Study: 42 Percent Of Organizations Report Unauthorized Active Directory Access

Consider the security risk if you moved into a new apartment and the landlord didn't bother getting the keys back from the previous tenants.

One night while you are away the previous tenant slips back into your place and takes your valuables. Upon confronting the landlord, you find that getting the keys or switching the locks wasn't a priority for him. For a company, this is what it's like with each employee promotion, division switch, project completion, or termination. With each delay in updating Active Directory, the system administrator is essentially leaving the door unlocked and putting a company's assets at risk.

According to a study conducted by Osterman Research and sponsored by Imanami, 42 percent of organizations report unauthorized access of information through Active Directory.

How serious is this? Imagine a company with 3,000 employees with a turnover rate of 10 percent. Until system administrators delete Active Directory access and disable access to their credentials, 300 former employees have access to e-mail and other network resources specific to their former job function. This doesn't even take into account the amount of internal turnover of jobs. In fact, 44 percent of the respondents have received an e-mail sent to a distribution list that used to be relevant to their job but is no longer.

Group management for Active Directory is time consuming and takes on average 5.8 hours per 1,000 users a week to manage. This is a mundane task which 81 percent of respondents manage manually, and only 7 percent use a solution to automate the process.

The problem is that although system administrators understand groups need to be managed, it is not a top priority and in fact falls to the bottom. 27 percent of respondents found managing Active Directory to be more boring than managing email servers, 21 percent found it more boring than filling out expense reports, and 19 percent found it more boring than taking out the garbage.

"It's no surprise that group management is time consuming and tends to be last on a systems administrator's to-do list, but it can't be neglected," said Michael Osterman, principal at Osterman Research. "A failure to manage groups properly poses a serious security threat and could lead to loss of intellectual property and other serious consequences. Companies need to shift from a manual approach and look to solutions that manage the entire lifecycle of the group."

"Group management is manually time intensive and often done behind schedule which highlights the need to have an easy and efficient process," said Robert Haaverson, CEO of Imanami. "In today's economy, IT resources are already scarce. Administrators don't have time to do mundane tasks, but managing group lifecycles is too important to delegate to someone who doesn't understand the implications of poor group management."

The Osterman Research study, entitled "The Hidden Costs and Challenges of Group Management," provides an analysis of the time and cost spent and the potential problems faced when managing groups in Active Directory.

The study was conducted in October with more than 100 organizations that are using Microsoft Exchange as a production e-mail system. The complete study can be found at www.imanami.com.

Featured

  • Cloud Security Alliance Brings AI-Assisted Auditing to Cloud Computing

    The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today introduced an innovative addition to its suite of Security, Trust, Assurance and Risk (STAR) Registry assessments with the launch of Valid-AI-ted, an AI-powered, automated validation system. The new tool provides an automated quality check of assurance information of STAR Level 1 self-assessments using state-of-the-art LLM technology. Read Now

  • Report: Nearly 1 in 5 Healthcare Leaders Say Cyberattacks Have Impacted Patient Care

    Omega Systems, a provider of managed IT and security services, today released new research that reveals the growing impact of cybersecurity challenges on leading healthcare organizations and patient safety. According to the 2025 Healthcare IT Landscape Report, 19% of healthcare leaders say a cyberattack has already disrupted patient care, and more than half (52%) believe a fatal cyber-related incident is inevitable within the next five years. Read Now

  • AI Is Now the Leading Cybersecurity Concern for Security, IT Leaders

    Arctic Wolf recently published findings from its State of Cybersecurity: 2025 Trends Report, offering insights from a global survey of more than 1,200 senior IT and cybersecurity decision-makers across 15 countries. Conducted by Sapio Research, the report captures the realities, risks, and readiness strategies shaping the modern security landscape. Read Now

  • Analysis of AI Tools Shows 85 Percent Have Been Breached

    AI tools are becoming essential to modern work, but their fast, unmonitored adoption is creating a new kind of security risk. Recent surveys reveal a clear trend – employees are rapidly adopting consumer-facing AI tools without employer approval, IT oversight, or any clear security policies. According to Cybernews Business Digital Index, nearly 90% of analyzed AI tools have been exposed to data breaches, putting businesses at severe risk. Read Now

  • Software Vulnerabilities Surged 61 Percent in 2024, According to New Report

    Action1, a provider of autonomous endpoint management (AEM) solutions, today released its 2025 Software Vulnerability Ratings Report, revealing a 61% year-over-year surge in discovered software vulnerabilities and a 96% spike in exploited vulnerabilities throughout 2024, amid an increasingly aggressive threat landscape. Read Now

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”