Area 06 / 12
Group Policy & SYSVOL
Anyone who can edit a GPO linked to a domain controller can own the domain. This area reviews GPO delegation and linking rights, removes the cpassword secrets left by Group Policy Preferences (MS14-025), and checks SYSVOL for insecure permissions and scripts.
Start the pathLearning path
0/4 done- 01Group Policy and SYSVOL hardeningLock down GPO delegation, purge Group Policy Preferences cpassword secrets from SYSVOL, and add change control to prevent silent GPO abuse.
- 02Auditing GPO permissions and gPLink rightsFind who can edit, create and link GPOs in Active Directory: GPO ACLs, gPLink rights on OUs and sites, Group Policy Creator Owners and WMI filters.
- 03Finding and removing GPP passwords (cpassword)Find every Group Policy Preferences cpassword in SYSVOL, backups and client caches, map it to the exposed account, rotate it and stop it coming back.
- 04Deploying Microsoft security baselines with GPODeploy Microsoft security baselines with Group Policy: SCT, Policy Analyzer gap analysis, LGPO testing, ring-based rollout, exceptions and drift checks.