
Explore practical, hands-on steps to build and harden a secure Active Directory environment, including setting up virtual machines, installing Active Directory, and implementing tiering models, security baselines, and protected users.
Demonstrate how adding accounts to the protected users group changes authentication behavior, prevents plaintext password exposure, and affects memory and wdigest handling in Active Directory.
Hardening Active Directory domain joins with a dedicated join account and permissions. Set msds quota to zero and use AD probe with a PowerShell script to detect and fix ownership.
Privileged accounts are a prime target for attackers—and protecting them requires more than strong passwords.
In this focused mini-course, you’ll learn how to defend high-value accounts by implementing the Protected Users group in Active Directory. This powerful security feature applies key protections automatically, drastically reducing the risk of credential theft — with minimal configuration effort.
What You'll Learn:
What the Protected Users group does — and why it matters for privileged account security
How to configure it safely, including which admin groups to add and which to exclude
Real-world attack demos showing how this group blocks credential extraction
Compatibility considerations like NTLM support and what to test before deployment
By the end of the course, you’ll understand both the benefits and limitations of Protected Users, how it impacts authentication protocols, and how to roll it out without locking yourself out.
Whether you manage Active Directory every day or support Windows infrastructure, this quick course will give you tactical knowledge you can apply immediately.
This course is a Free Trial of the Building a Secure Active Directory course, which gives you a hands-on practical experience building and hardening your own Active Directory environment.
Thank you and enjoy the course,
David
Founder of Horizon Secured