Active Directory hardening checklist: a 30/60/90-day plan
A prioritised 30/60/90-day Active Directory hardening checklist: measure first, stop the easy domain takeovers, close relay paths, then build structure.
Active Directory hardening guidance tends to arrive as a list of two hundred settings with no order. That is not how real domains get compromised, and it is not how they should be fixed. Incident after incident follows the same short set of paths: a shared local admin password, a roastable service account, an NTLM relay into AD CS, a stale ACL that grants DCSync, a Domain Admin who signed in to a workstation. Close those first and you remove most of the routes an attacker actually uses; everything else is refinement.
This checklist orders the work by how much risk each item removes per hour of effort. The first 30 days target the controls that stop the most common full-domain takeovers with little chance of breaking anything. Days 31 to 60 close the relay and delegation paths, which need more testing. Days 61 to 90 build the structural controls — tiering, trust hygiene, recovery — that keep the domain defensible over time. Each item links to a step-by-step guide.
Before you start
You cannot prioritise what you have not measured, and you cannot protect Tier 0 if you do not know what is in it. Spend the first few days on these, before touching a single GPO.
- Run a baseline assessment — a scored report gives you a before-and-after metric and a ranked list of findings. See Running a PingCastle assessment.
- Map attack paths to privileged groups — findings matter most when they chain into Domain Admins. See Attack path management with BloodHound.
- Inventory every Tier 0 asset — domain controllers are the obvious part; AD CS, Entra Connect, backup servers, hypervisors and GPO editors are the part people miss. See Defining Tier 0.
- Confirm you have a restorable, offline AD backup — before making changes, make sure you can undo the worst case. See AD assessment, backup and forest recovery.
- Turn on the audit policy you will need to measure impact — several later steps rely on events that are off by default. See AD auditing and detection.
Record the PingCastle score, the number of accounts in privileged groups and the number of attack paths to Domain Admins. These three numbers are what you report at day 30, 60 and 90.
Days 0–30: stop the bleeding
The goal of the first month is to remove the cheap, reliable paths to domain compromise. These items are low risk to operations, high impact against attackers, and mostly reversible.
Privileged accounts and groups
- Empty privileged groups down to named, justified members — every extra Domain Admin is another credential worth stealing. See Tier 0 and privileged access.
- Remove non-DC principals holding replication rights — anyone with DS-Replication-Get-Changes-All can dump every hash. See Finding and removing DCSync rights.
- Clean up orphaned adminCount and review AdminSDHolder — stale protections hide former admins and odd ACLs. See AdminSDHolder, SDProp and orphaned adminCount.
- Fix the most dangerous ACLs on domain, AdminSDHolder and Tier 0 objects — GenericAll and WriteDacl for broad groups are direct escalation paths. See Auditing Active Directory ACLs.
Credentials lying around
- Deploy Windows LAPS to every workstation and member server — unique local admin passwords kill the most common lateral movement. See Deploying Windows LAPS.
- Find and delete Group Policy Preferences passwords, then rotate them — cpassword values are readable by every domain user. See Removing GPP passwords.
- Remove unneeded SPNs and set long random passwords on the rest — this makes Kerberoasting and AS-REP roasting unprofitable. See Defending against Kerberoasting.
- Raise password length for admins and service accounts with fine-grained policies — length beats complexity rules. See Password policy that works.
Easy network wins
- Disable LLMNR, NBT-NS and WPAD — this removes the easiest credential capture on the LAN. See Disabling LLMNR, NBT-NS, mDNS and WPAD.
- Require SMB signing and remove SMBv1 — relay to SMB and wormable legacy SMB both disappear. See Requiring SMB signing.
- Set ms-DS-MachineAccountQuota to 0 — ordinary users should not be able to create computer accounts that later power RBCD and relay chains. See Set ms-DS-MachineAccountQuota to 0.
Domain controllers
- Patch DCs and confirm Netlogon secure channel enforcement — ZeroLogon-class bugs remain a one-shot domain takeover. See Netlogon secure channel enforcement.
- Stop the Print Spooler and other unnecessary services on DCs — fewer services, fewer coercion and exploit paths. See Domain controller hardening.
- Rotate the krbtgt password if it has not changed in years — an old krbtgt key means any past compromise may still grant golden tickets. See Rotating krbtgt safely.
At day 30, re-run PingCastle. A drop of a third or more in the score is typical when these items are done.
Days 31–60: close the relay and delegation paths
The second month deals with the controls that need an audit phase: NTLM relay protections, delegation clean-up and AD CS. Start each in audit or logging mode on day 31, then enforce as the data allows.
NTLM relay and legacy protocols
- Enforce LDAP signing and channel binding — relay to LDAP is how coerced authentication becomes RBCD or shadow credentials. See Enforcing LDAP signing and channel binding.
- Audit NTLM, then remove NTLMv1 and restrict NTLM where possible — every remaining NTLM flow is a potential relay. See Auditing and restricting NTLM.
- Review the NTLM relay picture end to end — signing, EPA and name resolution work together. See Stop NTLM relay.
- Block authentication coercion on DCs and Tier 0 servers — PetitPotam-style tricks feed every relay chain. See Blocking authentication coercion.
AD Certificate Services
- Audit certificate templates for ESC1–ESC4 — a template that lets the enrollee supply the subject is a domain admin certificate for anyone. See Auditing certificate templates.
- Secure or remove web enrollment — HTTP enrollment without EPA is the ESC8 relay target. See Securing AD CS web enrollment.
- Move to strong certificate mapping enforcement — weak mappings let forged or reused certificates impersonate accounts. See Strong certificate mapping.
- Treat CAs as Tier 0 and close the remaining ESC findings — see AD CS hardening.
Kerberos and delegation
- Remove unconstrained delegation from everything except DCs — any compromised host with it can capture privileged TGTs. See Removing unconstrained delegation.
- Review constrained delegation and who can write RBCD — protocol transition and writable msDS-AllowedToActOnBehalfOfOtherIdentity are quiet escalation paths. See Constrained delegation and RBCD done safely.
- Get the overall delegation picture, including trusts — see Active Directory delegation.
- Audit RC4 usage and plan its removal — RC4 tickets are what make roasting fast. See Disabling RC4 in Kerberos.
- Apply the broader Kerberos baseline — see Kerberos hardening.
Service accounts
- Migrate service accounts to gMSA (or dMSA on Windows Server 2025) — managed passwords remove the roasting and reuse problem for good. See Migrating service accounts to gMSA.
- Review service account privileges, SPNs and logon rights — see Service account hardening.
Days 61–90: structural hardening
With the obvious paths closed, the third month builds structure: tiering that prevents credential exposure by design, Group Policy you can trust, trusts that do not leak privilege, and a recovery capability you have actually tested.
Tiering and privileged access
- Deploy privileged access workstations for Tier 0 admins — the device an admin types on is part of the boundary. See Building privileged access workstations.
- Put Tier 0 accounts in authentication policy silos and Protected Users — stolen credentials become useless off approved hosts. See Authentication policies and silos for Tier 0.
- Decide on your long-term admin architecture — see ESAE/Red Forest vs the enterprise access model.
Group Policy and baselines
- Audit who can edit, link and create GPOs — GPO edit rights on a DC-linked policy are Domain Admin rights. See Auditing GPO permissions and links.
- Deploy Microsoft security baselines in rings — see Deploying Microsoft security baselines with GPO.
- Harden SYSVOL and GPO processing — see Group Policy and SYSVOL hardening.
Domain controllers
- Firewall DCs: required ports only, no outbound internet, management from Tier 0 only — see Firewalling domain controllers.
Trusts and forest design
- Verify SID filtering and apply selective authentication on external and forest trusts — see SID filtering and selective authentication.
- Clean up SIDHistory left by migrations — each leftover SID is extra privilege nobody reviews. See Cleaning up SIDHistory.
- Remove trusts that no longer serve a business purpose — see Hardening AD trusts and forest boundaries.
Backup and recovery
- Isolate AD backups from ransomware — backups that domain admins can delete are not backups. See Protecting AD backups from ransomware.
- Write a forest recovery plan — see Writing and rehearsing an AD forest recovery plan.
Ongoing: detect, rehearse, re-measure
Hardening decays. New servers get unconstrained delegation, a vendor asks for Domain Admin, someone re-enables RC4 for an old appliance. These items turn the 90-day project into an operating rhythm.
- Forward DC security logs to a central collector — detection is impossible if events roll over locally in hours. See Windows Event Forwarding for domain controllers.
- Build alerts on the high-value event IDs — group changes, DCSync, suspicious ticket requests, certificate issuance. See Active Directory security event IDs reference.
- Plant honeytokens — a decoy admin and a honey SPN give high-confidence, early warning of reconnaissance. See Honeytokens and deception in AD.
- Rotate krbtgt on a schedule — twice a year is a sensible cadence, and twice in a row after any incident. See Rotating krbtgt safely.
- Rehearse forest recovery at least annually in an isolated lab — see Writing and rehearsing an AD forest recovery plan.
- Re-run PingCastle monthly and BloodHound quarterly — track the score and the number of paths to Tier 0 as KPIs. See Running a PingCastle assessment.
- Re-validate the Tier 0 inventory whenever new infrastructure appears — see Defining Tier 0.
How to use this checklist
Copy the checklists into your ticketing system with one ticket per item, an owner, and a target date inside the phase. Do not wait for a phase to be complete before starting the next one's audit work: turning on NTLM or LDAP auditing on day 10 means you have a month of data when enforcement comes around on day 45.
Treat the order as a default, not a rule. If your PingCastle report shows a critical finding — DCSync rights for Everyone, an ESC1 template enrollable by Domain Users, a Domain Admin password unchanged since 2011 — fix it today, whatever phase it falls in. Likewise, if an item does not apply (no AD CS, no trusts), mark it as not applicable with a short note so the next auditor knows it was considered.
Finally, report progress with the numbers you captured before you started. A falling assessment score and a shrinking count of attack paths to Domain Admins are what justify the next round of investment, and they are much more persuasive than a list of GPOs changed.
Related reading: Tier 0 & Privileged Access, Kerberos & Authentication, Delegation, NTLM & Legacy Protocols, AD Certificate Services, Group Policy & SYSVOL, Domain Controller Hardening, Object & ACL Security, Passwords & Service Accounts, Trusts & Forest Design, Auditing, Logging & Detection, Assessment, Backup & Recovery.
Frequently asked questions
Can a small IT team really finish this in 90 days?
Most teams finish the first 30 days fully and make solid progress on the rest. The phases are ordered by risk reduction per hour of effort, not by calendar rigidity. If an item stalls because an application owner needs time, start it in audit mode, record the exception with an owner and a date, and move on. Ninety days of steady progress beats a perfect plan that never leaves the backlog.
Do I need a tool like PingCastle or BloodHound before starting?
You need some measurement before you change anything, and PingCastle is the quickest free way to get a scored baseline of a domain. BloodHound adds the attack path view that shows how the findings chain together. Neither is strictly required, but without them you are guessing at priorities and have no way to prove to management that the risk actually went down.
What if a change breaks a legacy application?
Almost every control in this checklist has an audit or logging mode: NTLM auditing, LDAP signing events, RC4 ticket events, authentication silo audit mode. Use it for two to four weeks before enforcing, fix or document what shows up, and keep a rollback GPO ready. When something truly cannot be fixed, isolate it and grant a narrow, time-boxed exception instead of weakening the whole domain.
Active Directory hardening checklist: a 30/60/90-day plan