Almost every enterprise intrusion of any size runs through identity at some point, and in a Windows shop that means Active Directory and its cloud extension, Entra ID. The posts here work through the attack paths that matter in practice, Kerberos ticket abuse, delegation, DCSync and Golden SAML, OAuth consent phishing, and pair each with the detection logic and hardening that actually closes it rather than a generic checklist. They assume you run this environment and need to defend it on Monday.