Sitemap
All pages on AD Hardening.
Home
Hardening map
- 01 · Tier 0 & Privileged Access
- 02 · Kerberos & Authentication
- 03 · Delegation
- 04 · NTLM & Legacy Protocols
- 05 · AD Certificate Services
- 06 · Group Policy & SYSVOL
- 07 · Domain Controller Hardening
- 08 · Object & ACL Security
- 09 · Passwords & Service Accounts
- 10 · Trusts & Forest Design
- 11 · Auditing, Logging & Detection
- 12 · Assessment, Backup & Recovery
Guides
- Active Directory hardening checklist: a 30/60/90-day plan
- Attack path management with BloodHound for defenders
- Disable LLMNR, NBT-NS, mDNS and WPAD in AD
- ESAE Red Forest vs the enterprise access model in 2026
- Writing and rehearsing an AD forest recovery plan
- Deploying Microsoft security baselines with GPO
- Protecting Active Directory backups from ransomware
- AdminSDHolder and SDProp: cleanup and monitoring
- Authentication policies and silos for Tier 0 accounts
- Auditing GPO permissions and gPLink rights
- Defending against Kerberoasting and AS-REP roasting
- PingCastle assessment: from AD report to action plan
- Finding and removing GPP passwords (cpassword)
- Audit and restrict NTLM in Active Directory
- SID filtering and selective authentication, step by step
- Cleaning up SIDHistory after AD migrations
- Require SMB signing and disable SMBv1 domain-wide
- Finding and removing DCSync rights in Active Directory
- Firewalling domain controllers: ports, egress, admin access
- AD honeytokens: honey accounts, honey SPNs and decoys
- Rotating the krbtgt password safely in Active Directory
- Enforce LDAP signing and channel binding on DCs
- Set ms-DS-MachineAccountQuota to 0 and delegate joins
- AD password policy that works: length, FGPP, blocklists
- Building privileged access workstations (PAWs) for AD
- Strong certificate mapping (KB5014754) in practice
- Windows Event Forwarding for domain controllers
- Active Directory security event IDs: a DC reference
- Auditing AD CS certificate templates for ESC1-ESC4
- Securing AD CS web enrollment against ESC8 and ESC11
- Blocking authentication coercion on domain controllers
- Constrained delegation and RBCD done safely in AD
- Disable RC4 in Kerberos: audit, fix and enforce AES
- Migrating service accounts to gMSA and dMSA
- Identify Tier 0 assets: a complete AD inventory method
- Netlogon secure channel hardening after ZeroLogon
- Remove unconstrained delegation from AD servers
- Deploying Windows LAPS: schema, permissions, policy
- Auditing Active Directory ACLs before an attacker does
- Active Directory delegation: finding and fixing risky trusts
- AD assessment, backup and forest recovery
- AD auditing and detection: audit policy and event IDs
- Hardening AD trusts and forest boundaries
- AD CS hardening: closing ESC1-ESC8 misconfigurations
- Domain controller hardening: the DC baseline
- Group Policy and SYSVOL hardening
- Kerberos hardening: RC4, roasting and golden tickets
- Stop NTLM relay: LDAP, SMB signing and LLMNR
- Service account hardening: gMSA, SPNs and LAPS
- Tier 0 and privileged access: locking down Domain Admins
Glossary
- AD CS ESC8
- Authentication policy silo
- BloodHound
- Fine-grained password policy
- Honeytoken
- krbtgt
- LAPS
- LLMNR poisoning
- Machine account quota
- PetitPotam
- Privileged access workstation (PAW)
- Protected Users
- SID filtering
- SID history
- SMB signing
- Tier model
- AD CS ESC1
- AdminSDHolder
- AS-REP roasting
- DCSync
- Group managed service account (gMSA)
- Golden ticket
- Kerberoasting
- LDAP channel binding
- NTLM relay
- Pass-the-hash
- Resource-based constrained delegation
- Silver ticket
- Unconstrained delegation
- Zerologon