BrkrOps Inc.

BrkrOps Blog

Field notes from Windows Server,
identity, and PKI
.

Long-form technical writing from the BrkrOps team — Active Directory Certificate Services, PKI defence, identity, and Windows Server, written by the people who do this work for a living.

BrkrOps · PKI Operations

The model has no answer.

An attacker pivots from a Tier 2 workstation to owning the whole forest through SCCM. The tiering model calls SCCM, Intune, Entra Connect, backup, and hypervisors Tier 1 — but each holds unrestricted administrative access to Tier 0. Why the guidance has an answer nobody implements.

· BrkrOps Inc.

BrkrOps · PKI Operations

The Notary Cannot Carry the Seal

An HSM-backed CA can pass every health check and still be unable to issue a certificate or publish a CRL — because its signing key lives across a network round trip. Why CRL publication is the failure you cannot absorb, and what to monitor instead.

· BrkrOps Inc.

BrkrOps · PKI Operations

Two writes.

Two things on a certificate template are called Write — the template ACL and the Supply-in-the-request setting. Only one is safe to delegate. Confuse them, and a helpful admin hands an attacker a template they can quietly rewrite into a domain-admin path.

· BrkrOps Inc.

BrkrOps · PKI Strategy

Cloud PKI Is Free. Sort Of.

Intune Cloud PKI is included with Microsoft 365 E5 as of July 1, 2026 — but almost no enterprise is 100% E5. The real five-year TCO of Cloud PKI vs ADCS, and where ADCS still earns its keep in 2026.

· BrkrOps Inc.

BrkrOps · PKI Operations

The Companies I Won't Give My Data To

What twelve years inside other people's PKI taught me about who actually protects your data — and who just says they do.

· BrkrOps Inc.

BrkrOps · PKI Operations

The Locked Door

Why only deploying what we planned for avoids a painful experience.

· BrkrOps Inc.

BrkrOps · PKI Operations

Your backup is the breach.

Why backing up your Tier 0 systems the same way you back up file servers is how an attacker walks off with your CA's private key — and how to back up DCs and CAs without handing them Tier 0.

· BrkrOps Inc.

Truvald · ADCS Security

Build the root the right way, sign your sub, get one year back.

Why a CAPolicy.inf root issues one-year subordinate certificates no matter what you typed — and the ValidityPeriodUnits issuance ceiling that actually controls it.

· BrkrOps Inc.

Truvald · ADCS Security

Time to come back to CDP.

Why your CRL distribution point doesn't belong on the CA, and probably shouldn't be in LDAP either.

· BrkrOps Inc.

Truvald · ADCS Security

Reading an AD Certificate Template: Every Attribute, Explained

A field guide to the attributes behind a certutil -dsTemplate dump: what each one does, and which ones you can actually change.

· BrkrOps Inc.

Truvald · ADCS Security

NAC with X.509: the good, the bad, and the ugly.

What 802.1X with EAP-TLS actually buys you, where the exceptions creep in, and why NAC is a PKI project — not a network project.

· BrkrOps Inc.

Truvald · ADCS Security

It's not ADCS.

Where certificate templates actually live, and what that means for hardening your PKI.

· BrkrOps Inc.

Truvald · ADCS Security

A CA is a CA.

Why your Certification Authority should do exactly one thing, and what to keep off it.

· BrkrOps Inc.

Truvald · ADCS Security

You checked your CAs.

How to replace a default certificate template, in three steps.

· BrkrOps Inc.

Truvald · ADCS Security

Twenty-five years.

Why the default certificate templates in every ADCS install are the foundation of most ESC findings.

· BrkrOps Inc.