Skip to content

Guides

In-depth Active Directory hardening guides with Group Policy paths, attribute values, PowerShell and verification steps.

50 guides12 areas

Search guides…⌘K

Start here

Active Directory hardening checklist: a 30/60/90-day plan

A prioritised 30/60/90-day Active Directory hardening checklist: measure first, stop the easy domain takeovers, close relay paths, then build structure.

Open the 90-day plan

Area 01 · 4 guides

Tier 0 & Privileged Access

A small, protected Tier 0, admin tiering and privileged access workstations.

View area
  1. 01Tier 0 and privileged access: locking down Domain AdminsBuild a working Tier 0 boundary in Active Directory with separate admin accounts, logon restrictions, PAWs, and authentication policy silos.
  2. 02Identify Tier 0 assets: a complete AD inventory methodInventory every Tier 0 asset in Active Directory: DCs, AD CS, Entra Connect, backup, hypervisors, and the groups and ACLs that give indirect control.
  3. 03Building privileged access workstations (PAWs) for ADDesign and build PAWs for Tier 0 admins: hardware, clean image, App Control allowlisting, no internet or email, and when a jump server is not enough.
  4. 04Authentication policies and silos for Tier 0 accountsRestrict where Tier 0 admins can authenticate with AD authentication policies and silos: prerequisites, claims, TGT lifetime, audit mode and enforcement.

Area 02 · 4 guides

Kerberos & Authentication

AES-only tickets, krbtgt rotation, pre-authentication and Kerberos armoring.

View area
  1. 01Kerberos hardening: RC4, roasting and golden ticketsEnforce AES-only Kerberos, disable RC4 and DONT_REQ_PREAUTH, rotate krbtgt correctly, and detect Kerberoasting and golden ticket abuse.
  2. 02Disable RC4 in Kerberos: audit, fix and enforce AESRemove RC4 from Kerberos safely: audit 4768/4769, fix accounts without AES keys, set msDS-SupportedEncryptionTypes and DefaultDomainSupportedEncTypes, enforce.
  3. 03Rotating the krbtgt password safely in Active DirectoryRotate krbtgt without an outage: New-KrbtgtKeys.ps1, replication checks, RODC krbtgt accounts, a routine schedule and the incident-mode double reset.
  4. 04Defending against Kerberoasting and AS-REP roastingShrink Kerberoasting and AS-REP roasting exposure: inventory SPNs, remove stale ones, move to gMSA and AES, deploy a honey SPN and detect RC4 4769 spikes.

Area 03 · 4 guides

Delegation

Remove unconstrained delegation, scope constrained/RBCD and protect Tier 0.

View area
  1. 01Active Directory delegation: finding and fixing risky trustsAudit unconstrained, constrained, and resource-based constrained delegation in Active Directory, and lock down privileged accounts against abuse.
  2. 02Remove unconstrained delegation from AD serversFind every non-DC account trusted for unconstrained delegation, map what depends on it, and migrate to constrained delegation or RBCD without outages.
  3. 03Constrained delegation and RBCD done safely in ADConfigure KCD and RBCD without new attack paths: protocol transition, SPN scoping, and auditing who can write msDS-AllowedToActOnBehalfOfOtherIdentity.
  4. 04Set ms-DS-MachineAccountQuota to 0 and delegate joinsStop any domain user from creating computer accounts: set ms-DS-MachineAccountQuota to 0, find who relies on it, and delegate domain join to an OU.

Area 04 · 5 guides

NTLM & Legacy Protocols

Sign and bind LDAP, require SMB signing, and audit then restrict NTLM.

View area
  1. 01Stop NTLM relay: LDAP, SMB signing and LLMNRHarden LDAP signing, LDAP channel binding, SMB signing, and disable LLMNR/NBT-NS to shut down NTLM relay paths against domain controllers.
  2. 02Enforce LDAP signing and channel binding on DCsRoll out LDAP signing and channel binding with evidence: collect events 2887, 2889 and 3039, fix clients, then set LdapEnforceChannelBinding safely.
  3. 03Require SMB signing and disable SMBv1 domain-wideEnforce SMB signing on clients and servers, understand Windows 11 24H2 and Server 2025 defaults, audit SMBv1 use, and remove it without breaking file access.
  4. 04Audit and restrict NTLM in Active DirectoryA step-by-step NTLM reduction plan: audit with events 8001-8004, fix the causes, build an exception list, remove NTLMv1 and set LmCompatibilityLevel 5.
  5. 05Disable LLMNR, NBT-NS, mDNS and WPAD in ADRemove the name-resolution fallbacks attackers poison: disable LLMNR, NetBIOS and mDNS by GPO and DHCP, and block WPAD with the DNS global query block list.

Area 05 · 4 guides

AD Certificate Services

Fix vulnerable templates and CA settings (ESC1–ESC8) that grant domain admin.

View area
  1. 01AD CS hardening: closing ESC1-ESC8 misconfigurationsHarden Active Directory Certificate Services against ESC1-ESC8 misconfigurations with template controls, EPA, and enrollment monitoring.
  2. 02Auditing AD CS certificate templates for ESC1-ESC4Audit every AD CS certificate template for ESC1-ESC4: subject flags, EKUs, enrollment rights and template ACLs, with PowerShell and a safe fix order.
  3. 03Securing AD CS web enrollment against ESC8 and ESC11Close NTLM relay to AD CS: find HTTP enrollment endpoints, enforce HTTPS and EPA, disable NTLM, remove Web Enrollment and enforce RPC encryption.
  4. 04Strong certificate mapping (KB5014754) in practiceGet certificate authentication ready for KB5014754 Full Enforcement: SID extension, altSecurityIdentities, KDC events 39/40/41 and the fixes that work.

Area 06 · 4 guides

Group Policy & SYSVOL

Lock down GPO delegation, purge Group Policy Preference passwords, fix SYSVOL ACLs.

View area
  1. 01Group Policy and SYSVOL hardeningLock down GPO delegation, purge Group Policy Preferences cpassword secrets from SYSVOL, and add change control to prevent silent GPO abuse.
  2. 02Auditing GPO permissions and gPLink rightsFind who can edit, create and link GPOs in Active Directory: GPO ACLs, gPLink rights on OUs and sites, Group Policy Creator Owners and WMI filters.
  3. 03Finding and removing GPP passwords (cpassword)Find every Group Policy Preferences cpassword in SYSVOL, backups and client caches, map it to the exposed account, rotate it and stop it coming back.
  4. 04Deploying Microsoft security baselines with GPODeploy Microsoft security baselines with Group Policy: SCT, Policy Analyzer gap analysis, LGPO testing, ring-based rollout, exceptions and drift checks.

Area 07 · 4 guides

Domain Controller Hardening

Baseline DCs, disable the Print Spooler, restrict logon and patch the DC-killers.

View area
  1. 01Domain controller hardening: the DC baselineA practical checklist for hardening domain controllers: security baselines, Print Spooler, logon rights, RDP, egress, and patch priorities.
  2. 02Blocking authentication coercion on domain controllersShut down PrinterBug, PetitPotam, DFSCoerce and ShadowCoerce on DCs with RPC filters, service reduction and relay-proof targets, then verify it holds.
  3. 03Netlogon secure channel hardening after ZeroLogonEnforce Netlogon secure RPC and sealing after ZeroLogon and CVE-2022-38023: audit events 5827-5831 and 5838-5839, empty the allowlist, verify.
  4. 04Firewalling domain controllers: ports, egress, admin accessBuild a domain controller firewall policy: required AD ports, restricted RPC, no internet egress, and RDP/WinRM only from Tier 0 PAWs. Measure first.

Area 08 · 4 guides

Object & ACL Security

Find dangerous ACLs, DCSync rights and AdminSDHolder drift across the directory.

View area
  1. 01Auditing Active Directory ACLs before an attacker doesHow to find dangerous AD ACLs like GenericAll and DCSync rights, clean up stale adminCount flags, and use BloodHound defensively.
  2. 02Finding and removing DCSync rights in Active DirectoryAudit who holds DS-Replication-Get-Changes-All and equivalent rights on the domain root, remove the ones that should not exist, and alert on DCSync.
  3. 03AdminSDHolder and SDProp: cleanup and monitoringBaseline the AdminSDHolder ACL, find orphaned adminCount=1 accounts, reset their ACLs safely, trigger SDProp on demand, and alert on AdminSDHolder changes.
  4. 04Attack path management with BloodHound for defendersUse BloodHound defensively: tag Tier Zero correctly, find choke points, fix attack paths in the right order, and track exposure over time with safe collection.

Area 09 · 4 guides

Passwords & Service Accounts

Group managed service accounts, fine-grained policies, banned passwords and LAPS.

View area
  1. 01Service account hardening: gMSA, SPNs and LAPSA practical guide to replacing risky service accounts with gMSA/dMSA, cleaning SPN exposure, fine-grained password policies, and Windows LAPS.
  2. 02Migrating service accounts to gMSA and dMSAStep-by-step migration from static service accounts to gMSA and Windows Server 2025 dMSA: KDS root key, retrieval rights, per-app notes and rollback.
  3. 03Deploying Windows LAPS: schema, permissions, policyDeploy Windows LAPS end to end: schema update, OU permissions, encryption, AD vs Entra backup, GPO settings, legacy LAPS migration and verification.
  4. 04AD password policy that works: length, FGPP, blocklistsBuild an Active Directory password policy on NIST guidance: long passphrases, fine-grained password policies, banned and breached password checks, no rotation.

Area 10 · 4 guides

Trusts & Forest Design

SID filtering, selective authentication and the forest as a security boundary.

View area
  1. 01Hardening AD trusts and forest boundariesWhy the forest — not the domain — is the AD security boundary, and how to lock down trusts with SID filtering, quarantine, and selective authentication.
  2. 02SID filtering and selective authentication, step by stepConfigure and verify SID filtering, quarantine and selective authentication on AD trusts with netdom and PowerShell, including trustAttributes and events.
  3. 03Cleaning up SIDHistory after AD migrationsFind, assess and safely remove sIDHistory left over from domain migrations: dangerous SIDs, ACL re-permissioning, staged removal, rollback limits and detection.
  4. 04ESAE Red Forest vs the enterprise access model in 2026Why Microsoft retired ESAE as the default, what the enterprise access model asks you to build instead, and when a bastion forest or PAM trust still makes sense.

Area 11 · 4 guides

Auditing, Logging & Detection

Advanced audit policy on DCs, object SACLs, key event IDs and Defender for Identity.

View area
  1. 01AD auditing and detection: audit policy and event IDsConfigure Advanced Audit Policy, SACLs, and Windows Event Forwarding so you can actually see Kerberoasting, DCSync, and privilege escalation in AD.
  2. 02Active Directory security event IDs: a DC referenceEvery AD security event ID worth collecting on domain controllers: logon, Kerberos, NTLM, account, group, directory and AD CS events, with fields to hunt.
  3. 03AD honeytokens: honey accounts, honey SPNs and decoysDeploy honey accounts, honey SPNs, AS-REP decoys, fake GPP passwords and read-audited decoy objects in AD, and alert on them with near-zero false positives.
  4. 04Windows Event Forwarding for domain controllersBuild a Windows Event Forwarding pipeline for DCs: source-initiated subscriptions, GPO, log access, XPath queries, collector sizing and health checks.

Area 12 · 4 guides

Assessment, Backup & Recovery

Score the domain, keep offline DC backups and rehearse forest recovery.

View area
  1. 01AD assessment, backup and forest recoveryRun recurring AD posture assessments against CIS and Microsoft baselines, protect Tier 0 backups, and rehearse forest recovery before you need it for real.
  2. 02PingCastle assessment: from AD report to action planRun a PingCastle health check on Active Directory, read the four risk scores correctly, triage findings into owners and sprints, and track progress over time.
  3. 03Protecting Active Directory backups from ransomwareDesign AD backups that survive ransomware: system state per domain, DSRM passwords, immutable and offline copies, a backup system outside the AD it protects.
  4. 04Writing and rehearsing an AD forest recovery planBuild an Active Directory forest recovery runbook from Microsoft's guide: clean room, first DC restore, SYSVOL, FSMO, RID pool, krbtgt resets and yearly drills.