<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>AD Hardening — Blog</title>
    <link>https://www.activedirectoryhardening.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Mon, 28 Sep 2026 17:42:59 GMT</lastBuildDate>
    <atom:link href="https://www.activedirectoryhardening.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Active Directory hardening checklist: a 30/60/90-day plan</title>
      <link>https://www.activedirectoryhardening.com/en/blog/active-directory-hardening-checklist</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/active-directory-hardening-checklist</guid>
      <description>A prioritised 30/60/90-day Active Directory hardening checklist: measure first, stop the easy domain takeovers, close relay paths, then build structure.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Attack path management with BloodHound for defenders</title>
      <link>https://www.activedirectoryhardening.com/en/blog/attack-path-management</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/attack-path-management</guid>
      <description>Use BloodHound defensively: tag Tier Zero correctly, find choke points, fix attack paths in the right order, and track exposure over time with safe collection.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Disable LLMNR, NBT-NS, mDNS and WPAD in AD</title>
      <link>https://www.activedirectoryhardening.com/en/blog/disable-llmnr-netbios-wpad</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/disable-llmnr-netbios-wpad</guid>
      <description>Remove the name-resolution fallbacks attackers poison: disable LLMNR, NetBIOS and mDNS by GPO and DHCP, and block WPAD with the DNS global query block list.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>ESAE Red Forest vs the enterprise access model in 2026</title>
      <link>https://www.activedirectoryhardening.com/en/blog/enterprise-access-model</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/enterprise-access-model</guid>
      <description>Why Microsoft retired ESAE as the default, what the enterprise access model asks you to build instead, and when a bastion forest or PAM trust still makes sense.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Writing and rehearsing an AD forest recovery plan</title>
      <link>https://www.activedirectoryhardening.com/en/blog/forest-recovery-plan</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/forest-recovery-plan</guid>
      <description>Build an Active Directory forest recovery runbook from Microsoft&apos;s guide: clean room, first DC restore, SYSVOL, FSMO, RID pool, krbtgt resets and yearly drills.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Deploying Microsoft security baselines with GPO</title>
      <link>https://www.activedirectoryhardening.com/en/blog/security-baselines-gpo</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/security-baselines-gpo</guid>
      <description>Deploy Microsoft security baselines with Group Policy: SCT, Policy Analyzer gap analysis, LGPO testing, ring-based rollout, exceptions and drift checks.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Protecting Active Directory backups from ransomware</title>
      <link>https://www.activedirectoryhardening.com/en/blog/ad-backup-ransomware</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/ad-backup-ransomware</guid>
      <description>Design AD backups that survive ransomware: system state per domain, DSRM passwords, immutable and offline copies, a backup system outside the AD it protects.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>AdminSDHolder and SDProp: cleanup and monitoring</title>
      <link>https://www.activedirectoryhardening.com/en/blog/adminsdholder-sdprop</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/adminsdholder-sdprop</guid>
      <description>Baseline the AdminSDHolder ACL, find orphaned adminCount=1 accounts, reset their ACLs safely, trigger SDProp on demand, and alert on AdminSDHolder changes.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Authentication policies and silos for Tier 0 accounts</title>
      <link>https://www.activedirectoryhardening.com/en/blog/authentication-policies-silos</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/authentication-policies-silos</guid>
      <description>Restrict where Tier 0 admins can authenticate with AD authentication policies and silos: prerequisites, claims, TGT lifetime, audit mode and enforcement.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Auditing GPO permissions and gPLink rights</title>
      <link>https://www.activedirectoryhardening.com/en/blog/gpo-permissions-audit</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/gpo-permissions-audit</guid>
      <description>Find who can edit, create and link GPOs in Active Directory: GPO ACLs, gPLink rights on OUs and sites, Group Policy Creator Owners and WMI filters.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Defending against Kerberoasting and AS-REP roasting</title>
      <link>https://www.activedirectoryhardening.com/en/blog/kerberoasting-defense</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/kerberoasting-defense</guid>
      <description>Shrink Kerberoasting and AS-REP roasting exposure: inventory SPNs, remove stale ones, move to gMSA and AES, deploy a honey SPN and detect RC4 4769 spikes.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>PingCastle assessment: from AD report to action plan</title>
      <link>https://www.activedirectoryhardening.com/en/blog/pingcastle-assessment</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/pingcastle-assessment</guid>
      <description>Run a PingCastle health check on Active Directory, read the four risk scores correctly, triage findings into owners and sprints, and track progress over time.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Finding and removing GPP passwords (cpassword)</title>
      <link>https://www.activedirectoryhardening.com/en/blog/remove-gpp-passwords</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/remove-gpp-passwords</guid>
      <description>Find every Group Policy Preferences cpassword in SYSVOL, backups and client caches, map it to the exposed account, rotate it and stop it coming back.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Audit and restrict NTLM in Active Directory</title>
      <link>https://www.activedirectoryhardening.com/en/blog/restrict-ntlm</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/restrict-ntlm</guid>
      <description>A step-by-step NTLM reduction plan: audit with events 8001-8004, fix the causes, build an exception list, remove NTLMv1 and set LmCompatibilityLevel 5.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SID filtering and selective authentication, step by step</title>
      <link>https://www.activedirectoryhardening.com/en/blog/sid-filtering-selective-authentication</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/sid-filtering-selective-authentication</guid>
      <description>Configure and verify SID filtering, quarantine and selective authentication on AD trusts with netdom and PowerShell, including trustAttributes and events.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Cleaning up SIDHistory after AD migrations</title>
      <link>https://www.activedirectoryhardening.com/en/blog/sid-history-cleanup</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/sid-history-cleanup</guid>
      <description>Find, assess and safely remove sIDHistory left over from domain migrations: dangerous SIDs, ACL re-permissioning, staged removal, rollback limits and detection.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Require SMB signing and disable SMBv1 domain-wide</title>
      <link>https://www.activedirectoryhardening.com/en/blog/smb-signing-enforcement</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/smb-signing-enforcement</guid>
      <description>Enforce SMB signing on clients and servers, understand Windows 11 24H2 and Server 2025 defaults, audit SMBv1 use, and remove it without breaking file access.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Finding and removing DCSync rights in Active Directory</title>
      <link>https://www.activedirectoryhardening.com/en/blog/dcsync-rights-audit</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/dcsync-rights-audit</guid>
      <description>Audit who holds DS-Replication-Get-Changes-All and equivalent rights on the domain root, remove the ones that should not exist, and alert on DCSync.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Firewalling domain controllers: ports, egress, admin access</title>
      <link>https://www.activedirectoryhardening.com/en/blog/domain-controller-firewall</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/domain-controller-firewall</guid>
      <description>Build a domain controller firewall policy: required AD ports, restricted RPC, no internet egress, and RDP/WinRM only from Tier 0 PAWs. Measure first.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>AD honeytokens: honey accounts, honey SPNs and decoys</title>
      <link>https://www.activedirectoryhardening.com/en/blog/honeytokens-deception</link>
      <guid isPermaLink="true">https://www.activedirectoryhardening.com/en/blog/honeytokens-deception</guid>
      <description>Deploy honey accounts, honey SPNs, AS-REP decoys, fake GPP passwords and read-audited decoy objects in AD, and alert on them with near-zero false positives.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>