BrkrOps Blog
Field notes from Windows Server,
identity, and PKI.
Long-form technical writing from the BrkrOps team — Active Directory Certificate Services, PKI defence, identity, and Windows Server, written by the people who do this work for a living.
BrkrOps · PKI Operations
The model has no answer.
An attacker pivots from a Tier 2 workstation to owning the whole forest through SCCM. The tiering model calls SCCM, Intune, Entra Connect, backup, and hypervisors Tier 1 — but each holds unrestricted administrative access to Tier 0. Why the guidance has an answer nobody implements.
BrkrOps · PKI Operations
The Notary Cannot Carry the Seal
An HSM-backed CA can pass every health check and still be unable to issue a certificate or publish a CRL — because its signing key lives across a network round trip. Why CRL publication is the failure you cannot absorb, and what to monitor instead.
BrkrOps · PKI Operations
Two writes.
Two things on a certificate template are called Write — the template ACL and the Supply-in-the-request setting. Only one is safe to delegate. Confuse them, and a helpful admin hands an attacker a template they can quietly rewrite into a domain-admin path.
BrkrOps · PKI Strategy
Cloud PKI Is Free. Sort Of.
Intune Cloud PKI is included with Microsoft 365 E5 as of July 1, 2026 — but almost no enterprise is 100% E5. The real five-year TCO of Cloud PKI vs ADCS, and where ADCS still earns its keep in 2026.
BrkrOps · PKI Operations
The Companies I Won't Give My Data To
What twelve years inside other people's PKI taught me about who actually protects your data — and who just says they do.
BrkrOps · PKI Operations
The Locked Door
Why only deploying what we planned for avoids a painful experience.
BrkrOps · PKI Operations
Your backup is the breach.
Why backing up your Tier 0 systems the same way you back up file servers is how an attacker walks off with your CA's private key — and how to back up DCs and CAs without handing them Tier 0.
Truvald · ADCS Security
Build the root the right way, sign your sub, get one year back.
Why a CAPolicy.inf root issues one-year subordinate certificates no matter what you typed — and the ValidityPeriodUnits issuance ceiling that actually controls it.
Truvald · ADCS Security
Time to come back to CDP.
Why your CRL distribution point doesn't belong on the CA, and probably shouldn't be in LDAP either.
Truvald · ADCS Security
Reading an AD Certificate Template: Every Attribute, Explained
A field guide to the attributes behind a certutil -dsTemplate dump: what each one does, and which ones you can actually change.
Truvald · ADCS Security
NAC with X.509: the good, the bad, and the ugly.
What 802.1X with EAP-TLS actually buys you, where the exceptions creep in, and why NAC is a PKI project — not a network project.
Truvald · ADCS Security
It's not ADCS.
Where certificate templates actually live, and what that means for hardening your PKI.
Truvald · ADCS Security
A CA is a CA.
Why your Certification Authority should do exactly one thing, and what to keep off it.
Truvald · ADCS Security
You checked your CAs.
How to replace a default certificate template, in three steps.
Truvald · ADCS Security
Twenty-five years.
Why the default certificate templates in every ADCS install are the foundation of most ESC findings.
