p>Si tratta di un attributo fondamentale del modello di sicurezza di Windows: una stringa immutabile che identifica in modo univoco un&#8217;entit&#224; (utente, gruppo, computer&#8230;) indipendentemente dal nome che le viene assegnato.</p><p>Un SID ha una struttura ben precisa e pu&#242; essere rappresentato in forma leggibile come segue:</p><p>S-1-5-21-&lt;DomainIdentifier&gt;-&lt;RelativeIdentifier&gt;</p><p>La prima parte del SID identifica <strong>l&#8217;autorit&#224; che lo ha emesso</strong> e il <strong>contesto di sicurezza</strong> in cui l&#8217;oggetto &#232; stato creato.<br>In particolare, la sequenza S-1-5-21 indica che il SID appartiene a un contesto di dominio Windows, mentre il valore &lt;DomainIdentifier&gt; rappresenta l&#8217;identit&#224; del dominio stesso.</p><p>Questo significa che <strong>tutti gli oggetti appartenenti allo stesso dominio condividono esattamente la stessa porzione iniziale del SID</strong>.</p><p>L&#8217;ultima parte, chiamata <strong>Relative Identifier (RID)</strong>, &#232; invece ci&#242; che rende l&#8217;oggetto univoco all&#8217;interno di quel dominio.<br>Il RID viene assegnato dal Domain Controller al momento della creazione dell&#8217;oggetto e distingue un utente, un gruppo o un computer da tutti gli altri che condividono lo stesso Domain SID.</p><p>In altre parole, il SID racconta sempre due verit&#224;:</p><ul><li><p><em>da dove proviene l&#8217;oggetto</em> (il dominio che lo ha emesso)</p></li><li><p><em>chi &#232; l&#8217;oggetto</em> all&#8217;interno di quel dominio</p></li></ul><p>Questa separazione &#232; uno dei pilastri del modello di sicurezza di Active Directory, se volete approfondire l&#8217;argomento vi lascio il riferimento all&#8217;<a href="https://learn.microsoft.com/en-gb/windows-server/identity/ad-ds/manage/understand-security-identifiers">articolo ufficiale</a>.</p><p>Grazie a questo meccanismo, sin dalla prima versione dei Domini NT, &#232; stato reso disponibile il meccanismo di <strong>Domain Trust</strong>, inizialmente basato su protocollo <strong>NTLM</strong>.</p><p>&#200; bene ricordare che, anche concettualmente, la fiducia ha una direzione precisa.<s>,</s> <s>l</s>La stessa cosa vale per la Domain Trust<s>,</s> dove <strong>chi offre le risorse</strong> (es: un File Server in un Dominio di risorse) <strong>concede fiducia a</strong> <strong>chi offre le identit&#224;</strong> (Dominio delle utenze). Questa direzione viene rappresentata con una freccia che va dalle risorse alle identit&#224;.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CzK5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb0c260-d65f-448d-baa3-336d4a3af830_540x184.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CzK5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb0c260-d65f-448d-baa3-336d4a3af830_540x184.png 424w, https://substackcdn.com/image/fetch/$s_!CzK5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb0c260-d65f-448d-baa3-336d4a3af830_540x184.png 848w, https://substackcdn.com/image/fetch/$s_!CzK5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb0c260-d65f-448d-baa3-336d4a3af830_540x184.png 1272w, https://substackcdn.com/image/fetch/$s_!CzK5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb0c260-d65f-448d-baa3-336d4a3af830_540x184.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CzK5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb0c260-d65f-448d-baa3-336d4a3af830_540x184.png" width="540" height="184" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eeb0c260-d65f-448d-baa3-336d4a3af830_540x184.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:184,&quot;width&quot;:540,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3568,&quot;alt&quot;:&quot;Schema della direzione di una trust tra un dominio di risorse e un dominio utenti, con freccia da resource.ad verso user.ad.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/192079223?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb0c260-d65f-448d-baa3-336d4a3af830_540x184.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Schema della direzione di una trust tra un dominio di risorse e un dominio utenti, con freccia da resource.ad verso user.ad." title="Schema della direzione di una trust tra un dominio di risorse e un dominio utenti, con freccia da resource.ad verso user.ad." srcset="https://substackcdn.com/image/fetch/$s_!CzK5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb0c260-d65f-448d-baa3-336d4a3af830_540x184.png 424w, https://substackcdn.com/image/fetch/$s_!CzK5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb0c260-d65f-448d-baa3-336d4a3af830_540x184.png 848w, https://substackcdn.com/image/fetch/$s_!CzK5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb0c260-d65f-448d-baa3-336d4a3af830_540x184.png 1272w, https://substackcdn.com/image/fetch/$s_!CzK5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeb0c260-d65f-448d-baa3-336d4a3af830_540x184.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Direzione di una Trust</figcaption></figure></div><p>Quando viene attivata una Trust<s>,</s> il dominio di risorse non importa utenti n&#233; replica oggetti dal dominio trusted. <s><br></s>Accetta invece una cosa molto pi&#249; semplice e molto pi&#249; potente: <strong>i Security Identifier emessi dall&#8217;altro lato</strong>.</p><p>Nel momento in cui un oggetto esterno viene utilizzato per la prima volta &#8212; ad esempio aggiungendolo a un gruppo locale o assegnandogli un permesso &#8212; Active Directory crea automaticamente un <strong>Foreign Security Principal</strong>.</p><p>Un <a href="https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/5aa09c90-c5db-4e97-98d0-b7cdd6bc1bfe">Foreign Security Principal</a> non &#232; un vero account locale, ma un <strong>puntatore</strong>: un oggetto minimale che contiene esclusivamente il SID dell&#8217;entit&#224; remota.<br>Serve a consentire al dominio di risorse di includere identit&#224; esterne nei propri meccanismi di autorizzazione, senza doverne conoscere la struttura o replicarne gli attributi.</p><p>Ancora una volta, tutto ruota attorno alla <strong>fiducia</strong>: il dominio di risorse non sa <em>chi</em> sia quell&#8217;oggetto, ma si fida del fatto che il suo SID sia stato emesso da un&#8217;autorit&#224; considerata <em>attendibile</em>.</p><h3>L&#8217;evoluzione delle trust: da collegamenti puntuali a fiducia architetturale</h3><p>Nel primo modello di domini Windows, la fiducia &#232; un concetto semplice e molto concreto: due domini si conoscono, si parlano, si fidano l&#8217;uno dell&#8217;altro.<br>Nulla di pi&#249;. Ogni trust &#232; un collegamento esplicito, costruito a mano, che vale solo tra due estremi ben definiti. Se serve altro, si crea un&#8217;altra trust. E poi un&#8217;altra ancora.</p><p>&#200; un modello coerente con l&#8217;epoca: ambienti piccoli, perimetri chiari, poche interazioni.<br>Ma &#232; anche un modello che non scala. Ogni nuova relazione aumenta la complessit&#224; e, soprattutto, rende la fiducia fragile: basta dimenticare un collegamento perch&#233; qualcosa smetta di funzionare.</p><p>Con l&#8217;arrivo di Active Directory e la nascita del concetto di <em>forest</em>, Microsoft cambia approccio.<br>I domini non sono pi&#249; isole indipendenti, ma parti di una struttura pi&#249; ampia, pensata per condividere uno spazio di fiducia comune. A supportare un modello gerarchico di Domini nascono le trust <strong>intra-forest<s>,</s> che </strong>diventano automatiche, bidirezionali e transitive: la fiducia non &#232; pi&#249; una decisione puntuale, ma una propriet&#224; della struttura.</p><p>&#200; un passaggio fondamentale: per la prima volta la fiducia smette di essere un insieme di eccezioni e diventa una regola portante.</p><p>Quando per&#242; serve uscire da questo perimetro (collaborare con domini esterni, ambienti legacy o foreste completamente separate) si torna temporaneamente al passato.<br>Come eredit&#224; delle Domain Trust nascono le <strong>External Trust</strong>: collegamenti espliciti, non transitivi, volutamente limitati. Un compromesso necessario, pensato per contenere il rischio e ridurre l&#8217;esposizione.</p><p>Il problema &#232; che, nel frattempo, il mondo &#232; andato avanti.</p><p>Con <strong>Windows Server 2003</strong> arriva il tentativo di sintesi definitiva: la <strong>Forest Trust</strong>.<br>Non pi&#249; una fiducia tra singoli domini, ma tra insiemi di domini. Non pi&#249; un&#8217;eccezione, ma un&#8217;estensione coerente del modello Kerberos-first introdotto con Active Directory. La fiducia diventa finalmente parte anche delle architetture estese: transitiva, strutturata, progettata per scenari complessi come migrazioni, consolidamenti e coesistenza di ambienti.</p><p>Da quel momento, le trust non sono pi&#249; solo un mezzo per &#8220;far funzionare le cose&#8221;, ma uno strumento di design da considerare con attenzione.</p><p>Abbiamo fin qui parlato di <a href="https://learn.microsoft.com/en-us/entra/identity/domain-services/concepts-forest-trust">tanti tipi di trust</a>, fare confusione &#232; un attimo, mettiamo le cose un po&#8217; in ordine:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BQhE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d23c39b-8c67-418c-926d-0cdd6655f4b4_1255x502.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BQhE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d23c39b-8c67-418c-926d-0cdd6655f4b4_1255x502.png 424w, https://substackcdn.com/image/fetch/$s_!BQhE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d23c39b-8c67-418c-926d-0cdd6655f4b4_1255x502.png 848w, https://substackcdn.com/image/fetch/$s_!BQhE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d23c39b-8c67-418c-926d-0cdd6655f4b4_1255x502.png 1272w, https://substackcdn.com/image/fetch/$s_!BQhE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d23c39b-8c67-418c-926d-0cdd6655f4b4_1255x502.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BQhE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d23c39b-8c67-418c-926d-0cdd6655f4b4_1255x502.png" width="1255" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d23c39b-8c67-418c-926d-0cdd6655f4b4_1255x502.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:1255,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:80930,&quot;alt&quot;:&quot;Tabella comparativa dei tipi di trust in Active Directory, con categoria, creazione, transitivit&#224;, protocolli e scopo.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/192079223?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d23c39b-8c67-418c-926d-0cdd6655f4b4_1255x502.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Tabella comparativa dei tipi di trust in Active Directory, con categoria, creazione, transitivit&#224;, protocolli e scopo." title="Tabella comparativa dei tipi di trust in Active Directory, con categoria, creazione, transitivit&#224;, protocolli e scopo." srcset="https://substackcdn.com/image/fetch/$s_!BQhE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d23c39b-8c67-418c-926d-0cdd6655f4b4_1255x502.png 424w, https://substackcdn.com/image/fetch/$s_!BQhE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d23c39b-8c67-418c-926d-0cdd6655f4b4_1255x502.png 848w, https://substackcdn.com/image/fetch/$s_!BQhE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d23c39b-8c67-418c-926d-0cdd6655f4b4_1255x502.png 1272w, https://substackcdn.com/image/fetch/$s_!BQhE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d23c39b-8c67-418c-926d-0cdd6655f4b4_1255x502.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Riepilogo sulle tipologie di Trust in una foresta Active Directory</figcaption></figure></div><p>In fase di design architetturale la &#8220;vera&#8221; scelta riguarda le trust di tipo esterno (non intra-forest), dove dobbiamo capire &#8220;quanta&#8221; fiducia concedere, ma soprattutto con che modalit&#224;.</p><p>Ed &#232; qui che nasce il gap che vediamo ancora oggi<s>,</s> perch&#233;, mentre il modello di fiducia &#232; evoluto, il modo di pensarlo spesso &#232; rimasto fermo.<br>Applicare un modello di Trust sbagliato rispetto al contesto molto spesso non &#232; un errore di configurazione.<br>&#200; un&#8217;eredit&#224; concettuale.</p><h2>Quali &#8220;danni&#8221; si possono fare</h2><p>Come per il primo capitolo ho ritenuto interessante ed efficace calare gli aspetti teorici in un contesto pratico, partendo sempre da quanto ho potuto osservare sul campo.</p><h3>Caso reale #1 &#8211; La trust che non ti aspetti</h3><p>Torniamo al <a href="https://www.legacythings.it/i/189367336/caso-reale-1-il-gruppo-che-non-ti-aspetti">Caso reale #1 del capitolo #1</a>, il progetto di migrazione &#232; complesso e prosegue il lavoro da &#8220;equilibrista&#8221;. Se pensavate di aver gi&#224; visto e risolto tutti i problemi vi sbagliate, &#232; una situazione che riserva ancora qualche sorpresa.</p><p>I permessi sulle utenze sono stati sistemati e si passa ai test di migrazione. Per capire bene tutto quello che include lo scenario credo per&#242; che valga la pena fare uno schema di riepilogo:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!l_b2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ea15524-32d7-4464-adaa-2f4121ed31c8_703x647.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!l_b2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ea15524-32d7-4464-adaa-2f4121ed31c8_703x647.png 424w, https://substackcdn.com/image/fetch/$s_!l_b2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ea15524-32d7-4464-adaa-2f4121ed31c8_703x647.png 848w, https://substackcdn.com/image/fetch/$s_!l_b2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ea15524-32d7-4464-adaa-2f4121ed31c8_703x647.png 1272w, https://substackcdn.com/image/fetch/$s_!l_b2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ea15524-32d7-4464-adaa-2f4121ed31c8_703x647.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!l_b2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ea15524-32d7-4464-adaa-2f4121ed31c8_703x647.png" width="703" height="647" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ea15524-32d7-4464-adaa-2f4121ed31c8_703x647.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:647,&quot;width&quot;:703,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:32248,&quot;alt&quot;:&quot;Diagramma dello scenario iniziale di migrazione con ambiente Active Directory source e target, Entra Connect in target, ADFS in source e trust tra gli ambienti. Gli utenti usano un suffisso UPN specifico e il login federato passa dalla farm ADFS del source.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/192079223?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ea15524-32d7-4464-adaa-2f4121ed31c8_703x647.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagramma dello scenario iniziale di migrazione con ambiente Active Directory source e target, Entra Connect in target, ADFS in source e trust tra gli ambienti. Gli utenti usano un suffisso UPN specifico e il login federato passa dalla farm ADFS del source." title="Diagramma dello scenario iniziale di migrazione con ambiente Active Directory source e target, Entra Connect in target, ADFS in source e trust tra gli ambienti. Gli utenti usano un suffisso UPN specifico e il login federato passa dalla farm ADFS del source." srcset="https://substackcdn.com/image/fetch/$s_!l_b2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ea15524-32d7-4464-adaa-2f4121ed31c8_703x647.png 424w, https://substackcdn.com/image/fetch/$s_!l_b2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ea15524-32d7-4464-adaa-2f4121ed31c8_703x647.png 848w, https://substackcdn.com/image/fetch/$s_!l_b2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ea15524-32d7-4464-adaa-2f4121ed31c8_703x647.png 1272w, https://substackcdn.com/image/fetch/$s_!l_b2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ea15524-32d7-4464-adaa-2f4121ed31c8_703x647.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Lo scenario di partenza: una migrazione che si basa su di una Trust attiva.</figcaption></figure></div><p>Anche solo contando il numero di frecce che sono servite a tracciare lo schema ci si rende conto del significato della parola &#8220;complesso&#8221;, gli elementi in campo sono diversi, soffermiamoci su quelli pi&#249; significativi:</p><p>&#183; Tra l&#8217;ambiente Active Directory sorgente e destinazione &#232; presente una Trust</p><p>&#183; Il motore di sincronizzazione Entra Connect &#232; in target ed ha un connettore anche verso il source</p><p>&#183; Gli utenti da migrare fanno uso di uno specifico suffisso nello UserPrincipalName (UPN), ovvero quell&#8217;attributo di logon simile alla mail</p><p>&#183; Il metodo di login per quel suffisso UPN sul tenant Entra ID &#232; di tipo federato e punta ad una Farm ADFS in source</p><p>Si tratta di uno scenario dove &#232; gi&#224; attiva una &#8220;collaborazione tra le parti&#8221; di cui la Trust &#232; la colonna portante, la migrazione delle identit&#224; &#232; solo una parte del disegno complessivo.</p><p>Ma rimanendo sulle identit&#224; mi preme sottolineare un paio di dettagli:</p><p>&#183; I nomi Netbios ed FQDN tra i due ambienti Active Directory sono differenti, requisito per poter attivare una trust</p><p>&#183; Il suffisso UPN degli utenti, che &#232; di fatto un FQDN aggiuntivo, pu&#242; essere registrato <strong>solo in una delle due Active Directory alla volta</strong>, pena la generazione di &#8220;<a href="https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc784334(v=ws.10)?redirectedfrom=MSDN#collision-detection">UPN suffix collision</a>&#8221;. Questo obbliga ad una migrazione di tipo cut-over, dove le utenze ed il relativo FQDN vengono spostate in blocco.</p><p>Torniamo ai nostri test, viene individuato un FQDN separato con cui svolgere tutto il processo, la procedura va avanti, si arriva al momento del cut-over, le utenze diventano attive in target e si passa al test di logon.</p><p>Pagina di logon di Microsoft 365, si inserisce lo UserPrincipalName di un utente di test, il sistema di federazione ci rimanda alla farm ADFS, si inserisce la password e&#8230; otteniamo un KO: <em>Incorrect username or password.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pYRb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7fc785d-e109-45fb-a592-7f6df85c2a00_703x647.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pYRb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7fc785d-e109-45fb-a592-7f6df85c2a00_703x647.png 424w, https://substackcdn.com/image/fetch/$s_!pYRb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7fc785d-e109-45fb-a592-7f6df85c2a00_703x647.png 848w, https://substackcdn.com/image/fetch/$s_!pYRb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7fc785d-e109-45fb-a592-7f6df85c2a00_703x647.png 1272w, https://substackcdn.com/image/fetch/$s_!pYRb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7fc785d-e109-45fb-a592-7f6df85c2a00_703x647.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pYRb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7fc785d-e109-45fb-a592-7f6df85c2a00_703x647.png" width="703" height="647" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f7fc785d-e109-45fb-a592-7f6df85c2a00_703x647.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:647,&quot;width&quot;:703,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31754,&quot;alt&quot;:&quot;Diagramma del fallimento di logon durante la migrazione: il login Microsoft 365 dell&#8217;utente viene reindirizzato alla farm ADFS del source, ma l&#8217;External Trust non consente il corretto instradamento del suffisso UPN aggiuntivo verso i Domain Controller del target.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/192079223?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7fc785d-e109-45fb-a592-7f6df85c2a00_703x647.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagramma del fallimento di logon durante la migrazione: il login Microsoft 365 dell&#8217;utente viene reindirizzato alla farm ADFS del source, ma l&#8217;External Trust non consente il corretto instradamento del suffisso UPN aggiuntivo verso i Domain Controller del target." title="Diagramma del fallimento di logon durante la migrazione: il login Microsoft 365 dell&#8217;utente viene reindirizzato alla farm ADFS del source, ma l&#8217;External Trust non consente il corretto instradamento del suffisso UPN aggiuntivo verso i Domain Controller del target." srcset="https://substackcdn.com/image/fetch/$s_!pYRb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7fc785d-e109-45fb-a592-7f6df85c2a00_703x647.png 424w, https://substackcdn.com/image/fetch/$s_!pYRb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7fc785d-e109-45fb-a592-7f6df85c2a00_703x647.png 848w, https://substackcdn.com/image/fetch/$s_!pYRb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7fc785d-e109-45fb-a592-7f6df85c2a00_703x647.png 1272w, https://substackcdn.com/image/fetch/$s_!pYRb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff7fc785d-e109-45fb-a592-7f6df85c2a00_703x647.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Il punto di rottura: la trust esiste, ma non sa portare la richiesta dove serve.</figcaption></figure></div><p>Uhm&#8230; errore molto generico, inizia la trafila delle verifiche:</p><p>&#183; L&#8217;utente &#232; attivo in target? &gt; S&#236;</p><p>&#183; Reset della password in target &gt; ancora KO</p><p>&#183; Tentativo di logon su ADFS con SamaccountName (DOMAIN\username) &gt; stesso errore</p><p>&#183; La risoluzione DNS funziona? &gt; S&#236;</p><p>&#183; I requisiti per gli <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/overview/ad-fs-requirements#multi-forest-requirements">scenari multi-forest</a> di ADFS sono soddisfatti? &gt; OK</p><p>&#183; La Trust &#232; configurata correttamente? &gt; &#8230;</p><p>Ecco, questo &#232; il momento in cui salta fuori il <em><strong>dettaglio che cambia tutto</strong></em>.</p><p>Andando ad analizzare la configurazione della Trust tra i due ambienti Active Directory ci si rende conto che &#232; stata attivata (o meglio ereditata) una <strong>External Trust</strong> e non una pi&#249; sofisticata <strong>Forest Trust</strong>.</p><p>Altro dettaglio importante, visto in precedenza, &#232; che le utenze oggetto di migrazione fanno uso di suffissi UPN aggiuntivi, es: <em>&lt;username&gt;@UPNsuffix.xyz</em></p><p>Questi ultimi sono definiti a livello di foresta e fanno parte dei metadati condivisi tramite la Configuration Partition.</p><p>Il meccanismo di Name / UPN Suffix Routing utilizza queste informazioni ed &#232; <a href="https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc784334(v=ws.10)?redirectedfrom=MSDN#routing-name-suffixes-across-forests-1">disponibile solo nel contesto di una forest trust</a>.</p><p><em>&#8220;Name suffix routing is a mechanism used to manage how authentication requests are routed across Windows Server 2003 forests that are joined together by forest trusts.&#8221;</em></p><p>Le <strong>External Trust</strong>, operando esclusivamente a livello di dominio, <strong>non hanno visibilit&#224; dei metadati di foresta e non possono quindi instradare suffissi UPN aggiuntivi.</strong></p><p>Per questo motivo un tentativo di logon con il suffisso UPN aggiuntivo, effettuato nella farm ADFS dell&#8217;ambiente source, non permette il corretto instradamento della richiesta verso i Domain Controller dell&#8217;ambiente Active Directory target.</p><p>Siamo quindi alle prese con una <strong>configurazione ereditata</strong>, sicuramente funzionale allo scopo originale, <strong>ma incompatibile con lo scenario presente.</strong></p><p>La domanda a questo punto &#232; inevitabile: come risolvere?</p><p>La soluzione tecnica pi&#249; ovvia sarebbe quella di sostituire l&#8217;<strong>External Trust </strong>con una <strong>Forest Trust</strong>. Logico no?</p><p>Peccato che nei progetti reali le soluzioni ovvie non siano sempre praticabili e si scontrano con le politiche aziendali.</p><p>In questo caso il cliente aveva le idee chiare: <strong>nessuna modifica architetturale poteva essere approvata senza una verifica formale degli impatti</strong>, condotta in un ambiente controllato che riproducesse fedelmente la produzione. E con un vincolo ulteriore, non negoziabile:<strong> l&#8217;esperienza utente non doveva cambiare.</strong></p><p>Requisiti comprensibili, anzi corretti e tutelativi, ma che nella pratica significavano una cosa sola: <em><strong>la strada pi&#249; semplice era sbarrata</strong></em>.</p><p>&#200; uno di quei momenti in cui il lavoro da equilibrista si fa sentire davvero. Hai la diagnosi, conosci la cura, ma non puoi somministrarla. Devi trovare un percorso alternativo che rispetti i vincoli, non comprometta l&#8217;esperienza utente e non faccia saltare la timeline del progetto.</p><p>La soluzione individuata &#232; stata quella di <strong>aggirare il limite senza ignorarlo</strong>: introdurre una nuova farm ADFS nell&#8217;ambiente target, validare l&#8217;architettura e l&#8217;esperienza utente con un suffisso UPN dedicato, raccogliere le evidenze necessarie per portare al tavolo una proposta formale di cambio architetturale in un secondo momento.</p><p>Non la risposta ideale. Ma la risposta possibile in quello specifico contesto.</p><p>Questo il diagramma di arrivo:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0zBF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa20cbdf1-bfaa-4eb8-ae49-d0b66e8747db_703x647.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0zBF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa20cbdf1-bfaa-4eb8-ae49-d0b66e8747db_703x647.png 424w, https://substackcdn.com/image/fetch/$s_!0zBF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa20cbdf1-bfaa-4eb8-ae49-d0b66e8747db_703x647.png 848w, https://substackcdn.com/image/fetch/$s_!0zBF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa20cbdf1-bfaa-4eb8-ae49-d0b66e8747db_703x647.png 1272w, https://substackcdn.com/image/fetch/$s_!0zBF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa20cbdf1-bfaa-4eb8-ae49-d0b66e8747db_703x647.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0zBF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa20cbdf1-bfaa-4eb8-ae49-d0b66e8747db_703x647.png" width="703" height="647" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a20cbdf1-bfaa-4eb8-ae49-d0b66e8747db_703x647.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:647,&quot;width&quot;:703,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31646,&quot;alt&quot;:&quot;Diagramma della soluzione finale con una nuova farm ADFS nell&#8217;ambiente target, introdotta per validare architettura ed esperienza utente senza modificare subito la trust esistente.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/192079223?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa20cbdf1-bfaa-4eb8-ae49-d0b66e8747db_703x647.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagramma della soluzione finale con una nuova farm ADFS nell&#8217;ambiente target, introdotta per validare architettura ed esperienza utente senza modificare subito la trust esistente." title="Diagramma della soluzione finale con una nuova farm ADFS nell&#8217;ambiente target, introdotta per validare architettura ed esperienza utente senza modificare subito la trust esistente." srcset="https://substackcdn.com/image/fetch/$s_!0zBF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa20cbdf1-bfaa-4eb8-ae49-d0b66e8747db_703x647.png 424w, https://substackcdn.com/image/fetch/$s_!0zBF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa20cbdf1-bfaa-4eb8-ae49-d0b66e8747db_703x647.png 848w, https://substackcdn.com/image/fetch/$s_!0zBF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa20cbdf1-bfaa-4eb8-ae49-d0b66e8747db_703x647.png 1272w, https://substackcdn.com/image/fetch/$s_!0zBF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa20cbdf1-bfaa-4eb8-ae49-d0b66e8747db_703x647.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">La soluzione possibile: aggirare il limite senza ignorarlo.</figcaption></figure></div><p>Anche in questo caso siamo di fronte ad uno sforzo extra che difficilmente pu&#242; essere preventivato durante la normale fase di assessment.</p><p>La Trust era attiva e stava facendo quello per cui era stata progettata, peccato che non fosse sufficiente a supportare lo scenario di migrazione.</p><p>Supponendo che la messa in opera della Trust sia stata fatta dopo il 2003, viene naturale aprire una riflessione sulla lungimiranza della scelta che ha portato all&#8217;uso della <strong>External Trust</strong> e dei vincoli che nel tempo si porta dietro.</p><h2>Cosa ci ha insegnato la fiducia</h2><p>La fiducia, nei sistemi informatici, &#232; uno di quei concetti che diamo per scontati fino a quando non smette di funzionare.<br>&#200; una compagna invisibile, silenziosa, che ci abitua alla sua presenza senza farsi sentire. Eppure, quando viene progettata o ereditata senza piena consapevolezza, &#232; in grado di determinare il successo o il fallimento di intere architetture.</p><p>Il caso visto in questo capitolo mostra chiaramente un punto spesso trascurato: <strong>una trust non &#232; solo un collegamento tecnico, &#232; una scelta di design</strong>.<br>Una scelta che nasce in un contesto preciso, per risolvere un problema specifico, e che pu&#242; restare perfettamente valida per anni&#8230; fino a quando <strong>il contesto cambia.</strong></p><p>Nel momento in cui entrano in gioco identit&#224; ibride, federazioni, suffissi UPN aggiuntivi e requisiti di continuit&#224; verso il cloud, quella stessa fiducia pu&#242; diventare un vincolo invisibile.<br>Non perch&#233; sia &#8220;sbagliata&#8221;, ma perch&#233; &#232; stata pensata per un mondo diverso, con confini pi&#249; semplici e percorsi di autenticazione meno articolati.</p><p>La lezione pi&#249; importante &#232; che <strong>la fiducia non scala automaticamente con la complessit&#224;</strong>.<br>Aggiungere nuovi componenti (Entra ID, ADFS, sincronizzazioni multi&#8209;forest) senza rimettere in discussione il modello di trust significa spesso costruire sopra <em><strong>fondamenta che non sono state progettate per sostenere quel peso</strong></em>.</p><p>C&#8217;&#232; poi una seconda lezione, ancora pi&#249; sottile: <strong>i problemi legati alla fiducia raramente si manifestano in modo esplicito</strong>.<br>Non producono errori chiari, non indicano una causa precisa. Si presentano come comportamenti ambigui, autenticazioni che falliscono &#8220;senza motivo&#8221;, configurazioni che sembrano corrette ma non funzionano. Ed &#232; proprio questa ambiguit&#224; a renderli costosi da diagnosticare e risolvere.</p><p>Come nel caso del guardiano visto nel Capitolo 1, anche qui <em><strong>il problema non sono le trust</strong></em>.<br>Esse continuano a fare esattamente ci&#242; per cui sono state progettate: delimitare perimetri, stabilire confini, definire chi pu&#242; fidarsi di chi.<br>Il problema nasce quando <strong>il design moderno ignora quei confini</strong>, assumendo che la fiducia sia implicita, transitiva o adattabile per default.</p><p>Negli ambienti ibridi<s>,</s> la fiducia non &#232; un dettaglio operativo<s>,</s> ma una <strong>decisione architetturale di primo livello</strong>.<br>Trattarla come un&#8217;eredit&#224; da subire, invece che come un elemento da comprendere e ridisegnare, significa spostare i problemi pi&#249; avanti nel tempo<s>,</s> dove saranno inevitabilmente pi&#249; complessi e pi&#249; costosi, soprattutto quando si inseriscono nell&#8217;equazione i vincoli &#8220;politici&#8221;.</p><p>Ed &#232; proprio da qui che <em><strong>Legacy Things</strong></em> continua il suo percorso: riportare alla luce quei meccanismi silenziosi che, pur nati decenni fa, continuano a determinare il comportamento delle infrastrutture moderne.<br>Perch&#233; ignorare il passato non lo rende innocuo. Lo rende solo pi&#249; difficile da riconoscere quando torna a farsi sentire.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Grazie per aver letto Legacy Things! Iscriviti gratuitamente per ricevere nuovi post e supportare il mio lavoro.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Chapter #2 – A Matter of Trust]]></title><description><![CDATA[Beyond the perimeter&#8217;s edge]]></description><link>https://www.legacythings.it/p/chapter-2-a-matter-of-trust</link><guid isPermaLink="false">https://www.legacythings.it/p/chapter-2-a-matter-of-trust</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Mon, 30 Mar 2026 06:10:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!LGe3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa39bffba-8323-4c05-ab04-8d8062c870f4_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Versione italiana disponibile qui &#8594;</em><a href="https://www.legacythings.it/p/capitolo-1-adminsdholder-il-guardiano"> </a><em><a href="https://www.legacythings.it/p/capitolo-2-una-questione-di-fiducia">[IT]</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LGe3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa39bffba-8323-4c05-ab04-8d8062c870f4_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LGe3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa39bffba-8323-4c05-ab04-8d8062c870f4_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!LGe3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa39bffba-8323-4c05-ab04-8d8062c870f4_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!LGe3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa39bffba-8323-4c05-ab04-8d8062c870f4_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!LGe3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa39bffba-8323-4c05-ab04-8d8062c870f4_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LGe3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa39bffba-8323-4c05-ab04-8d8062c870f4_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a39bffba-8323-4c05-ab04-8d8062c870f4_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3021479,&quot;alt&quot;:&quot;Illustration of a Formula 1 car on track, used as a metaphor for trust and the limits of the authentication perimeter discussed in the chapter.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/192082985?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa39bffba-8323-4c05-ab04-8d8062c870f4_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustration of a Formula 1 car on track, used as a metaphor for trust and the limits of the authentication perimeter discussed in the chapter." title="Illustration of a Formula 1 car on track, used as a metaphor for trust and the limits of the authentication perimeter discussed in the chapter." srcset="https://substackcdn.com/image/fetch/$s_!LGe3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa39bffba-8323-4c05-ab04-8d8062c870f4_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!LGe3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa39bffba-8323-4c05-ab04-8d8062c870f4_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!LGe3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa39bffba-8323-4c05-ab04-8d8062c870f4_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!LGe3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa39bffba-8323-4c05-ab04-8d8062c870f4_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Spring 1993</strong>, the writer is still completing studies.<br>One April Sunday the F1 Grand Prix takes place at Donington, UK. For the legendary <strong>Ayrton Senna</strong> it is a difficult year: his McLaren is inferior to the competition, and he starts fifth on the grid, but there is one detail that plays in his favour: <em><strong>it is raining!</strong></em> And when it rains, his <strong>trust</strong> in the car becomes absolute.<br>Green light, he launches forward like fury and by the end of the first lap he is already in the lead, in total domination. No one else has his <strong>confidence</strong> on a wet track.</p><p>In the rest of the world, in those same months, something equally extraordinary was taking shape, radically changing the way people <strong>trusted</strong> computer systems.<br>With the spread of the <strong>World Wide Web</strong> and the distribution of the <strong>NCSA Mosaic</strong> browser, the Internet stops being an environment reserved for a handful of specialists and suddenly becomes accessible.<br>Anyone can connect, explore remote resources, interact with systems they do not know and do not control.</p><p>Until that moment, security models had been built around clear boundaries: corporate networks, local systems, well&#8209;defined domains.<br>With the Web, instead, people begin relying on distant services, remote identities, infrastructures that live outside their direct control.</p><p>It is a cultural revolution even before a technological one.</p><p>In Enterprise systems the subject of trust is played out across two opposing fronts.<br>On one side, the <strong>Windows</strong> universe was spreading based on a closed, perimeter-based trust model that coincided with the first domains.<br>This is where the first explicit concept of <strong>trust</strong> was introduced, built on a proprietary protocol: <strong>NTLM</strong>.<br>A mechanism designed for controlled environments, where trust is a static, declared configuration.</p><p>On the other side, the <strong>Unix</strong> and academic world had long used distributed authentication models, reaching significant maturity with <strong>Kerberos V5</strong>.<br>Here, trust is not merely a connection between systems, but an element designed for open, interconnected, and potentially heterogeneous environments.</p><p>Two profoundly different visions of <strong>trust</strong>, created to respond to different needs.</p><p>With the introduction of <strong>Active Directory</strong>, however, Microsoft made a fundamental choice: it embraced the values of the other model and <strong>adopted Kerberos as the foundational basis of the new authentication system</strong>, initiating a path of convergence between these two worlds.<br>Initially the models coexisted, side by side more than integrated, as a necessary compromise to guarantee backward compatibility.</p><p>Only with <strong>Windows Server 2003</strong> did a more mature form of convergence arrive, marking the transition towards a <em>Kerberos&#8209;first</em> approach, in which trust became part of the architecture rather than merely a connection between separate perimeters.</p><p>And yet, despite this convergence having happened more than twenty years ago, it has not always been fully understood.<br>As if, paradoxically, <strong>trust itself had been lacking</strong> in the process that intended to unite schools of thought that were originally far apart.</p><p>This chapter starts from here.<br>From a kind of trust that has evolved technically, but not always conceptually, and from the consequences of not having truly understood that change all the way through.</p><h2>What it is and how it works</h2><p>We have understood that the concept of &#8220;Trust&#8221; has deep roots; let us now try to frame it into practical terms within the context of Active Directory.</p><h3>Basic mechanics of a Trust</h3><p>Let us start from a principle that is very often taken for granted: the Authentication Domain.</p><p>A Domain is a perimeter within which an implicit &#8220;trust&#8221; exists among the objects that belong to it, mediated by appropriate permissions that define who can access what and in which mode (we discussed ACLs in Chapter 1).<br>Between different perimeters (Domains) there is no implicit trust, and consequently access is not allowed.</p><p>The element that distinguishes all objects belonging to the same Domain is the <strong>Security Identifier (SID)</strong>.<br>This is a fundamental attribute of the Windows security model: an immutable string that uniquely identifies an entity (user, group, computer&#8230;) regardless of the name assigned to it.</p><p>A SID has a precise structure and can be represented in readable form as follows:<br>S&#8209;1&#8209;5&#8209;21&#8209;&lt;DomainIdentifier&gt;&#8209;&lt;RelativeIdentifier&gt;</p><p>The first part of the SID identifies <strong>the authority that issued it</strong> and the <strong>security context</strong> in which the object was created.<br>In particular, the sequence S&#8209;1&#8209;5&#8209;21 indicates that the SID belongs to a Windows domain context, while the value &lt;DomainIdentifier&gt; represents the identity of the domain itself.</p><p>This means that <strong>all objects belonging to the same domain share exactly the same initial portion of the SID</strong>.</p><p>The final part, called the <strong>Relative Identifier (RID)</strong>, is what makes the object unique within that domain.<br>The RID is assigned by the Domain Controller at the time the object is created and distinguishes a user, group or computer from all others that share the same Domain SID.</p><p>In other words, the SID always tells two different truths:</p><p>&#183; <em>where the object comes from</em> (the domain that issued it)</p><p>&#183; <em>who the object is</em> within that domain</p><p>This separation is one of the cornerstones of the Active Directory security model; if you want to explore the topic further, here is the link to the <a href="https://learn.microsoft.com/en-gb/windows-server/identity/ad-ds/manage/understand-security-identifiers">official article</a>.</p><p>Thanks to this mechanism, ever since the very first NT Domains, the <strong>Domain Trust</strong> mechanism has been available, initially based on the <strong>NTLM</strong> protocol.</p><p>It is important to remember that, even conceptually, trust has a precise direction, the same is true for Domain Trusts, where <strong>those who provide the resources</strong> (for example, a File Server in a resource Domain) <strong>extend trust to</strong> <strong>those who provide the identities</strong> (the user Domain).<br>This direction is represented with an arrow going from resources to identities.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cFHx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdeacbf-5cd5-43c5-97e8-ac6db74538f3_540x184.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cFHx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdeacbf-5cd5-43c5-97e8-ac6db74538f3_540x184.png 424w, https://substackcdn.com/image/fetch/$s_!cFHx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdeacbf-5cd5-43c5-97e8-ac6db74538f3_540x184.png 848w, https://substackcdn.com/image/fetch/$s_!cFHx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdeacbf-5cd5-43c5-97e8-ac6db74538f3_540x184.png 1272w, https://substackcdn.com/image/fetch/$s_!cFHx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdeacbf-5cd5-43c5-97e8-ac6db74538f3_540x184.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cFHx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdeacbf-5cd5-43c5-97e8-ac6db74538f3_540x184.png" width="540" height="184" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8cdeacbf-5cd5-43c5-97e8-ac6db74538f3_540x184.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:184,&quot;width&quot;:540,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3568,&quot;alt&quot;:&quot;Diagram showing the direction of a trust between a resource domain and a user domain, with an arrow from resource.ad to user.ad.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/192082985?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdeacbf-5cd5-43c5-97e8-ac6db74538f3_540x184.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram showing the direction of a trust between a resource domain and a user domain, with an arrow from resource.ad to user.ad." title="Diagram showing the direction of a trust between a resource domain and a user domain, with an arrow from resource.ad to user.ad." srcset="https://substackcdn.com/image/fetch/$s_!cFHx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdeacbf-5cd5-43c5-97e8-ac6db74538f3_540x184.png 424w, https://substackcdn.com/image/fetch/$s_!cFHx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdeacbf-5cd5-43c5-97e8-ac6db74538f3_540x184.png 848w, https://substackcdn.com/image/fetch/$s_!cFHx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdeacbf-5cd5-43c5-97e8-ac6db74538f3_540x184.png 1272w, https://substackcdn.com/image/fetch/$s_!cFHx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cdeacbf-5cd5-43c5-97e8-ac6db74538f3_540x184.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Trust direction</figcaption></figure></div><p>When a Trust is activated, the resource domain does not import users nor replicate objects from the trusted domain.<br>Instead, it accepts something much simpler and far more powerful: <strong>the Security Identifiers issued on the other side</strong>.</p><p>When an external object is used for the first time (for example, by adding it to a local group or assigning it a permission) Active Directory automatically creates a <strong>Foreign Security Principal</strong>.</p><p>A <a href="https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/5aa09c90-c5db-4e97-98d0-b7cdd6bc1bfe">Foreign Security Principal</a> is not a real local account, but a <strong>pointer</strong>: a minimal object containing only the SID of the remote entity.<br>It allows the resource domain to include external identities in its authorisation mechanisms without needing to know their structure or replicate their attributes.</p><p>Once again, everything revolves around <strong>trust</strong>: the resource domain does not know <em>who</em> that object is, but trusts that its SID was issued by an authority considered <em>reliable</em>.</p><h3>The evolution of trusts: from point-to-point connections to architectural trust</h3><p>In the first Windows domain model, trust was a simple and very concrete concept: two domains know each other, speak to each other, trust each other.<br>Nothing more. Every trust is an explicit, manually created connection that applies only between two well defined endpoints.<br>If you need something else, you create another trust, and then another.</p><p>It is a model coherent with its era: small environments, clear perimeters, few interactions.<br>But it is also a model that does not scale.<br>Every new relationship increases complexity and, more importantly, makes trust fragile: forgetting a single link is enough for something to stop working.</p><p>With the arrival of Active Directory and the birth of the <em>forest</em> concept, Microsoft changed approach.<br>Domains were no longer independent islands, but parts of a broader structure designed to share a common trust space.<br>To support a hierarchical domain model, <strong>intra&#8209;forest trusts</strong> were introduced: automatic, bidirectional, transitive.<br>Trust was no longer an exception but a structural property.</p><p>It was a fundamental shift: for the first time, trust stopped being a set of exceptions and became a foundational rule.</p><p>However, when it becomes necessary to leave this perimeter (to collaborate with external domains, legacy environments or completely separate forests) one temporarily returns to the past.<br>As a legacy of Domain Trusts, <strong>External Trusts</strong> were introduced: explicit, non&#8209;transitive links, deliberately limited.<br>A necessary compromise, designed to contain risk and reduce exposure.</p><p>The problem is that, in the meantime, the world moved on.</p><p>With <strong>Windows Server 2003</strong>, the attempt at a definitive synthesis arrived: the <strong>Forest Trust</strong>.<br>No longer trust between individual domains, but between entire sets of domains.<br>No longer an exception, but a coherent extension of the Kerberos&#8209;first model introduced with Active Directory.<br>Trust finally became part of extended architectures as well: transitive, structured, designed for complex scenarios such as migrations, consolidations and coexistence.</p><p>From that moment onwards, trusts were no longer just a way to &#8220;make things work&#8221;, but a design tool that must be considered carefully.</p><p>So far we have mentioned <a href="https://learn.microsoft.com/en-us/entra/identity/domain-services/concepts-forest-trust">many different types of trusts</a>; confusion is easy, so let&#8217;s put things in order:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!i7le!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788835a0-6c15-49d4-99cc-30a4d4c1b9dd_1255x476.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!i7le!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788835a0-6c15-49d4-99cc-30a4d4c1b9dd_1255x476.png 424w, https://substackcdn.com/image/fetch/$s_!i7le!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788835a0-6c15-49d4-99cc-30a4d4c1b9dd_1255x476.png 848w, https://substackcdn.com/image/fetch/$s_!i7le!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788835a0-6c15-49d4-99cc-30a4d4c1b9dd_1255x476.png 1272w, https://substackcdn.com/image/fetch/$s_!i7le!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788835a0-6c15-49d4-99cc-30a4d4c1b9dd_1255x476.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!i7le!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788835a0-6c15-49d4-99cc-30a4d4c1b9dd_1255x476.png" width="1255" height="476" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/788835a0-6c15-49d4-99cc-30a4d4c1b9dd_1255x476.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:476,&quot;width&quot;:1255,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:67854,&quot;alt&quot;:&quot;Comparison table of Active Directory trust types, showing category, creation, transitivity, protocols and purpose.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/192082985?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788835a0-6c15-49d4-99cc-30a4d4c1b9dd_1255x476.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Comparison table of Active Directory trust types, showing category, creation, transitivity, protocols and purpose." title="Comparison table of Active Directory trust types, showing category, creation, transitivity, protocols and purpose." srcset="https://substackcdn.com/image/fetch/$s_!i7le!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788835a0-6c15-49d4-99cc-30a4d4c1b9dd_1255x476.png 424w, https://substackcdn.com/image/fetch/$s_!i7le!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788835a0-6c15-49d4-99cc-30a4d4c1b9dd_1255x476.png 848w, https://substackcdn.com/image/fetch/$s_!i7le!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788835a0-6c15-49d4-99cc-30a4d4c1b9dd_1255x476.png 1272w, https://substackcdn.com/image/fetch/$s_!i7le!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788835a0-6c15-49d4-99cc-30a4d4c1b9dd_1255x476.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Trust type summary inside an Active Directory Forest</figcaption></figure></div><p>In architectural design, the <em>real</em> decision concerns <strong>external-type trusts</strong> (not intra-forest), where we must decide &#8220;how much&#8221; trust to grant and, above all, in what way.</p><p>And this is where the gap we still see today is born, because while the trust model has evolved, the way people think about it has often remained still.<br>Applying the wrong trust model to the wrong context is very often not a configuration error.<br>It is a conceptual legacy.</p><h2>What can go wrong</h2><p>As with the first chapter, I felt it would be both interesting and effective to place the theoretical aspects into a practical context, always starting from what I have been able to observe in the field.</p><h3>Real case #1 &#8211; The trust you do not expect</h3><p>Let us return to <a href="https://www.legacythings.it/i/189536509/real-case-1-the-group-you-dont-expect">Real Case #1 of Chapter #1</a>. The migration project is complex and the work of the &#8220;tightrope walker&#8221; goes on. If you thought you had already seen and solved every problem, you were mistaken: this is a situation that still has a few surprises in store.</p><p>Permissions on the user accounts have been fixed, and the migration tests begin. To fully understand everything that this scenario includes, I believe it is worth laying it out in a summary diagram:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NN3k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc13ccd3a-2526-4d88-a488-f2045620c6e1_703x647.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NN3k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc13ccd3a-2526-4d88-a488-f2045620c6e1_703x647.png 424w, https://substackcdn.com/image/fetch/$s_!NN3k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc13ccd3a-2526-4d88-a488-f2045620c6e1_703x647.png 848w, https://substackcdn.com/image/fetch/$s_!NN3k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc13ccd3a-2526-4d88-a488-f2045620c6e1_703x647.png 1272w, https://substackcdn.com/image/fetch/$s_!NN3k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc13ccd3a-2526-4d88-a488-f2045620c6e1_703x647.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NN3k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc13ccd3a-2526-4d88-a488-f2045620c6e1_703x647.png" width="703" height="647" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c13ccd3a-2526-4d88-a488-f2045620c6e1_703x647.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:647,&quot;width&quot;:703,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:32248,&quot;alt&quot;:&quot;Initial migration scenario diagram showing source and target Active Directory environments, Entra Connect in the target, ADFS in the source and a trust between the two environments. Users rely on a specific UPN suffix and federated sign-in goes through the source ADFS farm.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/192082985?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc13ccd3a-2526-4d88-a488-f2045620c6e1_703x647.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Initial migration scenario diagram showing source and target Active Directory environments, Entra Connect in the target, ADFS in the source and a trust between the two environments. Users rely on a specific UPN suffix and federated sign-in goes through the source ADFS farm." title="Initial migration scenario diagram showing source and target Active Directory environments, Entra Connect in the target, ADFS in the source and a trust between the two environments. Users rely on a specific UPN suffix and federated sign-in goes through the source ADFS farm." srcset="https://substackcdn.com/image/fetch/$s_!NN3k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc13ccd3a-2526-4d88-a488-f2045620c6e1_703x647.png 424w, https://substackcdn.com/image/fetch/$s_!NN3k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc13ccd3a-2526-4d88-a488-f2045620c6e1_703x647.png 848w, https://substackcdn.com/image/fetch/$s_!NN3k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc13ccd3a-2526-4d88-a488-f2045620c6e1_703x647.png 1272w, https://substackcdn.com/image/fetch/$s_!NN3k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc13ccd3a-2526-4d88-a488-f2045620c6e1_703x647.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The starting point: a migration already resting on an active trust relationship.</figcaption></figure></div><p>Even just by counting the number of arrows needed to draw the diagram, you immediately understand the meaning of the word &#8220;complex&#8221;. There are several elements in play, so let us focus on the most significant ones:</p><ul><li><p>There is a Trust between the source and target Active Directory environments</p></li><li><p>The Entra Connect synchronisation engine is in the target and has a connector to the source</p></li><li><p>The users to be migrated use a specific suffix in their UserPrincipalName (UPN), that logon attribute that resembles an email address</p></li><li><p>The login method for that UPN suffix in the Entra ID tenant is federated and points to an ADFS Farm in the source</p></li></ul><p>This is a scenario where a &#8220;collaboration between the parties&#8221; is already active, and the Trust is its main pillar. Identity migration is only one part of the overall design.</p><p>Staying on the topic of identities, however, I would like to highlight a couple of details:</p><ul><li><p>The NetBIOS names and FQDNs of the two Active Directory environments are different, which is a requirement for enabling a trust</p></li><li><p>The users&#8217; UPN suffix, which is effectively an additional FQDN, can be registered <em><strong>only in one of the two Active Directory environments at a time</strong></em>, otherwise an &#8220;<a href="https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc784334(v=ws.10)?redirectedfrom=MSDN#collision-detection">UPN suffix collision</a>&#8221; is generated. This forces a cut over migration approach, where the user accounts and the related FQDN are moved in one block.</p></li></ul><p>Back to our tests: a separate FQDN is identified with which to carry out the whole process, the procedure continues, cut over time arrives, the users become active in the target and the logon test begins.</p><p>Microsoft 365 logon page, the UserPrincipalName of a test user is entered, the federation system redirects us to the source ADFS Farm, the password is entered and&#8230; the attempt fails: <em>Incorrect username or password.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2a8Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab622100-7c43-4c32-9d20-ed43cac9c732_703x647.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2a8Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab622100-7c43-4c32-9d20-ed43cac9c732_703x647.png 424w, https://substackcdn.com/image/fetch/$s_!2a8Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab622100-7c43-4c32-9d20-ed43cac9c732_703x647.png 848w, https://substackcdn.com/image/fetch/$s_!2a8Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab622100-7c43-4c32-9d20-ed43cac9c732_703x647.png 1272w, https://substackcdn.com/image/fetch/$s_!2a8Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab622100-7c43-4c32-9d20-ed43cac9c732_703x647.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2a8Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab622100-7c43-4c32-9d20-ed43cac9c732_703x647.png" width="703" height="647" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ab622100-7c43-4c32-9d20-ed43cac9c732_703x647.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:647,&quot;width&quot;:703,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31754,&quot;alt&quot;:&quot;Failed logon diagram showing Microsoft 365 sign-in redirected to the source ADFS farm, where the External Trust cannot correctly route the additional UPN suffix towards the target Domain Controllers.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/192082985?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab622100-7c43-4c32-9d20-ed43cac9c732_703x647.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Failed logon diagram showing Microsoft 365 sign-in redirected to the source ADFS farm, where the External Trust cannot correctly route the additional UPN suffix towards the target Domain Controllers." title="Failed logon diagram showing Microsoft 365 sign-in redirected to the source ADFS farm, where the External Trust cannot correctly route the additional UPN suffix towards the target Domain Controllers." srcset="https://substackcdn.com/image/fetch/$s_!2a8Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab622100-7c43-4c32-9d20-ed43cac9c732_703x647.png 424w, https://substackcdn.com/image/fetch/$s_!2a8Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab622100-7c43-4c32-9d20-ed43cac9c732_703x647.png 848w, https://substackcdn.com/image/fetch/$s_!2a8Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab622100-7c43-4c32-9d20-ed43cac9c732_703x647.png 1272w, https://substackcdn.com/image/fetch/$s_!2a8Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab622100-7c43-4c32-9d20-ed43cac9c732_703x647.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The breaking point: the trust exists, but it cannot take the request where needed.</figcaption></figure></div><p>Hmm&#8230; a very generic error, and so the usual sequence of checks begins:</p><ul><li><p>Is the user active in the target? &gt; Yes</p></li><li><p>Password reset in the target &gt; still KO</p></li><li><p>Attempt to log on to ADFS using SamaccountName (DOMAIN\username) &gt; same error</p></li><li><p>Does DNS resolution work? &gt; Yes</p></li><li><p>Are the requirements for <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/overview/ad-fs-requirements#multi-forest-requirements">multi-forest</a> ADFS scenarios met? &gt; OK</p></li><li><p>Is the Trust configured correctly? &gt; &#8230;</p></li></ul><p>This is the moment when<em><strong> the detail that changes everything</strong></em> emerges.</p><p>By analysing the Trust configuration between the two Active Directory environments, it becomes clear that an <strong>External Trust</strong> had been enabled, or rather inherited, instead of a more sophisticated <strong>Forest Trust</strong>.</p><p>Another important detail, already mentioned above, is that the users being migrated use additional UPN suffixes, for example: <em>&lt;username&gt;@UPNsuffix.xyz</em></p><p>These are defined at forest level and are part of the metadata shared through the Configuration partition.</p><p>The Name / UPN Suffix Routing mechanism uses this information and is <a href="https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc784334(v=ws.10)?redirectedfrom=MSDN#routing-name-suffixes-across-forests-1">available only in the Forest Trust context</a>.</p><p><em>&#8220;Name suffix routing is a mechanism used to manage how authentication requests are routed across Windows Server 2003 forests that are joined together by forest trusts.&#8221;</em></p><p><strong>External Trusts</strong>, operating exclusively at domain level, <strong>do not have visibility over forest metadata and therefore cannot route additional UPN suffixes</strong>.</p><p>For this reason, an attempt to log on using the additional UPN suffix, carried out through the ADFS Farm in the source environment, cannot correctly route the request towards the Domain Controllers in the target Active Directory environment.</p><p>So, we are dealing with an <strong>inherited configuration</strong>, certainly functional for its original purpose, but <strong>incompatible with the current scenario</strong>.</p><p>At this point, the question becomes inevitable: how do we solve it?</p><p>The most obvious technical solution would be to replace the <strong>External Trust</strong> with a <strong>Forest Trust</strong>. Logical, right?</p><p>The problem is that, in real projects, obvious solutions are not always practical, and they clash with corporate policies.</p><p>In this case, the customer was very clear: <em><strong>no architectural change could be approved without a formal impact assessment</strong>,</em> carried out in a controlled environment that reproduced production faithfully. And there was an additional, non-negotiable constraint: <em><strong>the user experience must not change</strong></em>.</p><p>Understandable requirements indeed, correct and protective ones, but in practice they meant only one thing: <em><strong>the simplest path was blocked</strong></em>.</p><p>This is one of those moments when the tightrope walker&#8217;s work truly makes itself felt. You have the diagnosis, you know the cure, but you cannot administer it. You must find an alternative path that respects the constraints, does not compromise the user experience and does not blow up the project timeline.</p><p>The solution identified was to <strong>work around the limit without ignoring it:</strong> introduce a new ADFS Farm in the target environment, validate the architecture and the user experience with a dedicated UPN suffix, and collect the evidence needed to bring a formal proposal for architectural change to the table at a later stage.</p><p>Not the ideal answer. But the possible answer in that specific context.</p><p>This is the resulting diagram:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yFGQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40c2c123-6ee6-47bb-ad61-74072a116189_703x647.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yFGQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40c2c123-6ee6-47bb-ad61-74072a116189_703x647.png 424w, https://substackcdn.com/image/fetch/$s_!yFGQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40c2c123-6ee6-47bb-ad61-74072a116189_703x647.png 848w, https://substackcdn.com/image/fetch/$s_!yFGQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40c2c123-6ee6-47bb-ad61-74072a116189_703x647.png 1272w, https://substackcdn.com/image/fetch/$s_!yFGQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40c2c123-6ee6-47bb-ad61-74072a116189_703x647.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yFGQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40c2c123-6ee6-47bb-ad61-74072a116189_703x647.png" width="703" height="647" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/40c2c123-6ee6-47bb-ad61-74072a116189_703x647.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:647,&quot;width&quot;:703,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31646,&quot;alt&quot;:&quot;Final solution diagram showing a new ADFS farm introduced in the target environment in order to validate architecture and user experience without immediately changing the existing trust.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/192082985?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40c2c123-6ee6-47bb-ad61-74072a116189_703x647.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Final solution diagram showing a new ADFS farm introduced in the target environment in order to validate architecture and user experience without immediately changing the existing trust." title="Final solution diagram showing a new ADFS farm introduced in the target environment in order to validate architecture and user experience without immediately changing the existing trust." srcset="https://substackcdn.com/image/fetch/$s_!yFGQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40c2c123-6ee6-47bb-ad61-74072a116189_703x647.png 424w, https://substackcdn.com/image/fetch/$s_!yFGQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40c2c123-6ee6-47bb-ad61-74072a116189_703x647.png 848w, https://substackcdn.com/image/fetch/$s_!yFGQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40c2c123-6ee6-47bb-ad61-74072a116189_703x647.png 1272w, https://substackcdn.com/image/fetch/$s_!yFGQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40c2c123-6ee6-47bb-ad61-74072a116189_703x647.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The possible solution: working around the limit without ignoring it.</figcaption></figure></div><p>Once again, we are facing an extra effort that can hardly be anticipated during the normal assessment phase.</p><p>The Trust was active and was doing exactly what it had been designed to do, but it was not sufficient to support the migration scenario.</p><p>Assuming that the Trust was put in place after 2003, it becomes natural to reflect on the foresight of the decision that led to the use of an <strong>External Trust</strong> and on the constraints it carries forward over time.</p><h2>Lessons learned from the Trust</h2><p>Trust, in computer systems, is one of those concepts that we take for granted until it stops working.</p><p>It is an invisible, silent companion that accustoms us to its presence without ever making itself heard. And yet, when it is designed or inherited without full awareness, it can determine the success or failure of entire architectures.</p><p>The case seen in this chapter clearly shows a point that is often overlooked: <strong>a trust is not just a technical connection, it is a design choice</strong>.</p><p>A choice that is born in a specific context, to solve a specific problem, and that can remain perfectly valid for years&#8230; until <em><strong>the context changes</strong></em>.</p><p>When hybrid identities, federations, additional UPN suffixes and cloud continuity requirements come into play, that same trust can become an invisible constraint.</p><p>Not because it is &#8220;wrong&#8221;, but because it was designed for a different world, with simpler boundaries and less articulated authentication paths.</p><p>The most important lesson is that <strong>trust does not automatically scale with complexity</strong>.</p><p>Adding new components, such as Entra ID, ADFS and multi forest synchronisations, without rethinking the trust model often means building on <em><strong>foundations that were not designed to bear that weight.</strong></em></p><p>There is then a second lesson, even more subtle: <strong>trust related problems rarely manifest themselves explicitly</strong>.</p><p>They do not produce clear errors, they do not point to a precise cause. They present themselves as ambiguous behaviours, authentications that fail &#8220;for no reason&#8221;, configurations that appear correct but do not work. And it is precisely this ambiguity that makes them costly to diagnose and resolve.</p><p>As in the case of the guardian seen in Chapter 1, <em><strong>the problem is not the trusts themselves</strong></em>.</p><p>They continue to do exactly what they were designed to do: define perimeters, establish boundaries, and determine who can trust whom.</p><p>The problem arises when <strong>modern design ignores those boundaries</strong>, assuming that trust is implicit, transitive or adaptable by default.</p><p>In hybrid environments, trust is not an operational detail but a <strong>first level architectural decision</strong>.</p><p>Treating it as an inheritance to be endured, rather than as an element to be understood and redesigned, means pushing problems further into the future, where they will inevitably become more complex and more expensive, especially when &#8220;political&#8221; constraints are added to the equation.</p><p>And it is precisely from here that <em><strong>Legacy Things</strong></em><strong> </strong>continues its path: bringing back to light those silent mechanisms which, although born decades ago, still determine the behaviour of modern infrastructures.</p><p>Because ignoring the past does not make it harmless. It only makes it harder to recognise when it makes itself felt again.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Legacy Things! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Capitolo #1 - AdminSDholder: il guardiano]]></title><description><![CDATA[Quando un meccanismo di Active Directory di 25 anni fa continua a influenzare sicurezza e identity moderne]]></description><link>https://www.legacythings.it/p/capitolo-1-adminsdholder-il-guardiano</link><guid isPermaLink="false">https://www.legacythings.it/p/capitolo-1-adminsdholder-il-guardiano</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Mon, 02 Mar 2026 07:15:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!feII!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>English version available here &#8594;<a href="https://www.legacythings.it/p/chapter-1-adminsdholder-the-guardian"> [EN]</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!feII!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!feII!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!feII!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!feII!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!feII!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!feII!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2555496,&quot;alt&quot;:&quot;Illustrazione che rappresenta AdminSDHolder come un guardiano dei privilegi in Active Directory.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/189367336?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustrazione che rappresenta AdminSDHolder come un guardiano dei privilegi in Active Directory." title="Illustrazione che rappresenta AdminSDHolder come un guardiano dei privilegi in Active Directory." srcset="https://substackcdn.com/image/fetch/$s_!feII!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!feII!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!feII!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!feII!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>15 dicembre 1999, il mondo vive una strana tensione.<br>Nelle sale italiane si proietta <strong>Il miglio verde</strong>, negli Stati Uniti il pubblico discute animatamente di <strong>Fight Club</strong> e resta spiazzato dal finale de <strong>The Sixth Sense</strong>.</p><p>Le radio passano &#8220;Move Your Body&#8221; degli <strong>Eiffel 65</strong> e in Europa risuona &#8220;Mambo No. 5&#8221; di <strong>Lou Bega</strong>.</p><p>Ma nei meandri dell&#8217;IT, l&#8217;attenzione &#232; rivolta su tutt&#8217;altro.<br>Mancano sedici giorni al cambio di millennio e il mondo IT trattiene il fiato per il Millennium Bug. Si teme che allo scoccare del 1&#176; gennaio 2000 i sistemi possano bloccarsi, che i software scritti decenni prima non siano pronti al nuovo secolo.</p><p>&#200; in questo clima, tra euforia e inquietudine tecnologica, che Microsoft rilascia Windows 2000 in RTM, un sistema operativo che rompe col passato e sta per far sembrare vecchio tutto quanto c&#8217;era prima con l&#8217;introduzione di <strong>Active Directory</strong>.</p><p>E il guardiano &#232; gi&#224; l&#236;:<strong> AdminSDHolder</strong> &#232; un componente nativo, creato come prima difesa interna dei meccanismi della directory, che non pu&#242; essere sospeso n&#233; fermato, va solamente compreso.</p><h2>Cos&#8217;&#232; e come funziona</h2><p>Con <strong>AdminSDHolder</strong> ci si riferisce ad uno dei meccanismi di protezione pi&#249; importanti e pi&#249; dimenticati di Active Directory.</p><p>L&#8217;obiettivo &#232; semplice: <strong>proteggere gli account e i gruppi pi&#249; privilegiati del dominio</strong>, impedendo che permessi errati o deleghe troppo permissive possano comprometterli, volontariamente o per errore.</p><p>In parole povere: evitare di chiudersi fuori casa con le chiavi dentro o evitare che ci riesca qualche malintenzionato.<br>Per riuscire nel suo intento, Active Directory utilizza un approccio molto rigido e poco negoziabile, descritto in questo <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-c--protected-accounts-and-groups-in-active-directory">articolo</a> ufficiale.</p><p>All&#8217;interno di ogni dominio Active Directory esiste un oggetto speciale chiamato <strong>AdminSDHolder</strong>, che si trova nel container <em>System</em> del dominio.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jPOk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jPOk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 424w, https://substackcdn.com/image/fetch/$s_!jPOk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 848w, https://substackcdn.com/image/fetch/$s_!jPOk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 1272w, https://substackcdn.com/image/fetch/$s_!jPOk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jPOk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png" width="317" height="238" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:238,&quot;width&quot;:317,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:88946,&quot;alt&quot;:&quot;Schema che mostra l&#8217;oggetto AdminSDHolder nel container System di Active Directory.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/189367336?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Schema che mostra l&#8217;oggetto AdminSDHolder nel container System di Active Directory." title="Schema che mostra l&#8217;oggetto AdminSDHolder nel container System di Active Directory." srcset="https://substackcdn.com/image/fetch/$s_!jPOk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 424w, https://substackcdn.com/image/fetch/$s_!jPOk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 848w, https://substackcdn.com/image/fetch/$s_!jPOk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 1272w, https://substackcdn.com/image/fetch/$s_!jPOk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">L&#8217;oggetto AdminSDHolder contiene il template di sicurezza applicato agli account privilegiati del dominio.</figcaption></figure></div><p>Questo oggetto non rappresenta un utente o un gruppo, ma &#232; un ramo di Active Directory che contiene <strong>un modello di sicurezza, </strong>ovvero nel suo &#8220;Security Descriptor&#8221; (o ACL &gt; Access Control List) sono riportati i <strong>permessi standard </strong>che devono avere gli oggetti considerati critici e che devono essere preservati.</p><p>In altre parole:</p><blockquote><p>&#183; AdminSDHolder &#232; il <strong>template</strong></p><p>&#183; gli oggetti da proteggere sono il<strong> target </strong>a cui applicare il <strong>template</strong></p></blockquote><p>Ogni volta che Active Directory rileva una discrepanza tra il template e un oggetto target, interviene per ripristinare la situazione corretta. Ma come?</p><p>Tutto il meccanismo &#232; mosso da un &#8220;motore interno&#8221; chiamato <strong>SDProp</strong> (Security Descriptor Propagator).</p><p><strong>SDProp</strong> viene innescato sul Domain Controller che detiene il ruolo di <strong>PDCE</strong> (Primary Domain Controller Emulator), non agisce in tempo reale, effettua un ciclo di controllo con un intervallo base di 60 minuti, personalizzabile tramite chiave di registro.</p><p>Durante questo ciclo lavora come un guardiano che, se trova qualcosa fuori posto, lo riporta alla condizione attesa. </p><p>S&#236;, ma quali sono gli oggetti da proteggere?</p><p>La discriminante &#232; l&#8217;appartenenza ai gruppi built-in che detengono un minimo di privilegi sull&#8217;ambiente Active Directory, ecco la lista completa:</p><blockquote><p>&#183; Account Operators</p><p>&#183; Administrator</p><p>&#183; Administrators</p><p>&#183; Backup Operators</p><p>&#183; Domain Admins</p><p>&#183; Domain Controllers</p><p>&#183; Enterprise Admins</p><p>&#183; Enterprise Key Admins</p><p>&#183; Key Admins</p><p>&#183; Krbtgt</p><p>&#183; Print Operators</p><p>&#183; Read-only Domain Controllers</p><p>&#183; Replicator</p><p>&#183; Schema Admins</p><p>&#183; Server Operators</p></blockquote><p>Tutti i gruppi in questione e i relativi membri &#8220;subiscono&#8221; il template <strong>AdminSDHolder</strong>.</p><p><strong>NB:</strong> per membri si intendono inseriti direttamente o per via indiretta attraverso group-nesting, rendendo a volte difficile individuare gli oggetti in perimetro.</p><p>Questo spiega uno dei comportamenti pi&#249; frustranti per chi non conosce il meccanismo: &#8220;Imposto i permessi sugli oggetti, tutto funziona&#8230; e dopo un&#8217;ora spariscono.&#8221;</p><p>Ma come avviene l&#8217;applicazione del template? In una maniera intenzionalmente aggressiva: Active Directory assume che <strong>nessuna delega standard debba mai avere controllo su questi oggetti</strong>.</p><p>Ad un oggetto in ambito accadono tre cose fondamentali:</p><p>1. <strong>L&#8217;ereditariet&#224; dei permessi viene disabilitata</strong></p><blockquote><p>&#183; L&#8217;oggetto smette di ereditare le ACL dalla sua OU di appartenenza.</p><p>&#183; Questo significa che le deleghe impostate a livello di OU <strong>non hanno pi&#249; effetto</strong>.</p></blockquote><p>2. <strong>Vengono applicati i permessi di AdminSDHolder</strong></p><blockquote><p>&#183; L&#8217;ACL dell&#8217;oggetto viene resa coerente con quella del template, indipendentemente da dove l&#8217;oggetto si trovi nella struttura.</p></blockquote><p>3. <strong>Viene impostato l&#8217;attributo adminCount</strong></p><blockquote><p>&#183; L&#8217;attributo adminCount viene impostato a 1, segnalando che l&#8217;oggetto &#232; (o &#232; stato) protetto.</p><p>&#183; Questo attributo, per&#242;, <strong>non viene automaticamente ripristinato</strong> se l&#8217;oggetto esce dai gruppi privilegiati, creando spesso confusione e situazioni paradossali</p></blockquote><p>Ultima cosa da ricordare &#232; che questo meccanismo <strong>non pu&#242; essere disattivato</strong>, bisogna quindi avere ben chiare le sue dinamiche per poter progettare in maniera adeguata i processi IT che vanno a toccare Active Directory e soprattutto che fanno leva su specifiche ACL.</p><h2>Quali &#8220;danni&#8221; si possono fare</h2><p>Adesso che abbiamo capito come funzionano le cose, viene la parte a mio avviso pi&#249; interessante: vedere che &#8220;danni&#8221; si possono fare rimanendo all&#8217;oscuro di questi meccanismi.</p><p>Per farlo ho ritenuto efficace portare delle testimonianze prese direttamente sul campo.</p><h3>Caso reale #1 &#8211; Il gruppo che non ti aspetti</h3><p>Siamo nel pieno di un complesso progetto di migrazione in classico ambiente ibrido: <strong>Active Directory + Entra ID</strong>.<br>Un dominio AD sorgente con le utenze source, un dominio AD di destinazione con le utenze target, Entra Connect configurato per lavorare su entrambi e sincronizzare tutto verso Entra ID. Le utenze source sono le uniche in sync.<br>L&#8217;obiettivo &#232; chiaro quanto ambizioso: <strong>sganciare le utenze source e riagganciare quelle target</strong>, senza impatti sul cloud.</p><p>Per chi non si &#232; mai trovato in un progetto del genere, ribadisco il mio punto di vista: migrare risorse in un contesto moderno ed ibrido &#232; un lavoro da &#8220;equilibrista&#8221;.</p><p>Tutti gli aspetti coinvolti devono essere allineati al millimetro, pena il fallimento.</p><p>Quando si inizia a preparare la procedura di migrazione emergono subito i primi problemi: pi&#249; della met&#224; delle utenze presenta attributi incoerenti tra on&#8209;premise e cloud.<br>Da un rapido sguardo, Entra Connect segnala errori ricorrenti: <em><strong>permission-issue</strong></em>.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FDPx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FDPx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 424w, https://substackcdn.com/image/fetch/$s_!FDPx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 848w, https://substackcdn.com/image/fetch/$s_!FDPx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 1272w, https://substackcdn.com/image/fetch/$s_!FDPx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FDPx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png" width="356" height="225" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:225,&quot;width&quot;:356,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:85780,&quot;alt&quot;:&quot;Immagine di Entra Connect con errori di permission-issue&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/189367336?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Immagine di Entra Connect con errori di permission-issue" title="Immagine di Entra Connect con errori di permission-issue" srcset="https://substackcdn.com/image/fetch/$s_!FDPx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 424w, https://substackcdn.com/image/fetch/$s_!FDPx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 848w, https://substackcdn.com/image/fetch/$s_!FDPx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 1272w, https://substackcdn.com/image/fetch/$s_!FDPx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Entra Connect fallisce la sync con errori di permission-issue.</figcaption></figure></div><p>Prima verifica: i permessi dell&#8217;account di servizio di Entra Connect, coma suggerisce questo <a href="https://learn.microsoft.com/en-us/troubleshoot/entra/entra-id/user-prov-sync/troubleshoot-permission-issue-sync-service-manager">articolo</a> ufficiale.</p><p>Nulla di anomalo in apparenza.</p><p>Andando pi&#249; a fondo, emerge per&#242; un dettaglio curioso, tutte le utenze in errore hanno una cosa in comune: da un certo punto in avanti nel tempo, le nuove utenze vengono create con una membership &#8220;inspiegabile&#8221; &gt; <strong>Print Operators</strong>.</p><p>Quel <strong>dettaglio</strong> cambia tutto: Print Operators &#232; uno dei gruppi protetti di Active Directory.</p><p>Diventare membro significa finire automaticamente nel perimetro di <strong>AdminSDHolder</strong>, con ereditariet&#224; disabilitata, permessi riscritti da <strong>SDProp</strong> e ACL che non seguono pi&#249; la struttura dell&#8217;OU.</p><p><strong>Un meccanismo nato 25 anni fa stava bloccando il corretto flusso di dati verso il cloud</strong>.</p><p>La soluzione da applicare si &#232; rivelata tutt&#8217;altro che immediata:</p><ul><li><p>revisione dei meccanismi di provisioning</p></li><li><p>rimozione delle membership errate</p></li><li><p>ripristino dei permessi corretti su centinaia di utenze</p></li><li><p>riallineamento con il cloud</p></li></ul><p>Insomma, uno sforzo extra su molti fronti che si sarebbe potuto evitare all&#8217;origine con un po&#8217; di consapevolezza in pi&#249; nel disegno dei flussi di provisioning.</p><p>In questo caso il povero <strong>AdminSDHolder</strong> non stava ostacolando la migrazione, stava semplicemente facendo il proprio lavoro, proteggendo account che non avrebbero mai dovuto essere trattati come privilegiati.</p><h3>Caso reale #2 &#8211; Quando la sicurezza incontra l&#8217;eredit&#224;</h3><p>Altro cliente, altro ambiente ibrido: <strong>Active Directory + Entra ID</strong>, con Entra Connect regolarmente configurato.<br>Questa volta per&#242; il contesto &#232; diverso: <strong>ambiente stabile</strong>, nessuna migrazione in corso.</p><p>Viene introdotta una soluzione di <em>Manutenzione Utenti</em>, con due obiettivi ben definiti:</p><ul><li><p>notificare agli utenti la scadenza della password, consentendone il cambio da Entra ID con <em>password writeback </em>su Active Directory</p></li><li><p>disattivare automaticamente le utenze per cui non viene rilevata attivit&#224;, on&#8209;premise o cloud, da un certo periodo di tempo</p></li></ul><p>Il tutto seguendo rigorosamente il principio del<strong> Principle of Least Privilege (POLP)</strong>.<br>Vengono creati un Service Principal per Entra ID ed un GMSA per Active Directory. Agli account di servizio vengono assegnati solo i permessi strettamente necessari (POLP). La soluzione viene configurata, testata ed avviata.<br>Tutto &#232; pensato e realizzato secondo i <strong>moderni standard di sicurezza</strong> e, inizialmente, tutto sembra funzionare correttamente.</p><p>Dopo poco tempo, per&#242;, emergono i primi problemi:</p><ul><li><p>alcuni utenti non riescono a cambiare la password</p></li><li><p>altri non possono essere disattivati automaticamente</p></li></ul><p>A questo punto l&#8217;analisi si concentra dove ormai abbiamo intuito che conviene guardare: <strong>permessi</strong> sugli account impattati, <strong>AdminSDHolder</strong> ed <strong>SDProp</strong>.</p><p>Quello che emerge &#232; una situazione meno rara di quanto si possa pensare.<br>Sono presenti utenti che in passato <strong>hanno fatto parte di gruppi protetti</strong>, ma che successivamente ne sono usciti, lasciando una configurazione incoerente: oggetti che non sono pi&#249; privilegiati, che continuano ad avere <strong>adminCount = 1</strong>, <strong>eredit&#224; </strong>dei permessi<strong> interrotta</strong>, template <strong>AdminSDHolder</strong> applicato.</p><p>In questo caso specifico, la causa principale &#232; stata identificata nell&#8217;uso di <strong>assegnazioni dinamiche di gruppi privilegiati</strong>, basate su <strong>Just&#8209;In&#8209;Time Administration</strong>, sempre nel rispetto del POLP.<br>Una scelta corretta dal punto di vista della sicurezza, ma che non ha tenuto conto degli effetti persistenti di AdminSDHolder sugli oggetti in ambito.</p><p>La soluzione sulla carta sarebbe potuta sembrare semplice: <em>facciamo una bonifica e siamo a posto</em>. In realt&#224; si &#232; rivelata pi&#249; complessa del previsto, per alcune implicazioni supplementari.<br>La prima questione &#232; che, per consentire il corretto funzionamento della <em>Manutenzione Utenti</em>, &#232; stato necessario <strong>assegnare all&#8217;account di servizio i permessi direttamente sul template AdminSDHolder</strong>. Questo per consentire la manipolazione di oggetti rimasti &#8220;incastrati&#8221; nel limbo dei permessi.</p><p>Ancora una volta un <strong>dettaglio</strong> cambia per&#242; completamente lo scenario.</p><p>Questo ha infatti un impatto importante in termini di sicurezza: il sistema su cui gira la soluzione diventa a tutti gli effetti <strong>un asset critico</strong>, che deve essere trattato come <strong>Tier 0</strong> secondo <strong>l&#8217;AD Tier Model</strong>, con tutte le implicazioni del caso in termini di hardening, accessi e segregazione. Per questi aspetti vi rimando all&#8217;ottimo <a href="https://www.ictpower.it/sicurezza/implementare-active-directory-tier-model.htm">articolo</a> dell&#8217;amico <a href="https://www.linkedin.com/in/stefanonieri/">Stefano Nieri</a>.</p><p>Infine, serve prendere coscienza che non &#232; sufficiente fare tutto questo per poter risolvere: gli oggetti rimasti nel limbo vengono comunque <strong>esclusi dai successivi cicli di SDProp</strong>. Questo gli consente di &#8220;schivare&#8221; il nuovo set di permessi che consentirebbe alla soluzione di funzionare.</p><p>Unico modo per risolvere: una <strong>bonifica ad-hoc</strong> per ricondurre l&#8217;ambiente ad una situazione stabile.</p><p>Dopo aver rivisto tutto l&#8217;impianto:</p><p>&#183; una password resettata in cloud riesce ad essere propagata correttamente su Active Directory</p><p>&#183; un utente, che non accede in cloud od on-premise da molto tempo, riesce ad essere correttamente disattivato</p><p>Ancora una volta, non si tratta di una configurazione sbagliata, si tratta dell&#8217;interazione tra meccanismi legacy e requisiti di sicurezza moderni, il cui design se preso con leggerezza porta a risultati ingannevoli.</p><p>Gli ambienti ibridi quindi, con gli standard di sicurezza richiesti oggi, sono intrinsecamente pi&#249; complessi di quelli cloud-only.<br>Anche in questo caso, una maggiore consapevolezza in fase di design avrebbe permesso di impostare il lavoro fin dall&#8217;inizio nella direzione corretta, evitando costose correzioni a posteriori.</p><h2>Cosa ci ha insegnato il guardiano</h2><p>AdminSDHolder &#232; un perfetto esempio di come un &#8220;ingranaggio&#8221; che gira sotto il cofano da pi&#249; di vent&#8217;anni possa venire dimenticato: non richiede manutenzione, non genera alert, non fa rumore.</p><p>Eppure, il risultato del suo lavoro <strong>&#232; sempre presente</strong>, anche &#8211; e soprattutto &#8211; in contesti moderni e orientati al cloud.</p><p>La prima lezione che il guardiano ci lascia &#232; semplice, ma spesso sottovalutata: <strong>ignorare un meccanismo non lo rende innocuo</strong>.<br>AdminSDHolder continua a fare ci&#242; per cui &#232; stato progettato, applicando regole di sicurezza pensate per proteggere le fondamenta di Active Directory, anche quando sopra quelle fondamenta costruiamo automazioni, integrazioni cloud e processi &#8220;moderni&#8221;.</p><p>La seconda lezione &#232; che <strong>fare le cose correttamente non &#232; sempre sufficiente</strong>, se manca la consapevolezza di ci&#242; che accade sotto.<br>Nei casi visti non c&#8217;erano configurazioni improvvisate o ambienti trascurati: c&#8217;erano migrazioni pianificate, principi di least privilege, Just&#8209;In&#8209;Time administration e soluzioni pensate secondo gli standard di sicurezza attuali.<br>Eppure, senza conoscere gli effetti persistenti di AdminSDHolder, anche scelte corrette hanno prodotto risultati inattesi.</p><p>Il guardiano ci insegna anche che <strong>l&#8217;eredit&#224; sui sistemi non &#232; sempre visibile</strong>, ma prima o poi presenta il conto.<br>Utenti transitati da gruppi privilegiati, attributi come <em>adminCount</em> mai ripristinati, ereditariet&#224; dei permessi interrotta: elementi che possono restare latenti per anni, fino a quando un nuovo progetto, una nuova integrazione o un nuovo requisito di sicurezza non li porta improvvisamente alla luce.<br>Quando accade, il problema non si manifesta come un errore chiaro, ma come un comportamento &#8220;strano&#8221; da decifrare, difficile da diagnosticare e spesso pi&#249; costoso da correggere di quanto ci si aspetti.</p><p>C&#8217;&#232; infine una lezione di design pi&#249; ampia: <strong>negli ambienti ibridi la complessit&#224; non &#232; un&#8217;eccezione, &#232; la norma</strong>.<br>Cloud e on&#8209;premise non sono mondi separati, ma parti dello stesso sistema. Le regole del passato continuano a influenzare il presente, e progettare soluzioni moderne senza conoscerle significa semplicemente spostare i problemi pi&#249; avanti nel tempo.</p><p>&#200; proprio da questa consapevolezza che nasce<strong> </strong><em><strong>Legacy Things</strong></em>.<br>AdminSDHolder non &#232; un caso isolato, ma solo il primo di molti &#8220;vecchi ingranaggi&#8221; che continuano a vivere sotto la superficie delle infrastrutture attuali. Nei prossimi capitoli esploreremo altri meccanismi legacy, altre scelte progettuali del passato che ancora oggi condizionano il modo in cui costruiamo, proteggiamo e facciamo evolvere i nostri sistemi.</p><p>E a te che sei arrivato fino in fondo a questo primo capitolo chiedo:<br>quali sono i <strong>meccanismi nascosti</strong> che vorresti vedere portati alla luce nelle prossime puntate?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Grazie per aver letto Legacy Things! Iscriviti gratuitamente per ricevere nuovi post e supportare il mio lavoro.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Chapter #1 - AdminSDholder: the guardian]]></title><description><![CDATA[When a 25&#8209;year&#8209;old Active Directory mechanism still shapes modern security and identity]]></description><link>https://www.legacythings.it/p/chapter-1-adminsdholder-the-guardian</link><guid isPermaLink="false">https://www.legacythings.it/p/chapter-1-adminsdholder-the-guardian</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Mon, 02 Mar 2026 07:10:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!feII!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Versione italiana disponibile qui &#8594;</em><a href="https://www.legacythings.it/p/capitolo-1-adminsdholder-il-guardiano"> </a><em><a href="https://www.legacythings.it/p/capitolo-1-adminsdholder-il-guardiano">[IT]</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!feII!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!feII!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!feII!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!feII!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!feII!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!feII!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2555496,&quot;alt&quot;:&quot;Illustrazione che rappresenta AdminSDHolder come un guardiano dei privilegi in Active Directory.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/189367336?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustrazione che rappresenta AdminSDHolder come un guardiano dei privilegi in Active Directory." title="Illustrazione che rappresenta AdminSDHolder come un guardiano dei privilegi in Active Directory." srcset="https://substackcdn.com/image/fetch/$s_!feII!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!feII!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!feII!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!feII!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F552ae2d9-a69d-4f2f-b1f7-21bb74e9271f_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>December 15th, 1999.</strong><br>The world is living through a strange mix of excitement and tension.</p><p>In Italian cinemas, <em>The Green Mile</em> is on screen. In the United States, people debate <em>Fight Club</em> and are shocked by the ending of <em>The Sixth Sense</em>.<br>On the radio, <em>&#8220;Move Your Body&#8221;</em> by <strong>Eiffel 65</strong> plays nonstop, while <em>&#8220;Mambo No. 5&#8221;</em> by <strong>Lou Bega</strong> echoes across Europe.</p><p>But deep inside the IT world, attention is focused elsewhere.</p><p>Sixteen days remain before the turn of the millennium. The IT industry is holding its breath for the <strong>Millennium Bug</strong>, fearing that systems written decades earlier may fail when the date flips to January 1st, 2000.</p><p>In this climate of uncertainty, Microsoft releases <strong>Windows 2000 RTM</strong>, an operating system that breaks with the past and makes everything before it feel suddenly outdated, thanks to the introduction of <strong>Active Directory</strong>.</p><p>And the guardian is already there: <strong>AdminSDHolder</strong> is a native component, designed as an internal line of defense for the directory&#8217;s most critical mechanisms. It cannot be stopped or disabled. It can only be understood.</p><h2>What It Is and How It Works</h2><p><strong>AdminSDHolder</strong> refers to one of the most important &#8212; and most forgotten &#8212; protection mechanisms in Active Directory.</p><p>Its goal is simple: <strong>to protect the most privileged accounts and groups in the domain</strong>, preventing incorrect permissions or overly permissive delegations from compromising them, either accidentally or intentionally.</p><p>In simple terms: to avoid locking yourself out of your own house &#8212; or letting someone else do it for you.</p><p>To achieve this, Active Directory adopts a <strong>rigid and intentionally non&#8209;negotiable approach</strong>, documented in Microsoft&#8217;s <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-c--protected-accounts-and-groups-in-active-directory">official guidance</a> on protected accounts and groups.</p><p>Within every Active Directory domain, there is a special object called <strong>AdminSDHolder</strong>, located in the <strong>System</strong> container.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jPOk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jPOk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 424w, https://substackcdn.com/image/fetch/$s_!jPOk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 848w, https://substackcdn.com/image/fetch/$s_!jPOk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 1272w, https://substackcdn.com/image/fetch/$s_!jPOk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jPOk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png" width="317" height="238" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:238,&quot;width&quot;:317,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:88946,&quot;alt&quot;:&quot;Diagram showing the AdminSDHolder object in the System container of Active Directory.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/189367336?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Diagram showing the AdminSDHolder object in the System container of Active Directory." title="Diagram showing the AdminSDHolder object in the System container of Active Directory." srcset="https://substackcdn.com/image/fetch/$s_!jPOk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 424w, https://substackcdn.com/image/fetch/$s_!jPOk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 848w, https://substackcdn.com/image/fetch/$s_!jPOk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 1272w, https://substackcdn.com/image/fetch/$s_!jPOk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8e5681b-4d21-4660-859a-c95c3c3bf716_317x238.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">The AdminSDHolder object contains the security template applied to domain privileged accounts.</figcaption></figure></div><p>This object is not a user or a group. It is a branch of Active Directory that contains a <strong>security template</strong>.</p><p>More precisely, its <strong>security descriptor (ACL)</strong> defines the <strong>standard permissions</strong> that must be enforced on all objects considered critical.</p><p><strong>In other words:</strong></p><ul><li><p>AdminSDHolder is the<strong> template</strong></p></li><li><p>the objects to be protected are the<strong> targets </strong>to which the<strong> template </strong>is applied</p></li></ul><p>Whenever Active Directory detects a discrepancy between the template and a target object, it intervenes to restore the correct state. But how?</p><p>The entire mechanism is driven by an internal &#8220;engine&#8221; called <strong>SDProp</strong> (Security Descriptor Propagator).</p><p><strong>SDProp</strong> is triggered on the Domain Controller holding the <strong>PDCE</strong> (Primary Domain Controller Emulator) role. It does not act in real time; instead, it performs a control cycle with a default interval of <strong>60 minutes</strong>, which can be customized via a registry key.</p><p>During this cycle, it works like a guardian: if it finds something out of place, it brings it back to the expected state.</p><p>But which objects need to be protected?</p><p>The determining factor is <strong>membership in built&#8209;in groups that hold a minimum level of privilege</strong> within the Active Directory environment. Here is the complete list:</p><ul><li><p>Account Operators</p></li><li><p>Administrator</p></li><li><p>Administrators</p></li><li><p>Backup Operators</p></li><li><p>Domain Admins</p></li><li><p>Domain Controllers</p></li><li><p>Enterprise Admins</p></li><li><p>Enterprise Key Admins</p></li><li><p>Key Admins</p></li><li><p>Krbtgt</p></li><li><p>Print Operators</p></li><li><p>Read&#8209;only Domain Controllers</p></li><li><p>Replicator</p></li><li><p>Schema Admins</p></li><li><p>Server Operators</p></li></ul><p>All of these groups and their respective members are subject to the <strong>AdminSDHolder template</strong>.</p><p><strong>Note:</strong><br>By &#8220;members&#8221; we mean both <strong>direct membership</strong> and <strong>indirect membership through group nesting</strong>, which can sometimes make it difficult to identify which objects fall within scope.</p><p>This explains one of the most frustrating behaviors for those unfamiliar with the mechanism:</p><blockquote><p><em>&#8220;I set permissions on the objects, everything works&#8230; and an hour later they&#8217;re gone.&#8221;</em></p></blockquote><p>But how is the template actually applied?</p><p>In an <strong>intentionally aggressive</strong> way: Active Directory assumes that <strong>no standard delegation should ever have control over these objects</strong>.</p><p>When an object falls within scope, <strong>three fundamental things happen</strong>:</p><p>1. Permission inheritance is disabled</p><ul><li><p>The object stops inheriting ACLs from its parent OU.</p></li><li><p>This means that delegations configured at the OU level <strong>no longer apply</strong>.</p></li></ul><p>2. AdminSDHolder permissions are applied</p><ul><li><p>The object&#8217;s ACL is aligned with the template, regardless of where the object is located in the directory structure.</p></li></ul><p>3. The <code>adminCount</code> attribute is set</p><ul><li><p>The <code>adminCount</code> attribute is set to <strong>1</strong>, indicating that the object <strong>is (or has been) protected</strong>.</p></li><li><p>This attribute, however, <strong>is not automatically reset</strong> when the object is removed from privileged groups, often leading to confusion and paradoxical situations.</p></li></ul><p>The last thing to remember is that <strong>this mechanism cannot be disabled</strong>.<br>Its dynamics must be clearly understood in order to properly design IT processes that interact with Active Directory &#8212; especially those that rely on specific ACLs.</p><h2>What Can Go Wrong</h2><p>Now that we understand how the mechanism works, we get to what I personally find the most interesting part: seeing <strong>what can go wrong</strong> when these mechanisms are not fully understood.</p><p>To do that, I found it effective to bring in <strong>real&#8209;world cases taken directly from the field</strong>.</p><h3>Real Case #1 &#8211; The Group You Don&#8217;t Expect</h3><p>We are in the middle of a complex migration project in a classic <strong>hybrid environment</strong>: <strong>Active Directory + Entra ID</strong>.</p><p>There is:</p><ul><li><p>a <strong>source AD domain</strong> with <em>source</em> users</p></li><li><p>a <strong>target AD domain</strong> with <em>target</em> users</p></li><li><p><strong>Entra Connect</strong> configured to work with both domains and synchronize everything to Entra ID</p></li></ul><p>Only the <em>source</em> users are currently synchronized.</p><p>The goal is as clear as it is ambitious: <strong>detach the source users and attach the target users, without any impact on the cloud</strong>.</p><p>For those who have never been involved in a project like this, I&#8217;ll restate my point of view: <strong>migrating resources in a modern hybrid environment is a balancing act</strong>.</p><p>Every single aspect must be aligned with absolute precision &#8212; otherwise, failure is almost guaranteed.</p><p>As soon as the migration procedure is prepared, the first problems emerge: <strong>more than half of the users show inconsistent attributes between on&#8209;premises and cloud</strong>.</p><p>At a quick glance, Entra Connect reports recurring errors: <em><strong>permission-issue</strong></em>.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FDPx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FDPx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 424w, https://substackcdn.com/image/fetch/$s_!FDPx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 848w, https://substackcdn.com/image/fetch/$s_!FDPx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 1272w, https://substackcdn.com/image/fetch/$s_!FDPx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FDPx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png" width="356" height="225" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:225,&quot;width&quot;:356,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:85780,&quot;alt&quot;:&quot;Entra Connect showing synchronization errors caused by permission issues.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/189367336?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Entra Connect showing synchronization errors caused by permission issues." title="Entra Connect showing synchronization errors caused by permission issues." srcset="https://substackcdn.com/image/fetch/$s_!FDPx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 424w, https://substackcdn.com/image/fetch/$s_!FDPx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 848w, https://substackcdn.com/image/fetch/$s_!FDPx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 1272w, https://substackcdn.com/image/fetch/$s_!FDPx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1582aee-bdd3-4b08-884e-9b1dca0a3166_356x225.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Entra Connect fails synchronization due to permission issues.</figcaption></figure></div><p><strong>First check:</strong> the permissions of the <strong>Entra Connect service account</strong>, as suggested by this <a href="https://learn.microsoft.com/en-us/troubleshoot/entra/entra-id/user-prov-sync/troubleshoot-permission-issue-sync-service-manager">official article</a>.</p><p>Nothing unusual at first glance.</p><p>Digging deeper, however, a curious detail emerges: <strong>all the users affected by the issue have one thing in common</strong>: from a certain point onward, new users are being created with an <em>&#8220;unexplained&#8221;</em> membership &gt; <strong>Print Operators</strong>.</p><p>That <strong>detail </strong>changes everything:  <strong>Print Operators</strong> is one of the <strong>protected groups</strong> in Active Directory.</p><p>Becoming a member automatically places the object within the <strong>AdminSDHolder scope</strong>, with inheritance disabled, permissions rewritten by <strong>SDProp</strong>, and ACLs that no longer follow the OU structure.</p><p><strong>A mechanism designed 25 years ago was blocking the correct data flow to the cloud.</strong></p><p>The solution turned out to be anything but straightforward:</p><ul><li><p>review of provisioning mechanisms</p></li><li><p>removal of incorrect group memberships</p></li><li><p>restoration of correct permissions on hundreds of user accounts</p></li><li><p>realignment with the cloud</p></li></ul><p>In short, a significant effort across multiple fronts &#8212; one that could have been avoided from the start with a bit more awareness in the design of provisioning flows.</p><p>In this case, poor <strong>AdminSDHolder</strong> was not blocking the migration at all.<br>It was simply doing its job, <strong>protecting accounts that should never have been treated as privileged in the first place</strong>.</p><h3>Real Case #2 &#8211; When Security Meets Legacy</h3><p>Another customer, another hybrid environment: <strong>Active Directory + Entra ID</strong>, with <strong>Entra Connect</strong> properly configured.<br>This time, however, the context is different: <strong>a stable environment</strong>, with no migration in progress.</p><p>A <strong>User Maintenance</strong> solution is introduced, with two clearly defined goals:</p><ul><li><p>notify users of upcoming password expiration, allowing them to change it from Entra ID using <strong>password writeback</strong> to Active Directory</p></li><li><p>automatically disable user accounts for which no activity is detected, either on&#8209;premises or in the cloud, for a given period of time</p></li></ul><p>All of this is implemented in strict compliance with the <strong>Principle of Least Privilege (POLP)</strong>.</p><p>A <strong>Service Principal</strong> is created for Entra ID and a <strong>GMSA</strong> for Active Directory.<br>Only the strictly necessary permissions are assigned to the service accounts (POLP).<br>The solution is configured, tested, and put into production.</p><p>Everything is designed and implemented according to <strong>modern security standards</strong>, and at first, everything appears to be working correctly.</p><p>After a short time, however, the first problems begin to surface:</p><ul><li><p>some users are unable to change their passwords</p></li><li><p>others cannot be automatically disabled</p></li></ul><p>At this point, the analysis focuses where experience has taught us to look:<br><strong>permissions on the affected accounts, AdminSDHolder, and SDProp</strong>.</p><p>What emerges is a situation that is less rare than one might expect.</p><p>There are users who <strong>previously belonged to protected groups</strong>, but were later removed from them, leaving behind an inconsistent configuration: objects that are no longer privileged, yet still have <strong>adminCount = 1</strong>, <strong>permission inheritance disabled</strong>, and the <strong>AdminSDHolder template applied</strong>.</p><p>In this specific case, the root cause was identified in the use of <strong>dynamic assignments to privileged groups</strong>, based on <strong>Just&#8209;In&#8209;Time Administration</strong>, still fully compliant with POLP.</p><p>A correct choice from a security standpoint &#8212; but one that failed to account for the <strong>persistent effects of AdminSDHolder</strong> on the affected objects.</p><p>On paper, the solution might have seemed simple: <em>clean things up and move on</em>.<br>In reality, it turned out to be more complex than expected due to additional implications.</p><p>The first issue was that, to allow the User Maintenance solution to function correctly, it became necessary to assign permissions <strong>directly on the AdminSDHolder template</strong> to the service account.<br>This was required to enable the manipulation of objects that had become &#8220;stuck&#8221; in a permissions limbo.</p><p>Once again, <strong>a small detail </strong>completely changes the scenario.</p><p>This has a significant impact from a security perspective: the system running the solution effectively becomes a <strong>critical asset</strong>, which must be treated as <strong>Tier 0</strong> according to the <strong>AD Tier Model</strong>, with all the associated implications in terms of hardening, access control, and segregation.</p><p>For these aspects, I refer you to the excellent <a href="https://www.ictpower.it/sicurezza/implementare-active-directory-tier-model.htm">article</a> by my friend <strong><a href="https://www.linkedin.com/in/stefanonieri/">Stefano Nieri</a></strong>.</p><p>Finally, it is important to realize that even all of this is <strong>not sufficient</strong> on its own to fully resolve the issue: objects stuck in this limbo are still <strong>excluded from subsequent SDProp cycles</strong>.<br>This allows them to &#8220;bypass&#8221; the new permission set that would otherwise enable the solution to work correctly.</p><p>The only way to resolve the situation is an <strong>ad&#8209;hoc cleanup</strong>, aimed at bringing the environment back to a stable state.</p><p>After reviewing the entire setup:</p><ul><li><p>a password reset in the cloud is correctly propagated to Active Directory</p></li><li><p>a user who has not accessed either the cloud or on&#8209;premises for a long time can be properly disabled</p></li></ul><p>Once again, this is not a case of incorrect configuration.<br>It is the result of the interaction between <strong>legacy mechanisms and modern security requirements</strong>, whose design &#8212; if treated lightly &#8212; can lead to misleading results.</p><p>Hybrid environments, therefore, with today&#8217;s required security standards, are <strong>intrinsically more complex than cloud&#8209;only environments</strong>.</p><p>In this case as well, greater awareness during the design phase would have made it possible to set things up correctly from the start, <strong>avoiding costly corrective actions later on</strong>.</p><h2>Lessons learned from the Guardian</h2><p><strong>AdminSDHolder</strong> is a perfect example of how a &#8220;gear&#8221; that has been running under the hood for more than twenty years can be forgotten: it requires no maintenance, generates no alerts, and makes no noise.</p><p>And yet, the result of its work is always present &#8212; even, and especially, in modern cloud&#8209;oriented environments.</p><p>The first lesson the guardian teaches us is simple, but often underestimated:<br><strong>ignoring a mechanism does not make it harmless.</strong></p><p>AdminSDHolder continues to do exactly what it was designed to do, enforcing security rules meant to protect the foundations of Active Directory &#8212; even when, on top of those foundations, we build automation, cloud integrations, and &#8220;modern&#8221; processes.</p><p>The second lesson is that <strong>doing things correctly is not always enough</strong> if there is no awareness of what happens underneath.</p><p>In the cases we&#8217;ve seen, there were no improvised configurations or neglected environments.<br>There were planned migrations, least&#8209;privilege principles, Just&#8209;In&#8209;Time administration, and solutions designed according to current security standards.</p><p>And yet, without understanding the persistent effects of AdminSDHolder, even correct choices produced unexpected results.</p><p>The guardian also teaches us that <strong>legacy in systems is not always visible</strong>, but sooner or later, it comes back to collect its due.</p><p>Users who once belonged to privileged groups, attributes like <code>adminCount</code> that were never reset, broken permission inheritance &#8212; these are elements that can remain latent for years, until a new project, a new integration, or a new security requirement suddenly brings them to light.</p><p>When that happens, the problem does not manifest as a clear error, but as a &#8220;strange&#8221; behavior that is difficult to interpret, hard to diagnose, and often far more expensive to fix than expected.</p><p>Finally, there is a broader design lesson: <strong>in hybrid environments, complexity is not an exception &#8212; it is the norm.</strong></p><p>Cloud and on&#8209;premises are not separate worlds, but parts of the same system.<br>Rules from the past continue to influence the present, and designing modern solutions without knowing them simply means pushing problems further down the road.</p><p>It is precisely from this awareness that <em><strong>Legacy Things</strong></em> was born.</p><p>AdminSDHolder is not an isolated case, but only the first of many &#8220;old gears&#8221; that continue to operate beneath the surface of today&#8217;s infrastructures.<br>In the next chapters, we will explore other legacy mechanisms &#8212; other design choices from the past that still shape how we build, protect, and evolve our systems today.</p><p>And to you, who made it all the way to the end of this first chapter, I ask:</p><p><strong>which hidden mechanisms would you like to see brought into the light next?</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Grazie per aver letto Legacy Things! Iscriviti gratuitamente per ricevere nuovi post e supportare il mio lavoro.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Perché Legacy Things]]></title><description><![CDATA[Le radici del progetto]]></description><link>https://www.legacythings.it/p/perche-legacy-things</link><guid isPermaLink="false">https://www.legacythings.it/p/perche-legacy-things</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Sun, 01 Mar 2026 09:35:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!sO_L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39d4dc6-6d70-4a35-a405-f311f0fbb502_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>English version available here &#8594;<a href="https://legacythings.substack.com/publish/post/189152381"> [EN]</a></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sO_L!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39d4dc6-6d70-4a35-a405-f311f0fbb502_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sO_L!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39d4dc6-6d70-4a35-a405-f311f0fbb502_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!sO_L!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39d4dc6-6d70-4a35-a405-f311f0fbb502_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!sO_L!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39d4dc6-6d70-4a35-a405-f311f0fbb502_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!sO_L!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39d4dc6-6d70-4a35-a405-f311f0fbb502_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sO_L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39d4dc6-6d70-4a35-a405-f311f0fbb502_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c39d4dc6-6d70-4a35-a405-f311f0fbb502_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1506581,&quot;alt&quot;:&quot;Illustrazione che mostra tecnologie IT moderne in superficie e sistemi legacy come radici sottostanti, simbolo del progetto Legacy Things.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/189150877?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39d4dc6-6d70-4a35-a405-f311f0fbb502_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustrazione che mostra tecnologie IT moderne in superficie e sistemi legacy come radici sottostanti, simbolo del progetto Legacy Things." title="Illustrazione che mostra tecnologie IT moderne in superficie e sistemi legacy come radici sottostanti, simbolo del progetto Legacy Things." srcset="https://substackcdn.com/image/fetch/$s_!sO_L!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39d4dc6-6d70-4a35-a405-f311f0fbb502_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!sO_L!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39d4dc6-6d70-4a35-a405-f311f0fbb502_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!sO_L!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39d4dc6-6d70-4a35-a405-f311f0fbb502_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!sO_L!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc39d4dc6-6d70-4a35-a405-f311f0fbb502_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Osservando ci&#242; che accade nelle moderne infrastrutture IT, mi capita sempre pi&#249; spesso di imbattermi in malfunzionamenti o inefficienze che non nascono da bug di sistema o errori di progettazione, ma da qualcosa di molto pi&#249; semplice: <strong>un gap di conoscenza</strong>.</p><p>I nuovi custodi delle infrastrutture enterprise sono cresciuti in un contesto dinamico, dove il cloud &#232; il minimo sindacale e i sistemi si parlano tramite API o protocolli moderni. Sono estremamente competenti quando si parla di app, federazioni, container, AI.<br>Spesso per&#242; non hanno mai avuto l&#8217;opportunit&#224; di approfondire davvero le fondamenta on-premise che ancora reggono tutto e quando ci devono mettere le mani improvvisano o si affidano alle dubbie risposte dell&#8217;AI.</p><p>Meccanismi che per chi ha iniziato tra Windows 2000 e le prime foreste Active Directory sono familiari, oggi diventano enigmi a volte incomprensibili.<br>Ma non hanno colpe, stanno semplicemente vivendo un&#8217;epoca dove i temi on-premise sono stati &#8220;messi in soffitta&#8221;, perch&#233; nel tempo hanno perso di interesse e quindi di essere divulgati.</p><p>Sono argomenti che non generano pi&#249; nuovo business, non vengono presentati ad un keynote, non fanno marketing. Restano l&#236;, latenti, nell&#8217;ombra di tecnologie pi&#249; interessanti che sono il cuore pulsante degli articoli tecnici e degli eventi IT.</p><p>Eppure, nonostante siano da molti &#8220;dichiarate morte&#8221;, queste tecnologie resistono ai decenni e restano operative, come dei soldati fedeli a cui nessuno ha detto che la guerra &#232; finita.</p><p>Tutto questo porta per&#242; ad effetti domino inevitabili: una configurazione errata nelle fondamenta di Active Directory pu&#242; produrre conseguenze a cascata sui sistemi di autenticazione cloud (Entra ID) o sull&#8217;accesso a piattaforme SaaS.</p><p>La cosa interessante che noto &#232; per&#242; che, quando questi temi vengono spiegati, l&#8217;interesse &#232; altissimo. Il problema non &#232; la mancanza di curiosit&#224;, &#232; la mancanza di esposizione.</p><p>&#200; da questa osservazione che nasce questo piccolo progetto: <strong>Legacy Things</strong>.<br>Una serie di articoli per esplorare quei meccanismi progettati venti e passa anni fa che continuano a influenzare le infrastrutture di oggi, sperando cos&#236; di poter colmare almeno un poco questo gap di conoscenza.</p><p>Nel primo capitolo partiremo da uno di quei meccanismi silenziosi che, di recente, ha dimostrato sul campo quanto il passato sia ancora profondamente intrecciato con il presente.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Grazie per aver letto Legacy Things! Iscriviti gratuitamente per ricevere nuovi post e supportare il mio lavoro.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Why Legacy Things]]></title><description><![CDATA[The roots of the project]]></description><link>https://www.legacythings.it/p/why-legacy-things</link><guid isPermaLink="false">https://www.legacythings.it/p/why-legacy-things</guid><dc:creator><![CDATA[Marco Lelli]]></dc:creator><pubDate>Sun, 01 Mar 2026 09:30:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!X1mS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe504c28b-2207-4a23-bb18-5b5e0449725c_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Versione italiana disponibile qui &#8594;</em> [<a href="https://legacythings.substack.com/publish/post/189150877">IT</a>]</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!X1mS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe504c28b-2207-4a23-bb18-5b5e0449725c_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!X1mS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe504c28b-2207-4a23-bb18-5b5e0449725c_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!X1mS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe504c28b-2207-4a23-bb18-5b5e0449725c_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!X1mS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe504c28b-2207-4a23-bb18-5b5e0449725c_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!X1mS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe504c28b-2207-4a23-bb18-5b5e0449725c_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!X1mS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe504c28b-2207-4a23-bb18-5b5e0449725c_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e504c28b-2207-4a23-bb18-5b5e0449725c_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1506581,&quot;alt&quot;:&quot;Illustration showing modern IT technologies above and legacy systems as roots below, representing the Legacy Things project.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.legacythings.it/i/189152381?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe504c28b-2207-4a23-bb18-5b5e0449725c_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Illustration showing modern IT technologies above and legacy systems as roots below, representing the Legacy Things project." title="Illustration showing modern IT technologies above and legacy systems as roots below, representing the Legacy Things project." srcset="https://substackcdn.com/image/fetch/$s_!X1mS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe504c28b-2207-4a23-bb18-5b5e0449725c_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!X1mS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe504c28b-2207-4a23-bb18-5b5e0449725c_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!X1mS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe504c28b-2207-4a23-bb18-5b5e0449725c_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!X1mS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe504c28b-2207-4a23-bb18-5b5e0449725c_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>While observing what happens in modern IT infrastructures, I increasingly find myself dealing with malfunctions and inefficiencies that are not caused by bugs or design flaws, but by something much simpler: a <strong>knowledge gap</strong>.</p><p>The new custodians of enterprise infrastructures have grown up in a dynamic environment, where the cloud is the baseline and systems communicate through APIs and modern protocols.<br>They are highly skilled when it comes to applications, federations, containers, and AI.</p><p>Yet many of them have never had the opportunity to truly understand the on&#8209;premise foundations that still hold everything together. And when they are forced to interact with them, they often improvise or rely on questionable answers from AI tools.</p><p>Mechanisms that were familiar to those who started their careers with Windows 2000 and the first Active Directory forests have now become puzzling, sometimes incomprehensible.</p><p>This is not their fault.<br>They are simply operating in a time when on&#8209;premise topics have been pushed aside, having lost visibility, interest, and therefore proper documentation and discussion.</p><p>These are not topics that generate new business.<br>They are not showcased in keynotes.<br>They do not drive marketing narratives.</p><p>They remain there, latent, in the shadow of more appealing technologies that dominate technical articles and IT events.</p><p>And yet, despite being declared &#8220;dead&#8221; by many, these technologies have endured for decades and continue to operate &#8212; like loyal soldiers who were never told the war was over.</p><p>This inevitably leads to cascading effects: a misconfiguration in the foundations of a system can ripple through cloud authentication services or access to SaaS platforms.</p><p>What I find most interesting is that, when these topics are properly explained, <strong>interest is always high</strong>.<br>The problem is not a lack of curiosity &#8212; it is a lack of exposure.</p><p>It is from this observation that <strong>Legacy Things</strong> was born:<br>a series of articles aimed at exploring mechanisms designed more than twenty years ago that still influence today&#8217;s infrastructures, with the hope of closing at least part of this knowledge gap.</p><p>In the first chapter, we&#8217;ll start from one of those silent mechanisms that has recently shown, in real&#8209;world scenarios, just how deeply the past is still intertwined with the present.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.legacythings.it/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Grazie per aver letto Legacy Things! Iscriviti gratuitamente per ricevere nuovi post e supportare il mio lavoro.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>