Active Directory hardening checklist: a 30/60/90-day plan
A prioritised 30/60/90-day Active Directory hardening checklist: measure first, stop the easy domain takeovers, close relay paths, then build structure.
Security engineer writing practical, baseline-aligned hardening guides for Active Directory: identity, Kerberos, delegation and domain controllers.
A prioritised 30/60/90-day Active Directory hardening checklist: measure first, stop the easy domain takeovers, close relay paths, then build structure.
Use BloodHound defensively: tag Tier Zero correctly, find choke points, fix attack paths in the right order, and track exposure over time with safe collection.
Remove the name-resolution fallbacks attackers poison: disable LLMNR, NetBIOS and mDNS by GPO and DHCP, and block WPAD with the DNS global query block list.
Why Microsoft retired ESAE as the default, what the enterprise access model asks you to build instead, and when a bastion forest or PAM trust still makes sense.
Build an Active Directory forest recovery runbook from Microsoft's guide: clean room, first DC restore, SYSVOL, FSMO, RID pool, krbtgt resets and yearly drills.
Deploy Microsoft security baselines with Group Policy: SCT, Policy Analyzer gap analysis, LGPO testing, ring-based rollout, exceptions and drift checks.
Design AD backups that survive ransomware: system state per domain, DSRM passwords, immutable and offline copies, a backup system outside the AD it protects.
Baseline the AdminSDHolder ACL, find orphaned adminCount=1 accounts, reset their ACLs safely, trigger SDProp on demand, and alert on AdminSDHolder changes.
Restrict where Tier 0 admins can authenticate with AD authentication policies and silos: prerequisites, claims, TGT lifetime, audit mode and enforcement.
Find who can edit, create and link GPOs in Active Directory: GPO ACLs, gPLink rights on OUs and sites, Group Policy Creator Owners and WMI filters.
Shrink Kerberoasting and AS-REP roasting exposure: inventory SPNs, remove stale ones, move to gMSA and AES, deploy a honey SPN and detect RC4 4769 spikes.
Run a PingCastle health check on Active Directory, read the four risk scores correctly, triage findings into owners and sprints, and track progress over time.
Find every Group Policy Preferences cpassword in SYSVOL, backups and client caches, map it to the exposed account, rotate it and stop it coming back.
A step-by-step NTLM reduction plan: audit with events 8001-8004, fix the causes, build an exception list, remove NTLMv1 and set LmCompatibilityLevel 5.
Configure and verify SID filtering, quarantine and selective authentication on AD trusts with netdom and PowerShell, including trustAttributes and events.
Find, assess and safely remove sIDHistory left over from domain migrations: dangerous SIDs, ACL re-permissioning, staged removal, rollback limits and detection.
Enforce SMB signing on clients and servers, understand Windows 11 24H2 and Server 2025 defaults, audit SMBv1 use, and remove it without breaking file access.
Audit who holds DS-Replication-Get-Changes-All and equivalent rights on the domain root, remove the ones that should not exist, and alert on DCSync.
Build a domain controller firewall policy: required AD ports, restricted RPC, no internet egress, and RDP/WinRM only from Tier 0 PAWs. Measure first.
Deploy honey accounts, honey SPNs, AS-REP decoys, fake GPP passwords and read-audited decoy objects in AD, and alert on them with near-zero false positives.
Rotate krbtgt without an outage: New-KrbtgtKeys.ps1, replication checks, RODC krbtgt accounts, a routine schedule and the incident-mode double reset.
Roll out LDAP signing and channel binding with evidence: collect events 2887, 2889 and 3039, fix clients, then set LdapEnforceChannelBinding safely.
Stop any domain user from creating computer accounts: set ms-DS-MachineAccountQuota to 0, find who relies on it, and delegate domain join to an OU.
Build an Active Directory password policy on NIST guidance: long passphrases, fine-grained password policies, banned and breached password checks, no rotation.
Design and build PAWs for Tier 0 admins: hardware, clean image, App Control allowlisting, no internet or email, and when a jump server is not enough.
Get certificate authentication ready for KB5014754 Full Enforcement: SID extension, altSecurityIdentities, KDC events 39/40/41 and the fixes that work.
Build a Windows Event Forwarding pipeline for DCs: source-initiated subscriptions, GPO, log access, XPath queries, collector sizing and health checks.
Every AD security event ID worth collecting on domain controllers: logon, Kerberos, NTLM, account, group, directory and AD CS events, with fields to hunt.
Audit every AD CS certificate template for ESC1-ESC4: subject flags, EKUs, enrollment rights and template ACLs, with PowerShell and a safe fix order.
Close NTLM relay to AD CS: find HTTP enrollment endpoints, enforce HTTPS and EPA, disable NTLM, remove Web Enrollment and enforce RPC encryption.
Shut down PrinterBug, PetitPotam, DFSCoerce and ShadowCoerce on DCs with RPC filters, service reduction and relay-proof targets, then verify it holds.
Configure KCD and RBCD without new attack paths: protocol transition, SPN scoping, and auditing who can write msDS-AllowedToActOnBehalfOfOtherIdentity.
Remove RC4 from Kerberos safely: audit 4768/4769, fix accounts without AES keys, set msDS-SupportedEncryptionTypes and DefaultDomainSupportedEncTypes, enforce.
Step-by-step migration from static service accounts to gMSA and Windows Server 2025 dMSA: KDS root key, retrieval rights, per-app notes and rollback.
Inventory every Tier 0 asset in Active Directory: DCs, AD CS, Entra Connect, backup, hypervisors, and the groups and ACLs that give indirect control.
Enforce Netlogon secure RPC and sealing after ZeroLogon and CVE-2022-38023: audit events 5827-5831 and 5838-5839, empty the allowlist, verify.
Find every non-DC account trusted for unconstrained delegation, map what depends on it, and migrate to constrained delegation or RBCD without outages.
Deploy Windows LAPS end to end: schema update, OU permissions, encryption, AD vs Entra backup, GPO settings, legacy LAPS migration and verification.
How to find dangerous AD ACLs like GenericAll and DCSync rights, clean up stale adminCount flags, and use BloodHound defensively.
Audit unconstrained, constrained, and resource-based constrained delegation in Active Directory, and lock down privileged accounts against abuse.
Run recurring AD posture assessments against CIS and Microsoft baselines, protect Tier 0 backups, and rehearse forest recovery before you need it for real.
Configure Advanced Audit Policy, SACLs, and Windows Event Forwarding so you can actually see Kerberoasting, DCSync, and privilege escalation in AD.
Why the forest — not the domain — is the AD security boundary, and how to lock down trusts with SID filtering, quarantine, and selective authentication.
Harden Active Directory Certificate Services against ESC1-ESC8 misconfigurations with template controls, EPA, and enrollment monitoring.
A practical checklist for hardening domain controllers: security baselines, Print Spooler, logon rights, RDP, egress, and patch priorities.
Lock down GPO delegation, purge Group Policy Preferences cpassword secrets from SYSVOL, and add change control to prevent silent GPO abuse.
Enforce AES-only Kerberos, disable RC4 and DONT_REQ_PREAUTH, rotate krbtgt correctly, and detect Kerberoasting and golden ticket abuse.
Harden LDAP signing, LDAP channel binding, SMB signing, and disable LLMNR/NBT-NS to shut down NTLM relay paths against domain controllers.
A practical guide to replacing risky service accounts with gMSA/dMSA, cleaning SPN exposure, fine-grained password policies, and Windows LAPS.
Build a working Tier 0 boundary in Active Directory with separate admin accounts, logon restrictions, PAWs, and authentication policy silos.