Skip to content

Harden Active Directory, from the root.

A practical map of Active Directory hardening for identity, Kerberos and domain controllers. Every control comes with the Group Policy path, the attribute or registry value, the PowerShell to verify it and the things it will break.

Target state · Tier 0 domain controller

89%

controls enforced

RC4 tickets

0

−100% / 30 d

NTLM auth

3.1k

in audit

  • Kerberos encryptionEnforced
  • krbtgtEnforced
  • LDAPEnforced
  • SMB signingEnforced
  • Print SpoolerEnforced
  • DelegationEnforced
  • Protected UsersEnforced
  • AD CSEnforced
  • Restrict NTLMin audit
Illustrative target configuration

Aligned with

  • Microsoft Security Baselines
  • CIS Benchmarks
  • ANSSI AD guidance
  • MITRE ATT&CK
  • NIST SP 800-63B
areas
12
guides
50
glossary terms
30
languages
4

Why it works

Written for the people who change production

Every guide is built the same way, so you can go from finding to enforced control without a second tab open.

Exact paths and values

The Group Policy path, the registry value and the attribute to set. No hand-waving, no "consider hardening".

PowerShell to verify

Read the current state before you change it and prove the change afterwards, with commands you can paste.

What it breaks

Every guide ends with the compatibility fallout, so the control is not rolled back at the first help-desk ticket.

Audit before enforce

Audit modes, event IDs and staged rings: the rollout that survives contact with legacy apps.

Ordered by impact

A map of twelve areas and a 90-day plan that puts the controls behind most real breaches first.

The map

Twelve areas, from Tier 0 to recovery

Each area groups the controls that defend against the same class of attack. Start anywhere, but the first three areas stop most real-world domain compromises.

  1. 01Tier 0 & Privileged AccessA small, protected Tier 0, admin tiering and privileged access workstations.Admin tieringPAWProtected UsersIdentityDC4 guides
  2. 02Kerberos & AuthenticationAES-only tickets, krbtgt rotation, pre-authentication and Kerberos armoring.AES onlykrbtgt rotationArmoring (FAST)IdentityDC4 guides
  3. 03DelegationRemove unconstrained delegation, scope constrained/RBCD and protect Tier 0.No unconstrainedRBCDSensitive accountsIdentityDC4 guides
  4. 04NTLM & Legacy ProtocolsSign and bind LDAP, require SMB signing, and audit then restrict NTLM.LDAP signing + EPASMB signingRestrict NTLMIdentityDC5 guides
  5. 05AD Certificate ServicesFix vulnerable templates and CA settings (ESC1–ESC8) that grant domain admin.ESC1–ESC8Manager approvalEPA on CA webIdentity4 guides
  6. 06Group Policy & SYSVOLLock down GPO delegation, purge Group Policy Preference passwords, fix SYSVOL ACLs.GPO delegationNo GPP passwordsSYSVOL ACLsDCIdentity4 guides
  7. 07Domain Controller HardeningBaseline DCs, disable the Print Spooler, restrict logon and patch the DC-killers.DC baselineSpooler offRDP restrictionsDC4 guides
  8. 08Object & ACL SecurityFind dangerous ACLs, DCSync rights and AdminSDHolder drift across the directory.DCSync rightsAdminSDHolderACL reviewIdentityDC4 guides
  9. 09Passwords & Service AccountsGroup managed service accounts, fine-grained policies, banned passwords and LAPS.gMSAFine-grained policyLAPSIdentity4 guides
  10. 10Trusts & Forest DesignSID filtering, selective authentication and the forest as a security boundary.SID filteringSelective authTier 0 isolationForest4 guides
  11. 11Auditing, Logging & DetectionAdvanced audit policy on DCs, object SACLs, key event IDs and Defender for Identity.Advanced audit policySACLsDefender for IdentityDCIdentity4 guides
  12. 12Assessment, Backup & RecoveryScore the domain, keep offline DC backups and rehearse forest recovery.PingCastleForest recoveryCIS baselineForestDC4 guides

Roadmap

A 90-day plan, in three phases

The order matters. Close the paths attackers actually use first, then fix the structure, then keep it that way.

Method

Every change follows the same loop

Active Directory hardening fails when it breaks authentication and gets rolled back. Audit modes exist for LDAP signing, NTLM and more: use them before you enforce.

  1. 01MeasureRead the current state with PowerShell, an assessment tool or Policy Analyzer before changing anything.
  2. 02AuditTurn on the control in audit mode and collect the authentications it would have blocked.
  3. 03EnforceFix or exclude the real collisions, then enforce ring by ring with a rollback plan.
  4. 04VerifyRe-check the setting and alert on drift, so the control stays on after the next change.

Guides

Latest guides

View all guides
NTLM & Legacy Protocols

Disable LLMNR, NBT-NS, mDNS and WPAD in AD

Remove the name-resolution fallbacks attackers poison: disable LLMNR, NetBIOS and mDNS by GPO and DHCP, and block WPAD with the DNS global query block list.

Foundation
Assessment, Backup & Recovery

Writing and rehearsing an AD forest recovery plan

Build an Active Directory forest recovery runbook from Microsoft's guide: clean room, first DC restore, SYSVOL, FSMO, RID pool, krbtgt resets and yearly drills.

Advanced
Group Policy & SYSVOL

Deploying Microsoft security baselines with GPO

Deploy Microsoft security baselines with Group Policy: SCT, Policy Analyzer gap analysis, LGPO testing, ring-based rollout, exceptions and drift checks.

Intermediate
Assessment, Backup & Recovery

Protecting Active Directory backups from ransomware

Design AD backups that survive ransomware: system state per domain, DSRM passwords, immutable and offline copies, a backup system outside the AD it protects.

Intermediate

Harden the directory before someone else tests it.

Start with the 90-day plan, or pick the area that keeps you up at night.