Skip to content
Foundation

Active Directory hardening checklist: a 30/60/90-day plan

A prioritised 30/60/90-day Active Directory hardening checklist: measure first, stop the easy domain takeovers, close relay paths, then build structure.

Florian Amette10 min read

Active Directory hardening guidance tends to arrive as a list of two hundred settings with no order. That is not how real domains get compromised, and it is not how they should be fixed. Incident after incident follows the same short set of paths: a shared local admin password, a roastable service account, an NTLM relay into AD CS, a stale ACL that grants DCSync, a Domain Admin who signed in to a workstation. Close those first and you remove most of the routes an attacker actually uses; everything else is refinement.

This checklist orders the work by how much risk each item removes per hour of effort. The first 30 days target the controls that stop the most common full-domain takeovers with little chance of breaking anything. Days 31 to 60 close the relay and delegation paths, which need more testing. Days 61 to 90 build the structural controls — tiering, trust hygiene, recovery — that keep the domain defensible over time. Each item links to a step-by-step guide.

Before you start

You cannot prioritise what you have not measured, and you cannot protect Tier 0 if you do not know what is in it. Spend the first few days on these, before touching a single GPO.

  • Run a baseline assessment — a scored report gives you a before-and-after metric and a ranked list of findings. See Running a PingCastle assessment.
  • Map attack paths to privileged groups — findings matter most when they chain into Domain Admins. See Attack path management with BloodHound.
  • Inventory every Tier 0 asset — domain controllers are the obvious part; AD CS, Entra Connect, backup servers, hypervisors and GPO editors are the part people miss. See Defining Tier 0.
  • Confirm you have a restorable, offline AD backup — before making changes, make sure you can undo the worst case. See AD assessment, backup and forest recovery.
  • Turn on the audit policy you will need to measure impact — several later steps rely on events that are off by default. See AD auditing and detection.

Record the PingCastle score, the number of accounts in privileged groups and the number of attack paths to Domain Admins. These three numbers are what you report at day 30, 60 and 90.

Days 0–30: stop the bleeding

The goal of the first month is to remove the cheap, reliable paths to domain compromise. These items are low risk to operations, high impact against attackers, and mostly reversible.

Privileged accounts and groups

Credentials lying around

  • Deploy Windows LAPS to every workstation and member server — unique local admin passwords kill the most common lateral movement. See Deploying Windows LAPS.
  • Find and delete Group Policy Preferences passwords, then rotate them — cpassword values are readable by every domain user. See Removing GPP passwords.
  • Remove unneeded SPNs and set long random passwords on the rest — this makes Kerberoasting and AS-REP roasting unprofitable. See Defending against Kerberoasting.
  • Raise password length for admins and service accounts with fine-grained policies — length beats complexity rules. See Password policy that works.

Easy network wins

Domain controllers

  • Patch DCs and confirm Netlogon secure channel enforcement — ZeroLogon-class bugs remain a one-shot domain takeover. See Netlogon secure channel enforcement.
  • Stop the Print Spooler and other unnecessary services on DCs — fewer services, fewer coercion and exploit paths. See Domain controller hardening.
  • Rotate the krbtgt password if it has not changed in years — an old krbtgt key means any past compromise may still grant golden tickets. See Rotating krbtgt safely.

At day 30, re-run PingCastle. A drop of a third or more in the score is typical when these items are done.

Days 31–60: close the relay and delegation paths

The second month deals with the controls that need an audit phase: NTLM relay protections, delegation clean-up and AD CS. Start each in audit or logging mode on day 31, then enforce as the data allows.

NTLM relay and legacy protocols

AD Certificate Services

  • Audit certificate templates for ESC1–ESC4 — a template that lets the enrollee supply the subject is a domain admin certificate for anyone. See Auditing certificate templates.
  • Secure or remove web enrollment — HTTP enrollment without EPA is the ESC8 relay target. See Securing AD CS web enrollment.
  • Move to strong certificate mapping enforcement — weak mappings let forged or reused certificates impersonate accounts. See Strong certificate mapping.
  • Treat CAs as Tier 0 and close the remaining ESC findings — see AD CS hardening.

Kerberos and delegation

Service accounts

Days 61–90: structural hardening

With the obvious paths closed, the third month builds structure: tiering that prevents credential exposure by design, Group Policy you can trust, trusts that do not leak privilege, and a recovery capability you have actually tested.

Tiering and privileged access

Group Policy and baselines

Domain controllers

Trusts and forest design

Backup and recovery

Ongoing: detect, rehearse, re-measure

Hardening decays. New servers get unconstrained delegation, a vendor asks for Domain Admin, someone re-enables RC4 for an old appliance. These items turn the 90-day project into an operating rhythm.

How to use this checklist

Copy the checklists into your ticketing system with one ticket per item, an owner, and a target date inside the phase. Do not wait for a phase to be complete before starting the next one's audit work: turning on NTLM or LDAP auditing on day 10 means you have a month of data when enforcement comes around on day 45.

Treat the order as a default, not a rule. If your PingCastle report shows a critical finding — DCSync rights for Everyone, an ESC1 template enrollable by Domain Users, a Domain Admin password unchanged since 2011 — fix it today, whatever phase it falls in. Likewise, if an item does not apply (no AD CS, no trusts), mark it as not applicable with a short note so the next auditor knows it was considered.

Finally, report progress with the numbers you captured before you started. A falling assessment score and a shrinking count of attack paths to Domain Admins are what justify the next round of investment, and they are much more persuasive than a list of GPOs changed.

Related reading: Tier 0 & Privileged Access, Kerberos & Authentication, Delegation, NTLM & Legacy Protocols, AD Certificate Services, Group Policy & SYSVOL, Domain Controller Hardening, Object & ACL Security, Passwords & Service Accounts, Trusts & Forest Design, Auditing, Logging & Detection, Assessment, Backup & Recovery.

Frequently asked questions

Can a small IT team really finish this in 90 days?

Most teams finish the first 30 days fully and make solid progress on the rest. The phases are ordered by risk reduction per hour of effort, not by calendar rigidity. If an item stalls because an application owner needs time, start it in audit mode, record the exception with an owner and a date, and move on. Ninety days of steady progress beats a perfect plan that never leaves the backlog.

Do I need a tool like PingCastle or BloodHound before starting?

You need some measurement before you change anything, and PingCastle is the quickest free way to get a scored baseline of a domain. BloodHound adds the attack path view that shows how the findings chain together. Neither is strictly required, but without them you are guessing at priorities and have no way to prove to management that the risk actually went down.

What if a change breaks a legacy application?

Almost every control in this checklist has an audit or logging mode: NTLM auditing, LDAP signing events, RC4 ticket events, authentication silo audit mode. Use it for two to four weeks before enforcing, fix or document what shows up, and keep a rollback GPO ready. When something truly cannot be fixed, isolate it and grant a narrow, time-boxed exception instead of weakening the whole domain.

Active Directory hardening checklist: a 30/60/90-day plan

Related guides

Group Policy & SYSVOL

Deploying Microsoft security baselines with GPO

Deploy Microsoft security baselines with Group Policy: SCT, Policy Analyzer gap analysis, LGPO testing, ring-based rollout, exceptions and drift checks.

Intermediate
Domain Controller Hardening

Domain controller hardening: the DC baseline

A practical checklist for hardening domain controllers: security baselines, Print Spooler, logon rights, RDP, egress, and patch priorities.

Foundation