Active Directory Hardening¶
Baseline hardening for Active Directory environments: understanding the core AD structures, securing the authentication protocols that AD relies on, implementing least privilege through account types and tiered access, applying Microsoft's official security baselines, and closing off the attack paths most commonly used against AD.
| Topic | Description |
|---|---|
| General Concepts | Domain, Domain Controller, Trees, and Forests — the structures everything else builds on. |
| Securing Authentication Methods | LAN Manager hash, SMB signing, LDAP signing, password rotation, and password policy settings. |
| Implementing the Least Privilege Model | Account types and the Tiered Access Model (Tier 0/1/2). |
| Microsoft Security Compliance Toolkit | Installing official security baselines and using the Policy Analyser. |
| Protecting Against Known Attacks | Kerberoasting, weak passwords, RDP brute-forcing, and publicly accessible shares. |