Publish Evidence, Keep Administration Private
Context
ABD Labs needs a public portfolio, but the Microsoft Enterprise Lab will contain administration paths and intentionally broken configurations during learning and incident scenarios.
Decision
Publish sanitized architecture notes, case studies, diagrams and command evidence. Keep RDP, SMB, LDAP, Kerberos, DNS, WinRM, Windows Admin Center and hypervisor consoles private by default.
Alternatives Considered
Expose lab services directly with public DNS
Pros
- Simplifies initial access.
- Makes demos easy to reach.
Cons
- Creates avoidable attack surface.
- Confuses portfolio publishing with administration access.
- Violates the lab security guardrails.
Publish nothing until the lab is complete
Pros
- Very low disclosure risk.
Cons
- No public evidence trail.
- Harder to show progress and decision quality.
Publish sanitized evidence only
Pros
- Shows real work while preserving private operations.
- Lets case studies grow as the lab matures.
Cons
- Requires careful review before publishing screenshots or outputs.
Reasoning
The portfolio should prove work without becoming an access path. This keeps public credibility and private safety aligned.
Future public names such as vpn.abdlabs.org should only be considered after a separate access-broker or VPN design. Direct lab management services remain private by default.