Skip to content

Domains · Domain Controllers · Forests

Harden Active Directory, from the root.

A practical map of Active Directory hardening for identity, Kerberos and domain controllers. Every control comes with the Group Policy path, the attribute or registry value, the PowerShell to verify it and the things it will break.

areas
12
guides
12
glossary terms
14
Target state · Tier 0 domain controller
  • Kerberos encenforced
  • krbtgtenforced
  • LDAPenforced
  • SMB signingenforced
  • Print Spoolerenforced
  • Delegationenforced
  • Protected Usersenforced
  • AD CSenforced
  • Restrict NTLMin audit
8/9 controls enforced89%
Illustrative target configuration

The map

Twelve areas, from Tier 0 to recovery

Each area groups the controls that defend against the same class of attack. Start anywhere, but the first three areas stop most real-world domain compromises.

  1. 01Tier 0 & Privileged AccessA small, protected Tier 0, admin tiering and privileged access workstations.Admin tieringPAWProtected UsersIdentityDC1 guide
  2. 02Kerberos & AuthenticationAES-only tickets, krbtgt rotation, pre-authentication and Kerberos armoring.AES onlykrbtgt rotationArmoring (FAST)IdentityDC1 guide
  3. 03DelegationRemove unconstrained delegation, scope constrained/RBCD and protect Tier 0.No unconstrainedRBCDSensitive accountsIdentityDC1 guide
  4. 04NTLM & Legacy ProtocolsSign and bind LDAP, require SMB signing, and audit then restrict NTLM.LDAP signing + EPASMB signingRestrict NTLMIdentityDC1 guide
  5. 05AD Certificate ServicesFix vulnerable templates and CA settings (ESC1–ESC8) that grant domain admin.ESC1–ESC8Manager approvalEPA on CA webIdentity1 guide
  6. 06Group Policy & SYSVOLLock down GPO delegation, purge Group Policy Preference passwords, fix SYSVOL ACLs.GPO delegationNo GPP passwordsSYSVOL ACLsDCIdentity1 guide
  7. 07Domain Controller HardeningBaseline DCs, disable the Print Spooler, restrict logon and patch the DC-killers.DC baselineSpooler offRDP restrictionsDC1 guide
  8. 08Object & ACL SecurityFind dangerous ACLs, DCSync rights and AdminSDHolder drift across the directory.DCSync rightsAdminSDHolderACL reviewIdentityDC1 guide
  9. 09Passwords & Service AccountsGroup managed service accounts, fine-grained policies, banned passwords and LAPS.gMSAFine-grained policyLAPSIdentity1 guide
  10. 10Trusts & Forest DesignSID filtering, selective authentication and the forest as a security boundary.SID filteringSelective authTier 0 isolationForest1 guide
  11. 11Auditing, Logging & DetectionAdvanced audit policy on DCs, object SACLs, key event IDs and Defender for Identity.Advanced audit policySACLsDefender for IdentityDCIdentity1 guide
  12. 12Assessment, Backup & RecoveryScore the domain, keep offline DC backups and rehearse forest recovery.PingCastleForest recoveryCIS baselineForestDC1 guide

Method

Every change follows the same loop

Active Directory hardening fails when it breaks authentication and gets rolled back. Audit modes exist for LDAP signing, NTLM and more: use them before you enforce.

  1. 1Measure

    Read the current state with PowerShell, an assessment tool or Policy Analyzer before changing anything.

  2. 2Audit

    Turn on the control in audit mode and collect the authentications it would have blocked.

  3. 3Enforce

    Fix or exclude the real collisions, then enforce ring by ring with a rollback plan.

  4. 4Verify

    Re-check the setting and alert on drift, so the control stays on after the next change.

Guides

Latest guides

View all guides
12 · Assessment, Backup & Recovery

AD assessment, backup and forest recovery

Run recurring AD posture assessments against CIS and Microsoft baselines, protect Tier 0 backups, and rehearse forest recovery before you need it for real.

10 · Trusts & Forest Design

Hardening AD trusts and forest boundaries

Why the forest — not the domain — is the AD security boundary, and how to lock down trusts with SID filtering, quarantine, and selective authentication.