Guides
In-depth Active Directory hardening guides with Group Policy paths, attribute values, PowerShell and verification steps.
50 guides12 areas
Start here
Active Directory hardening checklist: a 30/60/90-day plan
A prioritised 30/60/90-day Active Directory hardening checklist: measure first, stop the easy domain takeovers, close relay paths, then build structure.
Area 01 · 4 guides
Tier 0 & Privileged Access
A small, protected Tier 0, admin tiering and privileged access workstations.
- 01Tier 0 and privileged access: locking down Domain AdminsBuild a working Tier 0 boundary in Active Directory with separate admin accounts, logon restrictions, PAWs, and authentication policy silos.
- 02Identify Tier 0 assets: a complete AD inventory methodInventory every Tier 0 asset in Active Directory: DCs, AD CS, Entra Connect, backup, hypervisors, and the groups and ACLs that give indirect control.
- 03Building privileged access workstations (PAWs) for ADDesign and build PAWs for Tier 0 admins: hardware, clean image, App Control allowlisting, no internet or email, and when a jump server is not enough.
- 04Authentication policies and silos for Tier 0 accountsRestrict where Tier 0 admins can authenticate with AD authentication policies and silos: prerequisites, claims, TGT lifetime, audit mode and enforcement.
Area 02 · 4 guides
Kerberos & Authentication
AES-only tickets, krbtgt rotation, pre-authentication and Kerberos armoring.
- 01Kerberos hardening: RC4, roasting and golden ticketsEnforce AES-only Kerberos, disable RC4 and DONT_REQ_PREAUTH, rotate krbtgt correctly, and detect Kerberoasting and golden ticket abuse.
- 02Disable RC4 in Kerberos: audit, fix and enforce AESRemove RC4 from Kerberos safely: audit 4768/4769, fix accounts without AES keys, set msDS-SupportedEncryptionTypes and DefaultDomainSupportedEncTypes, enforce.
- 03Rotating the krbtgt password safely in Active DirectoryRotate krbtgt without an outage: New-KrbtgtKeys.ps1, replication checks, RODC krbtgt accounts, a routine schedule and the incident-mode double reset.
- 04Defending against Kerberoasting and AS-REP roastingShrink Kerberoasting and AS-REP roasting exposure: inventory SPNs, remove stale ones, move to gMSA and AES, deploy a honey SPN and detect RC4 4769 spikes.
Area 03 · 4 guides
Delegation
Remove unconstrained delegation, scope constrained/RBCD and protect Tier 0.
- 01Active Directory delegation: finding and fixing risky trustsAudit unconstrained, constrained, and resource-based constrained delegation in Active Directory, and lock down privileged accounts against abuse.
- 02Remove unconstrained delegation from AD serversFind every non-DC account trusted for unconstrained delegation, map what depends on it, and migrate to constrained delegation or RBCD without outages.
- 03Constrained delegation and RBCD done safely in ADConfigure KCD and RBCD without new attack paths: protocol transition, SPN scoping, and auditing who can write msDS-AllowedToActOnBehalfOfOtherIdentity.
- 04Set ms-DS-MachineAccountQuota to 0 and delegate joinsStop any domain user from creating computer accounts: set ms-DS-MachineAccountQuota to 0, find who relies on it, and delegate domain join to an OU.
Area 04 · 5 guides
NTLM & Legacy Protocols
Sign and bind LDAP, require SMB signing, and audit then restrict NTLM.
- 01Stop NTLM relay: LDAP, SMB signing and LLMNRHarden LDAP signing, LDAP channel binding, SMB signing, and disable LLMNR/NBT-NS to shut down NTLM relay paths against domain controllers.
- 02Enforce LDAP signing and channel binding on DCsRoll out LDAP signing and channel binding with evidence: collect events 2887, 2889 and 3039, fix clients, then set LdapEnforceChannelBinding safely.
- 03Require SMB signing and disable SMBv1 domain-wideEnforce SMB signing on clients and servers, understand Windows 11 24H2 and Server 2025 defaults, audit SMBv1 use, and remove it without breaking file access.
- 04Audit and restrict NTLM in Active DirectoryA step-by-step NTLM reduction plan: audit with events 8001-8004, fix the causes, build an exception list, remove NTLMv1 and set LmCompatibilityLevel 5.
- 05Disable LLMNR, NBT-NS, mDNS and WPAD in ADRemove the name-resolution fallbacks attackers poison: disable LLMNR, NetBIOS and mDNS by GPO and DHCP, and block WPAD with the DNS global query block list.
Area 05 · 4 guides
AD Certificate Services
Fix vulnerable templates and CA settings (ESC1–ESC8) that grant domain admin.
- 01AD CS hardening: closing ESC1-ESC8 misconfigurationsHarden Active Directory Certificate Services against ESC1-ESC8 misconfigurations with template controls, EPA, and enrollment monitoring.
- 02Auditing AD CS certificate templates for ESC1-ESC4Audit every AD CS certificate template for ESC1-ESC4: subject flags, EKUs, enrollment rights and template ACLs, with PowerShell and a safe fix order.
- 03Securing AD CS web enrollment against ESC8 and ESC11Close NTLM relay to AD CS: find HTTP enrollment endpoints, enforce HTTPS and EPA, disable NTLM, remove Web Enrollment and enforce RPC encryption.
- 04Strong certificate mapping (KB5014754) in practiceGet certificate authentication ready for KB5014754 Full Enforcement: SID extension, altSecurityIdentities, KDC events 39/40/41 and the fixes that work.
Area 06 · 4 guides
Group Policy & SYSVOL
Lock down GPO delegation, purge Group Policy Preference passwords, fix SYSVOL ACLs.
- 01Group Policy and SYSVOL hardeningLock down GPO delegation, purge Group Policy Preferences cpassword secrets from SYSVOL, and add change control to prevent silent GPO abuse.
- 02Auditing GPO permissions and gPLink rightsFind who can edit, create and link GPOs in Active Directory: GPO ACLs, gPLink rights on OUs and sites, Group Policy Creator Owners and WMI filters.
- 03Finding and removing GPP passwords (cpassword)Find every Group Policy Preferences cpassword in SYSVOL, backups and client caches, map it to the exposed account, rotate it and stop it coming back.
- 04Deploying Microsoft security baselines with GPODeploy Microsoft security baselines with Group Policy: SCT, Policy Analyzer gap analysis, LGPO testing, ring-based rollout, exceptions and drift checks.
Area 07 · 4 guides
Domain Controller Hardening
Baseline DCs, disable the Print Spooler, restrict logon and patch the DC-killers.
- 01Domain controller hardening: the DC baselineA practical checklist for hardening domain controllers: security baselines, Print Spooler, logon rights, RDP, egress, and patch priorities.
- 02Blocking authentication coercion on domain controllersShut down PrinterBug, PetitPotam, DFSCoerce and ShadowCoerce on DCs with RPC filters, service reduction and relay-proof targets, then verify it holds.
- 03Netlogon secure channel hardening after ZeroLogonEnforce Netlogon secure RPC and sealing after ZeroLogon and CVE-2022-38023: audit events 5827-5831 and 5838-5839, empty the allowlist, verify.
- 04Firewalling domain controllers: ports, egress, admin accessBuild a domain controller firewall policy: required AD ports, restricted RPC, no internet egress, and RDP/WinRM only from Tier 0 PAWs. Measure first.
Area 08 · 4 guides
Object & ACL Security
Find dangerous ACLs, DCSync rights and AdminSDHolder drift across the directory.
- 01Auditing Active Directory ACLs before an attacker doesHow to find dangerous AD ACLs like GenericAll and DCSync rights, clean up stale adminCount flags, and use BloodHound defensively.
- 02Finding and removing DCSync rights in Active DirectoryAudit who holds DS-Replication-Get-Changes-All and equivalent rights on the domain root, remove the ones that should not exist, and alert on DCSync.
- 03AdminSDHolder and SDProp: cleanup and monitoringBaseline the AdminSDHolder ACL, find orphaned adminCount=1 accounts, reset their ACLs safely, trigger SDProp on demand, and alert on AdminSDHolder changes.
- 04Attack path management with BloodHound for defendersUse BloodHound defensively: tag Tier Zero correctly, find choke points, fix attack paths in the right order, and track exposure over time with safe collection.
Area 09 · 4 guides
Passwords & Service Accounts
Group managed service accounts, fine-grained policies, banned passwords and LAPS.
- 01Service account hardening: gMSA, SPNs and LAPSA practical guide to replacing risky service accounts with gMSA/dMSA, cleaning SPN exposure, fine-grained password policies, and Windows LAPS.
- 02Migrating service accounts to gMSA and dMSAStep-by-step migration from static service accounts to gMSA and Windows Server 2025 dMSA: KDS root key, retrieval rights, per-app notes and rollback.
- 03Deploying Windows LAPS: schema, permissions, policyDeploy Windows LAPS end to end: schema update, OU permissions, encryption, AD vs Entra backup, GPO settings, legacy LAPS migration and verification.
- 04AD password policy that works: length, FGPP, blocklistsBuild an Active Directory password policy on NIST guidance: long passphrases, fine-grained password policies, banned and breached password checks, no rotation.
Area 10 · 4 guides
Trusts & Forest Design
SID filtering, selective authentication and the forest as a security boundary.
- 01Hardening AD trusts and forest boundariesWhy the forest — not the domain — is the AD security boundary, and how to lock down trusts with SID filtering, quarantine, and selective authentication.
- 02SID filtering and selective authentication, step by stepConfigure and verify SID filtering, quarantine and selective authentication on AD trusts with netdom and PowerShell, including trustAttributes and events.
- 03Cleaning up SIDHistory after AD migrationsFind, assess and safely remove sIDHistory left over from domain migrations: dangerous SIDs, ACL re-permissioning, staged removal, rollback limits and detection.
- 04ESAE Red Forest vs the enterprise access model in 2026Why Microsoft retired ESAE as the default, what the enterprise access model asks you to build instead, and when a bastion forest or PAM trust still makes sense.
Area 11 · 4 guides
Auditing, Logging & Detection
Advanced audit policy on DCs, object SACLs, key event IDs and Defender for Identity.
- 01AD auditing and detection: audit policy and event IDsConfigure Advanced Audit Policy, SACLs, and Windows Event Forwarding so you can actually see Kerberoasting, DCSync, and privilege escalation in AD.
- 02Active Directory security event IDs: a DC referenceEvery AD security event ID worth collecting on domain controllers: logon, Kerberos, NTLM, account, group, directory and AD CS events, with fields to hunt.
- 03AD honeytokens: honey accounts, honey SPNs and decoysDeploy honey accounts, honey SPNs, AS-REP decoys, fake GPP passwords and read-audited decoy objects in AD, and alert on them with near-zero false positives.
- 04Windows Event Forwarding for domain controllersBuild a Windows Event Forwarding pipeline for DCs: source-initiated subscriptions, GPO, log access, XPath queries, collector sizing and health checks.
Area 12 · 4 guides
Assessment, Backup & Recovery
Score the domain, keep offline DC backups and rehearse forest recovery.
- 01AD assessment, backup and forest recoveryRun recurring AD posture assessments against CIS and Microsoft baselines, protect Tier 0 backups, and rehearse forest recovery before you need it for real.
- 02PingCastle assessment: from AD report to action planRun a PingCastle health check on Active Directory, read the four risk scores correctly, triage findings into owners and sprints, and track progress over time.
- 03Protecting Active Directory backups from ransomwareDesign AD backups that survive ransomware: system state per domain, DSRM passwords, immutable and offline copies, a backup system outside the AD it protects.
- 04Writing and rehearsing an AD forest recovery planBuild an Active Directory forest recovery runbook from Microsoft's guide: clean room, first DC restore, SYSVOL, FSMO, RID pool, krbtgt resets and yearly drills.