Skip to content

Cybersecurity Active Directory

The Grand Slam You Are Missing

Tyler clicked a link, downloaded a blank PDF, and moved on. What he did not know was that a ransomware script was now sitting on his computer waiting to run. What stopped it was a policy that had been set once and running silently in the background for two years. That is Active Directory.

Illustration for the article: The Grand Slam You Are Missing
Tyler clicked a link, downloaded a blank PDF, and moved on. What he did not know was that a ransomware script was now sitting on his computer waiting to run. What stopped it was a policy that had been set once and running silently in the background for two years. That is Active Directory.

Let me tell you about Tyler.

Tyler works in your office. He is a good employee. He is not reckless, he is not careless, he is just a person trying to get through his inbox on a Tuesday afternoon.

He gets an email. There is a link in it for an invoice. He clicks the link, downloads the PDF. The PDF is blank. He figures it did not load right, closes it, and moves on with his day.

What Tyler does not know is that clicking that link ran a script on his computer. The script is sitting there now, waiting. It is designed to execute when the computer goes idle – to start doing what it was built to do, which is encrypt every file it can reach and demand a ransom to get them back.

But here is what happens instead.

The computer locks after five minutes of inactivity, the way it was configured to. And when the script tries to do its next step – install the component it needs to run – it hits a wall. Application installation requires admin-level credentials. Tyler does not have admin-level credentials on his own machine. Nobody on the floor does.

The script fails. The ransomware never executes. Tyler never knows anything happened. The business never knows anything happened.

That is Active Directory. That is what it does when nobody is paying attention to it. And most businesses do not have it.

What Active Directory Actually Is

When I explain Active Directory to a business owner, I do not start with the technical definition. I start with this:

Every setting, every option, every configuration on every computer in your building can be controlled from one authoritative location.

That is it. That is the concept.

Want to prevent users from installing software? Remove their access to the installer – done across every machine at once.

Want to change the desktop background on every computer to the company logo? Done.

Want every computer to lock automatically after five minutes of inactivity? Done.

Want to put the help desk phone number, the support ticket link, the computer name, the IP address, and the username right on the desktop background so your users never have to call your cell phone to ask basic questions? Done. Every machine. Instantly.

Want to make sure that when an employee leaves, every door they had access to closes the moment you remove their account? Done – and we talked about exactly what happens when that is not in place in The Ghost Connection Problem.

Active Directory is the control room. It is the place where an IT administrator – or a vCISO, or a managed service provider – can see every device in the organization, enforce every policy, push every update, and respond to every problem from a single authoritative source rather than running from machine to machine hoping they got everything.

What Life Looks Like Without It

Most small and mid-sized businesses are running without centralized device management. What that actually looks like day to day is this:

Every computer is its own island. Settings were configured whenever the machine was set up – maybe by the IT person who installed it, maybe by the employee who turned it on for the first time, maybe by whoever was available that day. Those settings have not been audited since.

Stay Ahead of Technology Risk

Practical, no-jargon insights on cybersecurity, resilience, and IT strategy - built for business leaders, not engineers.

Users have local administrator access because it was easier to set it up that way and nobody thought through what that meant. Which means when Tyler downloads a malicious PDF, the script that runs afterward has the same permissions Tyler has – which is enough to do serious damage.

There is no consistent password policy. Some machines lock after five minutes. Some never lock. Some have 8-character passwords. Some have the same password they were set up with three years ago.

When an employee leaves, someone goes through a mental checklist of what to revoke – email, yes; the billing system login, maybe; the seventeen other systems and configurations they touched over two years, probably not.

And when something goes wrong on a machine, the IT person – or the accidental custodian – has to physically touch the device or remote in individually. One machine at a time. No visibility into what is happening across the fleet. No ability to push a fix everywhere at once.

This is not a criticism of anyone who built it that way. It is how almost every business starts. The problem is it is also how too many businesses stay – long after they have grown past the point where it is safe.

The Fight You Are Going to Have

I want to be honest about something.

When I bring Active Directory into the conversation with a business owner, it is almost never an easy yes. It is usually a fight. Not because the idea is wrong – the IT person in the room has been asking for this for years and is nodding before I finish the sentence. But because the owner has to trust that this is worth the investment, the disruption, and the change.

That trust takes time. It takes a track record. It takes the owner believing that the person recommending this is doing it for the company, not for the invoice.

I am not going to tell you it is a quick conversation. It is not. What I will tell you is that the businesses that have made the investment do not go back. Not after they see what centralized management actually means. Not after they realize the thing that stopped Tyler’s ransomware was a policy that was set once and ran silently in the background for two years without anyone thinking about it.

The IT person in your building already knows you need this. They have probably already asked. The question is whether you are ready to trust that they are right.

What the Grand Slam Actually Looks Like

Here is what a fully deployed Active Directory environment with MFA and Single Sign-On gives a business:

Every device enrolled and visible from one dashboard. Every policy enforced consistently across every machine. Software installation locked down so nothing runs without authorization. Screens locked automatically. Passwords enforced by policy, not by hope. Every user account federated – one account, one removal, every door closes.

And when something goes wrong – when Tyler clicks the link, when the script tries to run, when the ransomware looks for its opening – it finds a wall it was not expecting. Not because anyone was watching. Because the architecture was built to stop it before anyone had to.

That is the grand slam. Not a dramatic intervention. Not a last-minute save. Just a system that was built right, running quietly in the background, protecting a business that never had to know it was under attack.

Your IT person has been asking for this. They are not wrong.

Kelly Hansen is the author of The IT Dilemma: Why Good Businesses Fail During Cyberattacks, Outages, and Technology Disasters – and How to Prevent It. Have a question about your own environment? Reach out: Contact, or connect with me on LinkedIn.

Key Takeaways

  • Every setting every option every configuration on every computer in your building can be controlled from one authoritative location
  • Tyler never knew anything happened — the ransomware never executed because software installation required admin credentials Tyler did not have
  • Users have local administrator access because it was easier and nobody thought through what that meant
  • The IT person in your building already knows you need this — they have probably already asked
  • The grand slam is not a dramatic intervention — it is a system built right running quietly protecting a business that never had to know it was under attack