Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Active Directory: Securing Active Directory Domain Services
Highest Rated
Rating: 4.7 out of 5(764 ratings)
5,448 students

Active Directory: Securing Active Directory Domain Services

AD DS Security with Lab: domain controllers, account security, audit authentication, managed service accounts, PSO
Created byVitalii Shumylo
Last updated 8/2026
English
English [Auto],Japanese [Auto],

What you'll learn

  • Securing domain controllers
  • Security risks that can affect domain controllers
  • Modifying the security settings of domain controllers
  • What are RODCs?
  • Deploying an RODC
  • Configuring a password replication policy
  • Implementing account security
  • Password policies
  • Account lockout policies
  • Configuring a fine-grained password policy
  • Tools for creating PSOs
  • Implementing audit authentication
  • Account logon and logon events
  • Configuring managed service accounts

Course content

11 sections128 lectures13h 10m total length
  • Security risks that can affect domain controllers12:54

    Identify and defend against threats to your Windows Server domain controllers and Active Directory environment, from network security and authentication attacks to privilege escalation and physical security.

  • Kerberoasting Attack Demonstration Example: Service Account Configuration9:44

    Experience a hands-on kerberoasting attack demonstration creating a vulnerable service account with SPN, using PowerShell and Mimikatz to export, analyze, and crack Kerberos tickets offline, with detection strategies.

  • Demo: Kerberoasting Attack Example: Ticket Extraction with Mimikatz11:41

    Demonstrates a kerberoasting attack using Mimikatz to extract a Kerberos service ticket, convert it to a crackable hash, and crack offline, while auditing and tracing Kerberos activity in Active Directory.

  • Demo: Kerberoasting Prevention via AES Encryption and GMSA Implementation9:09

    Prevent kerberoasting by enforcing aes encryption for kerberos tickets and deploying gmsa, while monitoring event logs and using PowerShell to detect suspicious ticket requests.

  • Demo: Network Security Assessment on Domain Controllers Using Nmap10:40

    Install and use nmap to assess a domain controller's security by listing open ports and services, performing OS fingerprinting and vulnerability scanning to reveal Windows Server 2022 risks.

  • Knowledge Check: Security risks that can affect domain controllers7:11

    Explore knowledge checks on security risks to Active Directory and domain controllers, including authentication credentials, denial of service, elevation of privilege, and protections via certificates, updates, and physical security.

  • Domain Controller Security Fundamentals via GPO Management9:19

    Centralize domain controller security management with group policy objects, applying default domain policy and custom gpos, audit and account policies, plus standardized event log retention.

  • Advanced Security Controls for Enterprise Infrastructure11:56

    Configure restricted groups via group policy to protect critical security groups from unauthorized changes. Implement system services, Windows firewall, PKI policies, and advanced audit configuration with clear documentation.

  • Knowledge Check: Modifying the security settings of domain controllers7:45

    Explore knowledge-check questions on configuring Active Directory domain controller security with GPOs, covering default domain controllers policy, custom GPOs, account policies, restricted groups, auditing, and identical security log retention.

  • Demo Example 1: Configuring and Verifying Domain Controller Security Policies5:14

    Configure and verify domain controller security policies by practicing password length, audit settings, and log size adjustments, updating policies, and reviewing security events in Event Viewer.

  • Demo Example 2: Configuring Custom Security Policies for Domain Controllers7:07

    Configure a custom GPO for domain controllers to enforce restricted groups and restrict remote desktop access to selected users, while disabling unnecessary services like the printer spooler.

  • Demo Example 3: Windows Server 2025 Practical Implementation of DC Security11:47

    Explore practical domain controller security with a custom GPO in Windows Server 2025, configuring advanced audit policies, security options, interactive logon, and Kerberos enhancements.

  • Knowledge Check: Configuring and Verifying Domain Controller Security Policies6:40

    Master domain controller security policies with Group Policy Objects using the Group Policy Management Console, covering minimum password length, logon event IDs, restricted groups, gpupdate /force, and disabling unnecessary services.

  • Scripts to create lab users1:19
  • Benefits of Custom GPOs for Domain Controllers: Best Practices and Consideration3:38

    Explore why creating a custom GPO for domain controllers preserves defaults, improves organization, enables granular control, and supports change management over the default policy.

  • Knowledge Check: Benefits of Custom GPOs for Domain Controllers: Best Practices7:38

    Explore best practices for using custom GPOs with domain controllers, learn the processing order and last-applied policy wins, and understand how to document settings for change management.

  • Implementing secure authentication8:04

    Implement secure authentication in Active Directory by hardening user accounts and passwords, guarding elevated groups, and enforcing two-factor or smart card authentication, with network protection, deprovisioning, and client device security.

  • Knowledge Check: Implementing secure authentication9:33

    Explore secure authentication in Active Directory by answering knowledge-check questions on two-factor authentication, elevated-permissions group practices, de-provisioning, IPsec, client security, and device health attestation.

  • Securing physical access to domain controllers3:48

    Secure physical access to domain controllers to safeguard credentials in Active Directory; deploy only in secure rooms, use RAW DCs where possible, enable BitLocker, and secure backups.

  • Knowledge Check: Securing physical access to domain controllers8:30

    Focus on securing domain controllers through physical security, read-only domain controllers in less secure environments, BitLocker encryption, hotswap disk monitoring, secure backups, and securing virtual disks.

  • What are RODCs?11:36

    Explore how a read-only domain controller (RODC) serves branch offices by caching select credentials via a password replication policy, enabling local authentication with inbound replication only.

  • Knowledge Check: What is RODC?9:00

    Explore the security benefits and limitations of read-only domain controllers for branch offices, including password replication policies and inbound replication. Assess deployment factors like bandwidth and secure housing.

  • Deploying an RODC3:32

    Deploy a read-only domain controller (rodc) remotely using the active directory domain services configuration wizard or powershell, with one-step or two-step deployment and delegated promotion, including password replication policy planning.

  • Planning and configuring an RODC password replication policy6:17

    Plan and configure an RODC password replication policy by defining allowed and denied lists and their precedence. Understand branch office caching and RODC filtered attribute sets to protect sensitive data.

  • Demonstration: Configuring a password replication policy7:56

    Configure and verify a ROTC password replication policy for a read-only domain controller in Active Directory, staging a delegated installation and validating outcomes in the Active Directory Administrative Center.

  • Separating RODC local administration2:44

    Implement role-separation for RODC local administration by delegating domain users or groups as root local administrators, enabling maintenance tasks without broader domain access.

  • Best Practices for Securing Active Directory10:36

    Apply best practices for securing active directory by reducing entry points and safeguarding against credential theft. Enforce least-privilege administration, secure domain controllers, and use multi-factor authentication and secure administrative hosts.

  • Knowledge Check: Best Practices for Securing Active Directory7:28

    Develop best practices for securing Active Directory by enforcing least privilege, securing administrative hosts, ensuring up-to-date antivirus deployments, and monitoring sensitive objects to reduce attack surfaces.

Requirements

  • Familiarity with general Windows and Microsoft server administration and technologies

Description

This course is aimed to IT Pros and is supposed to give the viewer the information they need to know to get started with Active Directory (AD DS) and its key concepts. The goal is to provide coverage of AD DS components of advanced AD DS deployments, how to deploy a distributed AD DS environment and· Configure AD DS Security.

The course is targeted to help learning Active Directory and do your job more efficiently. 

After completing this course, you will be able to:

· Describe how to Secure domain controllers

· Implementing account security.

· Implementing audit authentication

· Configuring managed service accounts


In your organization’s information technology (IT) infrastructure, securing Active Directory Domain Services (AD DS) domain controllers is a critical task. Domain controllers provide access to many different resources, and they contain information about users and their passwords. If a single domain controller is compromised, any objects in the same Active Directory domain or in any trusted domain are at risk of being compromised, too.

The Windows Server 2016 operating system provides features and apps that you can use to help secure your network against security threats. The operating system provides measures to secure domain controllers by minimizing their attack surface and determining their domain-controller placements. The operating system also determines the AD DS roles that are used for administration and design, and implements password security, in addition to auditing when attacks occur. You also can use domain controllers to deploy security measures to other clients and servers in your Windows-based infrastructure.

AD DS administrators must understand the threats to domain controllers and the methods that they can use to secure AD DS and its domain controllers.


Objectives

After completing this module, you will be able to:

· Secure domain controllers.

· Implement account security.

· Implement audit authentication.

· Configure managed service accounts (MSAs).

Who this course is for:

  • Active Directory Administrators
  • Windows Server Administrators
  • IT Specialists
  • Security Specialists