

Inside Active Directory's Origin Story: Aaron Turner on Microsoft's "Kill Novell" Mission
In episode one of this two-part series of Identity Decoded, hosts Roy Akerman and Rob Ainscough sit down with Aaron Turner, who spent eight years at Microsoft during the founding of Active Directory — starting as a support engineer and later working on Active Directory, SQL Server, Windows Mobile, and Xbox Live. Aaron takes listeners back to the mid-'90s mindset that shaped Active Directory's design: a mission to "kill Novell" and sell more Windows and Office licenses, not to build a security boundary. The conversation traces how that original trade-off — deployment speed over security — led to decades of "identity debt," why LSASS (designed in 1998) has become a favorite target in modern ransomware-as-a-service kill chains, and what the NSA's declassified account of removing Russian actors from the US Treasury reveals about identity segmentation done right (and wrong). 🎧 Episode Highlights [00:02:00] Aaron's origin story: getting into computers after watching WarGames, early penetration testing, and landing a bilingual, Novell-experienced role at Microsoft. [00:04:00] The Venezuela story: building a countrywide identity platform on NT4, and how that trip led to Bill Gates personally awarding Aaron a "gold star" in 1999. [00:07:00] Why Active Directory's original mission statement was to "steal Novell's lunch money," not build a product with security in mind from the start — and the resulting tension between deployment speed and security. [00:11:00] The mismatch at the heart of Active Directory: enterprise-grade authentication, handed to teams without enterprise-grade security operations. [00:15:00] The economics of identity debt: roughly $250 billion spent on firewalls since 1999, versus an estimated 2% of that on identity. [00:18:48] The LSASS problem — why a process designed in 1998 to run for a week at most now caches years of credentials, and how that fuels modern ransomware-as-a-service kill chains. [00:22:20] Aaron's practical playbook: turn on success logging, visualize authentication traffic with tools like Gravwell, and eliminate legacy protocol dependencies (like clear-text LDAP) one server at a time. [00:24:25] The NSA's declassified account of removing Russian actors from the US Treasury — how attackers moved across five separate identity planes (on-prem AD, AD FS, Entra, Okta, Duo) to stay hidden, and why simplifying your identity stack matters more than adding another layer. 🔑 Key Takeaways: Takeaway 1: Active Directory was never designed as a security boundary — it was built to sell more Windows and Office licenses, and decades of security assumptions have been built on top of an infrastructure tool, not a security system. Takeaway 2: The industry's massive underinvestment in identity relative to firewalls (an estimated $250B vs. ~2% of that on identity) has created a structural "identity debt" that most enterprises can't simply modernize their way out of — many will have to invest in shoring up legacy infrastructure rather than fully replacing it. Takeaway 3: Adding more identity providers doesn't reduce risk if it adds more places for attackers to hide — as seen in the NSA's Treasury case study, simplifying and consolidating your identity stack is often more effective than layering on additional cloud identity tools. 👤 Guest Spotlight Aaron Turner, IANS Faculty Aaron Turner has spent over 30 years in the security industry, starting as an early penetration tester in the 1990s before joining Microsoft, where he spent eight years working across Active Directory, SQL Server, Windows Mobile, and Xbox Live. Early in his Microsoft career, he helped rebuild a national identity platform for Venezuela on NT4 — a project that led Bill Gates to personally recognize him with a "gold star" award in 1999, one of the company's most selective honors at the time. That recognition gave Aaron the freedom to work across some of Microsoft's most foundational identity and security projects during the internet's early enterprise era. He has since founded his own company and continues to research and speak on Identity Security, attacker tradecraft, and the long-term consequences of decisions made in Active Directory's earliest design days. Stay connected https://www.silverfort.com https://www.linkedin.com/in/aaronrturner https://www.linkedin.com/in/rob-ainscough https://www.linkedin.com/in/roy-akerman






