{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/require-rpc-packet-privacy-ad-cs-enrollment-esc11/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/require-rpc-packet-privacy-ad-cs-enrollment-esc11/",
        "slug": "require-rpc-packet-privacy-ad-cs-enrollment-esc11",
        "url": "https://update.dsesecurity.com/updates/require-rpc-packet-privacy-ad-cs-enrollment-esc11/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/require-rpc-packet-privacy-ad-cs-enrollment-esc11.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/require-rpc-packet-privacy-ad-cs-enrollment-esc11/"
        },
        "title": "Require RPC packet privacy on AD CS enrollment interfaces flagged as ESC11",
        "summary": "Use Certificates security posture assessment in Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.",
        "format": {
            "slug": "briefing",
            "name": "Briefing"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-27T12:13:05+00:00",
        "modified_at": "2026-08-27T13:04:09+00:00",
        "reviewed_on": "2026-08-26",
        "reading_minutes": 3,
        "word_count": 643,
        "potentially_affected": "Teams, systems, services, or facilities within the stated scope of Certificates security posture assessment in Microsoft Defender for Identity",
        "dse_recommendation": "Compare the observed state with the cited official source, document applicability and exceptions, and test any approved change with rollback safeguards.",
        "primary_source": {
            "name": "Certificates security posture assessment in Microsoft Defender for Identity",
            "url": "https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/certificates",
            "published_on": "2026-07-02",
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p>Use this document to resolve one bounded operational decision: Require RPC packet privacy on AD CS enrollment interfaces flagged as ESC11. Only the official source and traced locations below supply facts. Confirm applicability before acting.</p>\n<h2>Source fact:</h2>\n<p>The official <a href=\"https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/certificates\" target=\"_blank\" rel=\"noopener noreferrer\">Certificates security posture assessment in Microsoft Defender for Identity</a> from Microsoft supports the following bounded statements:</p>\n<ul>\n<li>AD CS certificate enrollment can use the MS-ICPR RPC interface, whose certification-authority settings determine whether packet privacy is required. The research record locates this support at <strong>Enforce encryption for RPC certificate enrollment interface (ESC11) &gt; Description</strong>.</li>\n<li>With IF_ENFORCEENCRYPTICERTREQUEST enabled, the interface accepts RPC_C_AUTHN_LEVEL_PKT_PRIVACY and signs and encrypts each packet; without packet privacy, the enrollment interface is vulnerable to ESC11 relay attacks. The research record locates this support at <strong>Enforce encryption for RPC certificate enrollment interface (ESC11) &gt; Description</strong>.</li>\n<li>The ESC11 assessment is available only when a Defender for Identity sensor is installed on the AD CS server. The research record locates this support at <strong>Enforce encryption for RPC certificate enrollment interface (ESC11) &gt; Note</strong>.</li>\n</ul>\n<p>These statements are the factual basis for this document. Do not extend them into a broader assurance. Review directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking only where the source and recorded environment align.</p>\n<h2>What the source does not establish</h2>\n<p>Microsoft notes that the flag is sometimes disabled for legacy clients; research the exception and test compatibility in a controlled environment before production enforcement. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners before translating the source into an operational decision.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>For source statement 1 at <strong>Enforce encryption for RPC certificate enrollment interface (ESC11) &gt; Description</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>For source statement 2 at <strong>Enforce encryption for RPC certificate enrollment interface (ESC11) &gt; Description</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>For source statement 3 at <strong>Enforce encryption for RPC certificate enrollment interface (ESC11) &gt; Note</strong>, which observable configuration, record, or test can confirm applicability here?</li>\n<li>Which deployed instance of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking will be compared with the source, and why that instance?</li>\n<li>How will the review distinguish a source mismatch from a failure in Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners?</li>\n<li>Who approves the conclusion, exception, test window, and rollback threshold?</li>\n</ul>\n<h2>DSE recommendation:</h2>\n<p>DSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking, observed and expected states, owner, and reason for deviation.</p>\n<p>Translate the conclusion into change control only after documenting dependencies, impact, test method, expected signals, failure signals, and restoration steps. Include Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners, while excluding secrets and sensitive personal or topology data from ordinary tickets.</p>\n<h2>Verification and evidence</h2>\n<p>Keep the source locations <strong>Enforce encryption for RPC certificate enrollment interface (ESC11) &gt; Description</strong>; <strong>Enforce encryption for RPC certificate enrollment interface (ESC11) &gt; Description</strong>; <strong>Enforce encryption for RPC certificate enrollment interface (ESC11) &gt; Note</strong> adjacent to the sanitized artifacts used for comparison. Prefer affected-entity lists, directory attributes, relationship paths, assessment timestamps, remediation tests, and accepted exceptions, with enough identity and timing data for an independent recheck.</p>\n<p>Record the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/certificates\" target=\"_blank\" rel=\"noopener noreferrer\">Certificates security posture assessment in Microsoft Defender for Identity</a> — Microsoft</li>\n</ul>",
        "content_text": "Use this document to resolve one bounded operational decision: Require RPC packet privacy on AD CS enrollment interfaces flagged as ESC11. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Certificates security posture assessment in Microsoft Defender for Identity from Microsoft supports the following bounded statements:\n\nAD CS certificate enrollment can use the MS-ICPR RPC interface, whose certification-authority settings determine whether packet privacy is required. The research record locates this support at Enforce encryption for RPC certificate enrollment interface (ESC11) > Description.\nWith IF_ENFORCEENCRYPTICERTREQUEST enabled, the interface accepts RPC_C_AUTHN_LEVEL_PKT_PRIVACY and signs and encrypts each packet; without packet privacy, the enrollment interface is vulnerable to ESC11 relay attacks. The research record locates this support at Enforce encryption for RPC certificate enrollment interface (ESC11) > Description.\nThe ESC11 assessment is available only when a Defender for Identity sensor is installed on the AD CS server. The research record locates this support at Enforce encryption for RPC certificate enrollment interface (ESC11) > Note.\n\nThese statements are the factual basis for this document. Do not extend them into a broader assurance. Review directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking only where the source and recorded environment align.\nWhat the source does not establish\nMicrosoft notes that the flag is sometimes disabled for legacy clients; research the exception and test compatibility in a controlled environment before production enforcement. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners before translating the source into an operational decision.\nApplicability questions\n\nFor source statement 1 at Enforce encryption for RPC certificate enrollment interface (ESC11) > Description, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Enforce encryption for RPC certificate enrollment interface (ESC11) > Description, which observable configuration, record, or test can confirm applicability here?\nFor source statement 3 at Enforce encryption for RPC certificate enrollment interface (ESC11) > Note, which observable configuration, record, or test can confirm applicability here?\nWhich deployed instance of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking will be compared with the source, and why that instance?\nHow will the review distinguish a source mismatch from a failure in Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners?\nWho approves the conclusion, exception, test window, and rollback threshold?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking, observed and expected states, owner, and reason for deviation.\nTranslate the conclusion into change control only after documenting dependencies, impact, test method, expected signals, failure signals, and restoration steps. Include Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners, while excluding secrets and sensitive personal or topology data from ordinary tickets.\nVerification and evidence\nKeep the source locations Enforce encryption for RPC certificate enrollment interface (ESC11) > Description; Enforce encryption for RPC certificate enrollment interface (ESC11) > Description; Enforce encryption for RPC certificate enrollment interface (ESC11) > Note adjacent to the sanitized artifacts used for comparison. Prefer affected-entity lists, directory attributes, relationship paths, assessment timestamps, remediation tests, and accepted exceptions, with enough identity and timing data for an independent recheck.\nRecord the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.\nOfficial references\n\nCertificates security posture assessment in Microsoft Defender for Identity — Microsoft",
        "content_markdown": "Use this document to resolve one bounded operational decision: Require RPC packet privacy on AD CS enrollment interfaces flagged as ESC11. Only the official source and traced locations below supply facts. Confirm applicability before acting.\n\n## Source fact:\n\nThe official [Certificates security posture assessment in Microsoft Defender for Identity](https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/certificates) from Microsoft supports the following bounded statements:\n\n- AD CS certificate enrollment can use the MS-ICPR RPC interface, whose certification-authority settings determine whether packet privacy is required. The research record locates this support at Enforce encryption for RPC certificate enrollment interface (ESC11) > Description.\n\n- With IF_ENFORCEENCRYPTICERTREQUEST enabled, the interface accepts RPC_C_AUTHN_LEVEL_PKT_PRIVACY and signs and encrypts each packet; without packet privacy, the enrollment interface is vulnerable to ESC11 relay attacks. The research record locates this support at Enforce encryption for RPC certificate enrollment interface (ESC11) > Description.\n\n- The ESC11 assessment is available only when a Defender for Identity sensor is installed on the AD CS server. The research record locates this support at Enforce encryption for RPC certificate enrollment interface (ESC11) > Note.\n\nThese statements are the factual basis for this document. Do not extend them into a broader assurance. Review directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking only where the source and recorded environment align.\n\n## What the source does not establish\n\nMicrosoft notes that the flag is sometimes disabled for legacy clients; research the exception and test compatibility in a controlled environment before production enforcement. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners before translating the source into an operational decision.\n\n## Applicability questions\n\n- For source statement 1 at Enforce encryption for RPC certificate enrollment interface (ESC11) > Description, which observable configuration, record, or test can confirm applicability here?\n\n- For source statement 2 at Enforce encryption for RPC certificate enrollment interface (ESC11) > Description, which observable configuration, record, or test can confirm applicability here?\n\n- For source statement 3 at Enforce encryption for RPC certificate enrollment interface (ESC11) > Note, which observable configuration, record, or test can confirm applicability here?\n\n- Which deployed instance of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking will be compared with the source, and why that instance?\n\n- How will the review distinguish a source mismatch from a failure in Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners?\n\n- Who approves the conclusion, exception, test window, and rollback threshold?\n\n## DSE recommendation:\n\nDSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking, observed and expected states, owner, and reason for deviation.\n\nTranslate the conclusion into change control only after documenting dependencies, impact, test method, expected signals, failure signals, and restoration steps. Include Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners, while excluding secrets and sensitive personal or topology data from ordinary tickets.\n\n## Verification and evidence\n\nKeep the source locations Enforce encryption for RPC certificate enrollment interface (ESC11) > Description; Enforce encryption for RPC certificate enrollment interface (ESC11) > Description; Enforce encryption for RPC certificate enrollment interface (ESC11) > Note adjacent to the sanitized artifacts used for comparison. Prefer affected-entity lists, directory attributes, relationship paths, assessment timestamps, remediation tests, and accepted exceptions, with enough identity and timing data for an independent recheck.\n\nRecord the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.\n\n## Official references\n\n- [Certificates security posture assessment in Microsoft Defender for Identity](https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/certificates) — Microsoft"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/require-rpc-packet-privacy-ad-cs-enrollment-esc11/",
                "url": "https://update.dsesecurity.com/updates/require-rpc-packet-privacy-ad-cs-enrollment-esc11/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-26"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/require-rpc-packet-privacy-ad-cs-enrollment-esc11/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Require RPC packet privacy on AD CS enrollment interfaces flagged as ESC11",
                        "item": "https://update.dsesecurity.com/updates/require-rpc-packet-privacy-ad-cs-enrollment-esc11/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/require-rpc-packet-privacy-ad-cs-enrollment-esc11/#article",
                "identifier": "https://update.dsesecurity.com/updates/require-rpc-packet-privacy-ad-cs-enrollment-esc11/",
                "url": "https://update.dsesecurity.com/updates/require-rpc-packet-privacy-ad-cs-enrollment-esc11/",
                "headline": "Require RPC packet privacy on AD CS enrollment interfaces flagged as ESC11",
                "description": "Use Certificates security posture assessment in Microsoft Defender for Identity to review this narrow operational decision without extending the source…",
                "abstract": "Use Certificates security posture assessment in Microsoft Defender for Identity to review this narrow operational decision without extending the source beyond its stated scope.",
                "articleBody": "Use this document to resolve one bounded operational decision: Require RPC packet privacy on AD CS enrollment interfaces flagged as ESC11. Only the official source and traced locations below supply facts. Confirm applicability before acting.\nSource fact:\nThe official Certificates security posture assessment in Microsoft Defender for Identity from Microsoft supports the following bounded statements:\n\nAD CS certificate enrollment can use the MS-ICPR RPC interface, whose certification-authority settings determine whether packet privacy is required. The research record locates this support at Enforce encryption for RPC certificate enrollment interface (ESC11) > Description.\nWith IF_ENFORCEENCRYPTICERTREQUEST enabled, the interface accepts RPC_C_AUTHN_LEVEL_PKT_PRIVACY and signs and encrypts each packet; without packet privacy, the enrollment interface is vulnerable to ESC11 relay attacks. The research record locates this support at Enforce encryption for RPC certificate enrollment interface (ESC11) > Description.\nThe ESC11 assessment is available only when a Defender for Identity sensor is installed on the AD CS server. The research record locates this support at Enforce encryption for RPC certificate enrollment interface (ESC11) > Note.\n\nThese statements are the factual basis for this document. Do not extend them into a broader assurance. Review directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking only where the source and recorded environment align.\nWhat the source does not establish\nMicrosoft notes that the flag is sometimes disabled for legacy clients; research the exception and test compatibility in a controlled environment before production enforcement. The citation is not a substitute for observed state, authorization, compliance evidence, or dependency health. Examine Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners before translating the source into an operational decision.\nApplicability questions\n\nFor source statement 1 at Enforce encryption for RPC certificate enrollment interface (ESC11) > Description, which observable configuration, record, or test can confirm applicability here?\nFor source statement 2 at Enforce encryption for RPC certificate enrollment interface (ESC11) > Description, which observable configuration, record, or test can confirm applicability here?\nFor source statement 3 at Enforce encryption for RPC certificate enrollment interface (ESC11) > Note, which observable configuration, record, or test can confirm applicability here?\nWhich deployed instance of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking will be compared with the source, and why that instance?\nHow will the review distinguish a source mismatch from a failure in Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners?\nWho approves the conclusion, exception, test window, and rollback threshold?\n\nDSE recommendation:\nDSE recommends using the cited source as the evidence anchor for this decision. Start with applicability, then compare the observed state with the cited source. Record the source location, examined part of directory identities, posture assessments, exposed relationships, recommendations, ownership, remediation, and exception tracking, observed and expected states, owner, and reason for deviation.\nTranslate the conclusion into change control only after documenting dependencies, impact, test method, expected signals, failure signals, and restoration steps. Include Active Directory data quality, Windows DNS, sensor coverage, time, synchronization, cloud processing, and accountable identity owners, while excluding secrets and sensitive personal or topology data from ordinary tickets.\nVerification and evidence\nKeep the source locations Enforce encryption for RPC certificate enrollment interface (ESC11) > Description; Enforce encryption for RPC certificate enrollment interface (ESC11) > Description; Enforce encryption for RPC certificate enrollment interface (ESC11) > Note adjacent to the sanitized artifacts used for comparison. Prefer affected-entity lists, directory attributes, relationship paths, assessment timestamps, remediation tests, and accepted exceptions, with enough identity and timing data for an independent recheck.\nRecord the decision even when no change is made, including uncertainty and the next trigger. Use safe testing conditions for disruptive work, preserve rollback proof, and revisit the conclusion after relevant platform, dependency, vendor, or ownership changes.\nOfficial references\n\nCertificates security posture assessment in Microsoft Defender for Identity — Microsoft",
                "datePublished": "2026-08-27T12:13:05+00:00",
                "dateModified": "2026-08-27T13:04:09+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/require-rpc-packet-privacy-ad-cs-enrollment-esc11/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/require-rpc-packet-privacy-ad-cs-enrollment-esc11/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Require RPC packet privacy on AD CS enrollment interfaces flagged as ESC11"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Briefing",
                    "Advisory priority"
                ],
                "genre": "Briefing",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 643,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Certificates security posture assessment in Microsoft Defender for Identity",
                    "url": "https://learn.microsoft.com/en-us/defender-for-identity/security-posture-assessments/certificates",
                    "datePublished": "2026-07-02"
                }
            }
        ]
    }
}