<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel><title>Windows domains — Trust is earned, not given</title><link>https://www.bobhuang.com/series/windows-domains/</link><description>How Windows proves who you are: the NT domain trust maze before Active Directory, then AD, Kerberos and NTLM, hybrid identity, and the passwordless endgame.</description><language>en</language><lastBuildDate>08 Oct 2024 12:00:00 GMT</lastBuildDate><atom:link href="https://www.bobhuang.com/series/windows-domains/feed.xml" rel="self" type="application/rss+xml"/><item><title>Windows domains, part 6: NTLM retirement, Server 2025, and the passwordless endgame</title><link>https://www.bobhuang.com/blog/786/windows-domains-part6-ntlm-retirement-future/</link><guid>https://www.bobhuang.com/blog/786/windows-domains-part6-ntlm-retirement-future/</guid><pubDate>08 Oct 2024 12:00:00 GMT</pubDate><description>In 2023 Microsoft did what this series has been building toward since part 3: it put NTLM on a deprecation path — first blocking NTLMv1 and turning off…</description></item><item><title>Windows domains, part 5: hybrid identity — Entra Connect, the PRT, and the seam between two worlds</title><link>https://www.bobhuang.com/blog/785/windows-domains-part5-hybrid-entra/</link><guid>https://www.bobhuang.com/blog/785/windows-domains-part5-hybrid-entra/</guid><pubDate>17 May 2022 12:00:00 GMT</pubDate><description>By 2022 the forest was no longer the whole story. Most enterprises run a hybrid: AD for the devices, file servers, and legacy apps; Entra ID (Azure AD, renamed…</description></item><item><title>Windows domains, part 4: the feature arc — Server 2008 R2 to 2019</title><link>https://www.bobhuang.com/blog/784/windows-domains-part4-feature-arc/</link><guid>https://www.bobhuang.com/blog/784/windows-domains-part4-feature-arc/</guid><pubDate>04 Jun 2019 12:00:00 GMT</pubDate><description>Between 2009 and 2019 the forest quietly acquired almost every operational safety net it now depends on. Each release added one or two big things; knowing…</description></item><item><title>Windows domains, part 3: Kerberos and NTLM — how Windows actually proves who you are</title><link>https://www.bobhuang.com/blog/783/windows-domains-part3-kerberos-ntlm/</link><guid>https://www.bobhuang.com/blog/783/windows-domains-part3-kerberos-ntlm/</guid><pubDate>21 Nov 2017 12:00:00 GMT</pubDate><description>Forests and transitive trusts only pay off if the authentication protocol is worth trusting transitively. This part is the protocol deep-dive: NTLM, the NT-era…</description></item><item><title>Windows domains, part 2: AD 2000 changed everything — forests, trees, and transitive trust</title><link>https://www.bobhuang.com/blog/782/windows-domains-part2-ad-forest/</link><guid>https://www.bobhuang.com/blog/782/windows-domains-part2-ad-forest/</guid><pubDate>08 Sep 2016 12:00:00 GMT</pubDate><description>When Windows 2000 shipped Active Directory, it did not upgrade the NT domain — it replaced its geometry. Three ideas did most of the work, and all three are…</description></item><item><title>Windows domains before Active Directory: NT domains, master domains, and the trust maze</title><link>https://www.bobhuang.com/blog/781/windows-domains-part1-nt-era/</link><guid>https://www.bobhuang.com/blog/781/windows-domains-part1-nt-era/</guid><pubDate>14 Apr 2015 12:00:00 GMT</pubDate><description>Fifteen years after Active Directory shipped, the shape of its design still only makes sense once you understand what it replaced. This series starts where…</description></item></channel></rss>