{"id":3185,"date":"2026-08-07T23:38:11","date_gmt":"2026-08-07T20:38:11","guid":{"rendered":"https:\/\/www.jussimetso.com\/?p=3185"},"modified":"2026-08-07T23:38:13","modified_gmt":"2026-08-07T20:38:13","slug":"red-forest-the-predecessor-of-eam","status":"publish","type":"post","link":"https:\/\/www.jussimetso.com\/index.php\/2026\/08\/07\/red-forest-the-predecessor-of-eam\/","title":{"rendered":"Red Forest: The predecessor of EAM"},"content":{"rendered":"<div id=\"bsf_rt_marker\"><\/div>\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"3185\" class=\"elementor elementor-3185\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6b356d2 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"6b356d2\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-bba9bd9\" data-id=\"bba9bd9\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-cf4ea30 elementor-widget elementor-widget-text-editor\" data-id=\"cf4ea30\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The second part of my red tenant study comes now.\u00a0<\/p><p>In my <a href=\"https:\/\/www.jussimetso.com\/index.php\/2026\/03\/31\/red-tenant-intro\/\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">first part<\/span><\/a>, kind of mockup intro to the Red Tenant concept introduced some core ideas in title level what are included in the model.<\/p><p>In practice, a \u201cRed Tenant\u201d usually means an <strong data-start=\"754\" data-end=\"786\">isolated admin control plane<\/strong>. The common components are: a dedicated Entra tenant for admin identities, separate admin accounts from normal user accounts, hardened admin devices\/PAWs, strict Conditional Access, just-in-time role activation through Microsoft Entra PIM, monitoring\/auditing for privileged actions, and controlled ways to manage production tenants or on-prem AD without letting compromise in the normal estate spread into the admin estate. That matches both the public vendor (which is glueckkanja ) descriptions and Microsoft\u2019s privileged-access guidance.<\/p><p>Before going in the modern way to do it let&#8217;s look at the history where it began.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f0ab8bd elementor-widget elementor-widget-heading\" data-id=\"f0ab8bd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The predecessor of them all - the ESAE<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-38e94bb elementor-widget elementor-widget-text-editor\" data-id=\"38e94bb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div data-olk-copy-source=\"MessageBody\">ESAE,\u00a0 the <a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/esae-retirement\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\"><b>Enhanced Security Administrative Environment<\/b><\/span><\/a>, universally nicknamed the &#8220;<strong>Red Forest<\/strong>&#8221;\u00a0 was Microsoft&#8217;s reference architecture from roughly the mid-2010s for protecting the most powerful credentials in an Active Directory environment.<\/div><div data-olk-copy-source=\"MessageBody\">\u00a0<\/div><div data-olk-copy-source=\"MessageBody\">It&#8217;s the direct ancestor of the tiering and isolated-admin ideas from the earlier background, so it&#8217;s worth understanding what it actually did.\u00a0 The core insight behind it is that in Active Directory, the\u00a0<strong><i>forest<\/i> <\/strong>not the domain is the real security boundary.<\/div><div>\u00a0<\/div><div>A compromised domain can be used to pivot to other domains in the same forest, but crossing a forest boundary is much harder. ESAE exploited this by standing up a <b>dedicated administrative forest<\/b>, separate from the production forest where users, servers, and workloads lived. That admin forest was where the <strong>Tier 0<\/strong> privileged accounts and the workstations used to administer production actually resided. It was deliberately tiny and hardened: very few accounts, no email, no internet browsing, strict baselines, minimal attack surface.<\/div><div>\u00a0<\/div><div>The two forests were connected by a\u00a0<b>one-way trust<\/b>: production trusted the admin forest, but the admin forest did\u00a0<strong><i>not<\/i>\u00a0<\/strong>trust production. This is the whole point. Even if an attacker fully owned the production forest, they still couldn&#8217;t reach into the red forest to steal the admin credentials that governed everything, the trust simply didn&#8217;t flow that direction. The admin forest was often paired with Microsoft Identity Manager&#8217;s PAM feature to provide time-bound, just-in-time membership in privileged groups, so even within the red forest, standing privilege was limited. It sat alongside the tier model and Privileged Access Workstations as a package.<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e6360b4 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"e6360b4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3f7c228 elementor-widget elementor-widget-heading\" data-id=\"3f7c228\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The reasons for the retirement<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0126132 elementor-widget elementor-widget-image\" data-id=\"0126132\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_the_legacy_red_forest.png?ssl=1\" data-elementor-open-lightbox=\"yes\" data-elementor-lightbox-title=\"The legacy Red Forest ESAEedt_the_legacy_red_forest\" data-e-action-hash=\"#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6MzE5MSwidXJsIjoiaHR0cHM6XC9cL3d3dy5qdXNzaW1ldHNvLmNvbVwvd3AtY29udGVudFwvdXBsb2Fkc1wvMjAyNlwvMDhcL3JlZHRfdGhlX2xlZ2FjeV9yZWRfZm9yZXN0LnBuZyJ9\">\n\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"640\" height=\"427\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_the_legacy_red_forest.png?fit=640%2C427&amp;ssl=1\" class=\"attachment-large size-large wp-image-3191\" alt=\"The legacy Red Forest ESAE\" srcset=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_the_legacy_red_forest.png?w=1536&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_the_legacy_red_forest.png?resize=300%2C200&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_the_legacy_red_forest.png?resize=1024%2C683&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_the_legacy_red_forest.png?resize=768%2C512&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_the_legacy_red_forest.png?resize=850%2C567&amp;ssl=1 850w, https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_the_legacy_red_forest.png?w=1280&amp;ssl=1 1280w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\">Copyright Jussi Metso - a two forest environment<\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5e94010 elementor-widget elementor-widget-text-editor\" data-id=\"5e94010\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div data-olk-copy-source=\"MessageBody\">Microsoft\u00a0retired the ESAE guidance around 2020\u20132021, and the reasons are instructive because they explain why the modern models look the way they do.<\/div><div data-olk-copy-source=\"MessageBody\">\u00a0<\/div><div>First, it was expensive and complex. Standing up and maintaining an entire second forest, the trust, MIM (Microsoft Identity Manager), and the operational discipline around it was a heavy lift, and many organizations deployed it partially or misconfigured it,\u00a0 which produced a false sense of security rather than real protection. It had a tendency to become a checkbox that let teams neglect broader hygiene like patching, attack-surface reduction, and privileged access management everywhere else.<\/div><div>\u00a0<\/div><div>Second, and more fundamentally, the world moved to hybrid and cloud. ESAE was intensely AD-centric, built for a time when on-prem Active Directory was the center of gravity. Once Entra ID, SaaS, and cloud workloads became business-critical, isolating just the on-prem AD admin forest was solving yesterday&#8217;s problem while leaving the cloud identity attack surface unaddressed. A hardened red forest does nothing for a compromised cloud admin.<\/div><div>\u00a0<\/div><div>Microsoft replaced it with the modern\u00a0<b>Enterprise Access Model<\/b> (<strong>EAM<\/strong>) and a rapid modernization plan for privileged access, built on Zero Trust principles: just-in-time privilege through Entra PIM, hardened PAWs, and Conditional Access gating everything on device and risk signals,\u00a0 securing identity holistically across cloud and on-prem rather than walling off one forest.<\/div><div>\u00a0<\/div><div>ESAE wasn&#8217;t declared wrong, exactly; it was narrowed to a very small set of genuinely isolated on-prem scenarios (think air-gapped OT environments) and dropped as general guidance for everyone else.<\/div><div>\u00a0<\/div><div>So the through-line is: the red forest&#8217;s containment instinct was correct and survives in EAM and isolated admin tenants, but the mechanism, a separate on-prem forest with a one-way trust, was too costly, too easily botched, and too on-prem bound for a cloud world. The newer models keep the principle and swap the machinery.<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-de3fcf1 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"de3fcf1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-15462a8 elementor-widget elementor-widget-heading\" data-id=\"15462a8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">If you still have ESAE - Guidance for existing deployments<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c201198 elementor-widget elementor-widget-text-editor\" data-id=\"c201198\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The next chapters are quotes from <a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/esae-retirement\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">Microsoft Learn<\/span><\/a>:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-60811b8 elementor-blockquote--skin-border elementor-widget elementor-widget-blockquote\" data-id=\"60811b8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"blockquote.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<blockquote class=\"elementor-blockquote\">\n\t\t\t<p class=\"elementor-blockquote__content\">\n\t\t\t\tthere's no urgency to retire or replace an ESAE implementation if it's being operated as designed and intended. As with any enterprise systems, you should maintain the software in it by applying security updates and ensuring software is within support lifecycle.\t\t\t<\/p>\n\t\t\t\t\t<\/blockquote>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-407ecc0 elementor-blockquote--skin-border elementor-widget elementor-widget-blockquote\" data-id=\"407ecc0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"blockquote.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<blockquote class=\"elementor-blockquote\">\n\t\t\t<p class=\"elementor-blockquote__content\">\n\t\t\t\tadopt the modern privileged access strategy using the rapid modernization plan (RAMP) guidance. This guidance complements an existing ESAE implementation and provides appropriate security for roles not already protected by ESAE including Microsoft Entra administrators, sensitive business users, and standard enterprise users.\t\t\t<\/p>\n\t\t\t\t\t<\/blockquote>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7cd5910 elementor-widget elementor-widget-heading\" data-id=\"7cd5910\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Links to consider<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ba012bd elementor-widget elementor-widget-text-editor\" data-id=\"ba012bd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p id=\"guidance-for-existing-deployments\" class=\"heading-anchor\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/esae-retirement#guidance-for-existing-deployments\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">Guidance for Existing Deployments<\/span><\/a><\/p><p id=\"best-practice-for-securing-on-premises-ad\" class=\"heading-anchor\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/esae-retirement#best-practice-for-securing-on-premises-ad\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">Best Practice for Securing on-premises AD<\/span><\/a><\/p><p><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/privileged-access-security-levels\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">Privileged Access Strategy<\/span><\/a><\/p><p><a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/privileged-access-workstations\/security-rapid-modernization-plan\" target=\"_blank\" rel=\"noopener\"><span style=\"text-decoration: underline;\">Rapid modernization plan (RAMP)<\/span><\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-671449c elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"671449c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cf9e45c elementor-widget elementor-widget-text-editor\" data-id=\"cf9e45c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>This was the history part. The next one is the modern part. At least part number one. The EAM model, some explanations of MIM PAM (Privileged Access Management) vs Entra ID PIM (Privileged Identity Management). Also where I started the &#8220;Red tenant&#8221; reference architecture at least in short.<\/p><p>There&#8217;s so much stuff around these so I&#8217;ll try to be strict and not spread the idea too much. Let&#8217;s see how I can manage this.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-72dc543 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"72dc543\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1f5bdb07 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1f5bdb07\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4bdc676b\" data-id=\"4bdc676b\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a27e5ee elementor-widget elementor-widget-author-box\" data-id=\"a27e5ee\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"author-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-author-box\">\n\t\t\t\t\t\t\t<div  class=\"elementor-author-box__avatar\">\n\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2024\/07\/jussi_06_2024.jpg?fit=262%2C300&#038;ssl=1\" alt=\"Picture of Jussi Metso\" loading=\"lazy\">\n\t\t\t\t<\/div>\n\t\t\t\n\t\t\t<div class=\"elementor-author-box__text\">\n\t\t\t\t\t\t\t\t\t<div >\n\t\t\t\t\t\t<h6 class=\"elementor-author-box__name\">\n\t\t\t\t\t\t\tJussi Metso\t\t\t\t\t\t<\/h6>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-author-box__bio\">\n\t\t\t\t\t\t<p>Author is a lifelong IT enthusiast, Microsoft Security MVP and interested in Cloud Security, XDR, SIEM and AI. Motto: Learning is the key for your future. <\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p> In the on-premises Active Directory world, Microsoft used to recommend the Enhanced Security Administrative Environment \u2014 a dedicated, hardened AD forest used only for administering your production forest<\/p>\n","protected":false},"author":1,"featured_media":3201,"comment_status":"open","ping_status":"open","sticky":false,"template":"elementor_theme","format":"standard","meta":{"advanced_seo_description":"ESAE - The Enhanced Security Administrative Environment","jetpack_seo_html_title":"A concept of Red Forest","jetpack_seo_noindex":false,"jetpack_seo_schema_type":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[71],"tags":[68,69,70],"class_list":["post-3185","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-red","tag-activedirectory","tag-redforest","tag-redtenant"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.jussimetso.com\/wp-content\/uploads\/2026\/08\/redt_redforest_blogtitle.png?fit=736%2C444&ssl=1","jetpack_shortlink":"https:\/\/wp.me\/pes24X-Pn","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3185","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/comments?post=3185"}],"version-history":[{"count":14,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3185\/revisions"}],"predecessor-version":[{"id":3202,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/posts\/3185\/revisions\/3202"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/media\/3201"}],"wp:attachment":[{"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/media?parent=3185"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/categories?post=3185"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jussimetso.com\/index.php\/wp-json\/wp\/v2\/tags?post=3185"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}