Area 07 / 12
Domain Controller Hardening
Domain controllers are the domain: any code execution or authentication coercion on a DC is game over. This area applies the DC security baseline, disables the Print Spooler, restricts who can log on locally and over RDP, and prioritises the patches for ZeroLogon, PetitPotam and the PrintNightmare family.
Start the pathLearning path
0/4 done- 01Domain controller hardening: the DC baselineA practical checklist for hardening domain controllers: security baselines, Print Spooler, logon rights, RDP, egress, and patch priorities.
- 02Blocking authentication coercion on domain controllersShut down PrinterBug, PetitPotam, DFSCoerce and ShadowCoerce on DCs with RPC filters, service reduction and relay-proof targets, then verify it holds.
- 03Netlogon secure channel hardening after ZeroLogonEnforce Netlogon secure RPC and sealing after ZeroLogon and CVE-2022-38023: audit events 5827-5831 and 5838-5839, empty the allowlist, verify.
- 04Firewalling domain controllers: ports, egress, admin accessBuild a domain controller firewall policy: required AD ports, restricted RPC, no internet egress, and RDP/WinRM only from Tier 0 PAWs. Measure first.