CONCLUSION

Add software to AD, even if it's for backup:

  • increases the attack surface and requires additional monitoring (updating the agent for example),

  • often requires a service account which is often with a password that never expires and domain administrator

Although third-party backup software saves time, it is quite possible to do without if the budget is limited. it's better to put the money in protection software (antivirus, EDR, etc.) or off-site/off-line remote storage (export to tapes).

Last updated