Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity News

Red forest is gone, now what?

By Bryan Patton
active directory - cyber
September 24, 2021

Given that approximately 90% of the world’s enterprises use Active Directory (AD) as their primary authentication and authorization platform for organizations running Windows, it is no surprise that AD is a key target for cybercriminals. Most known attacks targeting AD accounts are conducted by attackers pursuing horizontal kill chains with pass-the-hash, golden-ticket and related techniques that utilize authentication protocols such as NTLM and Kerberos. 


To prevent these types of attacks, Microsoft developed a reference architecture designed to isolate privileged credentials in what they called Enhanced Security Administrative Environment (ESAE), or Red Forest. ESAE is a layered security approach that requires creating a special administrative forest to manage all privileged identities in AD by dividing and tiering access of administrator accounts into three levels: Tier 0, Tier 1 and Tier 2. By tiering and controlling where admins can log in, organizations can reduce the risk of privilege escalation by preventing bad guys from accessing privileged credentials or using the credentials if they gain access. 


Microsoft recently announced that they’re retiring the 10-year old ESAE/Red Forest model and are replacing it with a modern, cloud-based privileged access strategy that can be implemented using their new guidance — Rapid Modernization Plan (RAMP). This is good news for AD administrators, given that migrating to a Red Forest architecture was never something easy to do. RAMP allows organizations to rapidly deploy security strategies that offer the same level of AD protection, if not more, more efficiently.


Why the Red Forest is Not a Panacea 

The Red Forest approach is not practical for most organizations, although great in principle. It requires an extremely complex architecture which can be costly and cumbersome. Implementing ESAE is time-consuming as most organizations don’t want to risk causing downtime due to breaking something in the process. Disabling NTLM Authentication is a challenge, and most businesses can’t do that because they rely on NTLM applications to provide revenue-generating products and services. While you may be more secure without NTLM, it’s not realistic. It also requires additional infrastructure, making it costly and messy, and organizations are already struggling to keep up with basic configurations. ESAE operates on “assume breach” principles. This sometimes requires a full migration of an existing environment to another environment to mitigate risk, which is another costly and time-consuming process. 


Is It Really Gone?

Red Forest is going away, but not in its entirety. There are very specific use cases that are still recommended, such as in isolated on-premises environments like SCADA and industrial control systems or highly regulated environments that require an administrative forest configuration. And not everyone will make the shift to the cloud. In these scenarios, ESAE implementation is advisable. For organizations that don’t fall into any of these exceptions, it is recommended that they follow RAMP, which allows you to rapidly deploy privileged identity security strategies in a modern AD environment, including those that run both AD and Azure AD. RAMP is more efficient and effective to implement and provides more protection since AD and Azure AD can now be joined to prevent lateral movement in an attack. The key is to do something now and do it fast, as leaving AD credentials unprotected is not an option.


Speaking of RAPID – the proxy approach

The keyword in RAMP is RAPID. Organizations need to change rapidly, and part of that modernization plan could include the Orange Forest approach, which achieves much of the same functionality but in a faster time. With this approach, Quest has seen customers do ActiveRoles implementation in less than two weeks. It doesn’t require disabling NTLM Authentication but instead requires removing native rights and enabling admins to proxy their access into their directory. 

The Orange Forest provides the additional benefit of extra provisioning capabilities for objects and the added ability to have workflow approval for changes in the directory or in Group Policies. The proxy method ensures that nobody has more rights than they need and that no one account has full rights. After all, should any one person really have absolute power? 

KEYWORDS: active directory cyber secu information security risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Bryan patton headshot

Bryan Patton, CISSP, is a Principal Strategic Systems Consultant at Quest Software. For nearly 20 years, he has helped customers shape their Microsoft environments. With particular emphasis on Active Directory and Office 365 environments, Patton specializes in Identity and Access Management, Data Governance, Migration and Security.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • europe-flag-enews

    Preparing for the GDPR: What Security Needs to Know Now

    See More
  • Tiktok

    Banning TikTok and Chinese apps is a national security red herring

    See More
  • cyber security freepik

    Why security has broken down—and what it means now (Part 1)

    See More

Related Products

See More Products
  • The Database Hacker's Handboo

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing