
Assess threat landscape for domain controllers and implement network protections, authentication defenses, and measures against denial of service, OS and application attack surfaces, to secure your Active Directory.
Experience a hands-on kerberoasting attack demonstration creating a vulnerable service account with SPN, using PowerShell and Mimikatz to export, analyze, and crack Kerberos tickets offline, with detection strategies.
Demonstrates a kerberoasting attack using Mimikatz to extract a Kerberos service ticket, convert it to a crackable hash, and crack offline, while auditing and tracing Kerberos activity in Active Directory.
Prevent kerberoasting by enforcing aes encryption for kerberos tickets and deploying gmsa, while monitoring event logs and using PowerShell to detect suspicious ticket requests.
Install and use nmap to assess a domain controller's security by listing open ports and services, performing OS fingerprinting and vulnerability scanning to reveal Windows Server 2022 risks.
Explore key security risks facing Active Directory domain controllers and learn to identify and mitigate threats, including authentication credentials, denial-of-service, elevation of privilege, wireless certificates, updates, and physical security.
Centralize domain controller security management with group policy objects, applying default domain policy and custom gpos, audit and account policies, plus standardized event log retention.
Enforce restricted groups and system service controls via group policy; implement consistent firewall rules, PKI policies, and advanced audit policy configuration across Windows Server 2025 domain controllers.
Explore knowledge-check questions on configuring Active Directory domain controller security with GPOs, covering default domain controllers policy, custom GPOs, account policies, restricted groups, auditing, and identical security log retention.
Configure and verify domain controller security policies by practicing password length, audit settings, and log size adjustments, updating policies, and reviewing security events in Event Viewer.
Configure a custom GPO for domain controllers to enforce restricted groups and restrict remote desktop access to selected users, while disabling unnecessary services like the printer spooler.
Explore practical domain controller security with a custom GPO in Windows Server 2025, configuring advanced audit policies, security options, interactive logon, and Kerberos enhancements.
Configure domain controller security in Active Directory with Group Policy Management Console, enforce minimum password length, monitor logon events (4624), apply restricted groups, use gpupdate /force, and disable unnecessary services.
Create a new custom GPO for domain controllers instead of modifying the default policy, to easily revert changes, improve organization, preserve defaults, and support change management.
Understand the benefits of custom GPOs for domain controllers, including preserving default settings and simplifying troubleshooting. Learn the GPO processing order and why documentation aids change management.
Implement secure authentication in Active Directory by securing user accounts and passwords, managing elevated groups, and enabling multi-factor authentication, audit controls, and deprovisioning workflows.
Reinforce secure authentication in a domain environment by evaluating two-factor authentication, secure admin practices, deprovisioning, IPsec, client security updates, and device health attestation.
Secure physical access to domain controllers to safeguard credentials in Active Directory; deploy only in secure rooms, use RAW DCs where possible, enable BitLocker, and secure backups.
Learn the importance of securing physical access to domain controllers, protect credentials stored in Active Directory, and apply safeguards like read-only domain controllers, BitLocker, and secure backups.
Explore why branch offices deploy a read-only domain controller (RoDC) to localize authentication and limit credential exposure. Note password replication policy, unidirectional replication, one RoDC per site, and key limitations.
Explore the security advantages of read-only domain controllers in branch offices, including password replication policies, inbound replication only, and deployment considerations for authentication.
Deploy a read-only domain controller (RODC) using the Active Directory Domain Services configuration wizard remotely or via PowerShell, with two-step deployment and delegated promotion, and plan a password replication policy.
Explore how read-only domain controllers cache credentials using the password replication policy, detailing allowed and denied lists, per-RODC and domain-wide groups, and the RODC filtered attribute set.
Demonstrates staging a delegated rodc installation, viewing and configuring a rodc-specific password replication policy, and verifying the resulting policy within Active Directory Domain Services.
Delegate RoDC local administrators using admin role separation to perform maintenance without granting domain rights. Configure delegation during RoDC installation or on the Delegation of RoDC Installation and Administration pages.
Apply best practices for securing active directory by reducing entry points and safeguarding against credential theft. Enforce least-privilege administration, secure domain controllers, and use multi-factor authentication and secure administrative hosts.
Develop best practices for securing Active Directory by enforcing least privilege, securing administrative hosts, ensuring up-to-date antivirus deployments, and monitoring sensitive objects to reduce attack surfaces.
Explore how Windows Server 2016 and later strengthens Active Directory security with password policies, account lockout, Kerberos settings, and fine-grained PSOs, plus Windows Hello and MFA options.
Explore user rights in Windows Server, how they govern system-level actions like logon locally, backup, and shutdown, and how they differ from resource permissions within local or domain policies.
Master how user rights empower system-wide actions in Windows Server, distinguish them from permissions, and configure them via local security policy or group policy to enforce least privilege.
Learn best practices for managing user rights on Windows Server, applying the principle of least privilege, auditing rights, using built in groups, and documenting changes to prevent privilege escalation.
Explore best practices for managing user rights on Windows Server, including least privilege, remote access controls, auditing with Security Configuration and Analysis, and documenting changes.
Configure user rights and account security options in Windows Server with the Local Security Policy tool, assigning rights such as log on locally to enforce least privilege.
Enforce strong password policies with complexity, expiration, and history; configure account lockout thresholds to deter brute-force attempts, then test user rights and policy effectiveness on Windows Server.
Configure password policy, account lockout, and Kerberos policy in Active Directory Domain Services. Use Group Policy Management Console to enforce password history, age, length, and complexity.
Test your understanding of Active Directory password policies, including enforce password history, age limits, and complexity. Learn where domain policies apply and the recommended minimum length of 10 characters.
Configure account lockout policies with thresholds and durations to deter brute-force attacks, implement auto-unlock rules, monitor failed sign-ins, and balance security with potential DoS risks, and Kerberos policies.
Learn how account lockout policies protect Active Directory environments by detecting brute-force attempts and preventing denial-of-service through proper lockout threshold and duration, especially for high-security accounts.
Configure Kerberos policy settings at the domain level to manage ticket lifetimes, TGTs, and clock synchronization, and enable claims-based authentication with dynamic access control.
Explore Kerberos policies that enable single sign-on, enforce user logon restrictions, manage ticket lifetimes, time synchronization tolerance, and claims and compound authentication with Kerberos.
Configure a domain-based password policy and an account lockout policy using Group Policy Management, setting history 20, max age 45, length 10, complexity enabled, and 30-minute lockout with 15-minute reset.
Explore restricted groups in group policy to control local group memberships on servers and workstations, with updates and administrator exceptions, and review the protected users group and its authentication constraints.
Reinforce your understanding of restricted groups and protected users in AD DS, including membership controls, NTLM restrictions, and Kerberos pre-auth encryption exclusions.
Implement fine-grained password policies by linking PSOs to users or groups, managed via the password settings container, with domain functional level at least Windows Server 2008.
This lecture explains how password settings objects enable fine-grained policies by applying multiple domain policies to different users or groups, stored in the Password Settings Container.
Learn to create and apply fine-grained password policies (PSOs) in Active Directory, configuring complexity, password length and age, history, encryption, and lockout settings via PowerShell or Active Directory Administrative Center.
Explore knowledge-check questions on fine-grained password policies (PSOs): password history, precedence, tools like ADAC, linking PSOs to groups, lockout behavior, and complexity settings.
Configure a fine-grained password policy with a password settings object for adatum\manager, setting length, history, complexity, age, and lockout. Demonstrate PSO precedence and resultant PSO behavior.
Link multiple PSOs to a user or group; ADDS computes the resultant PSO using the lowest MSDS-PasswordSettingsPrecedence value, then the smallest object grid, otherwise the default domain policy.
Discover how Active Directory determines the effective PSO when multiple sources apply, using precedence and the object grid as a tie-breaker, and how to view the MSDS resultant attribute.
Explore configuring Kerberos ticket lifetimes, including 240-minute TGTs, domain defaults, and protected users' four-hour limits, then implement authentication policies and silos with DEC claims for targeted access.
Explore how protected users mitigate credential theft by preventing local caching, enforce stronger Kerberos pre-authentication, and apply authentication policies and silos in Active Directory domain services.
Configure ADDS user account policies with local security policy and domain group policy, covering password, Kerberos, and lockout settings, noting default domain policy governs and may override local settings.
Explore configuring user account policies in an Active Directory domain services environment, covering local security policy, group policy precedence, Kerberos, password and account lockout policies, and the default domain policy.
Configure auditing for active directory domain services by setting policies, auditing objects, and viewing security logs, and describe account logon and logoff events on Windows Server 2016 domain controllers.
Explore the differences between account logon events and logon events, and learn how advanced and basic audit policies shape auditing on domain controllers and computer logons.
Configure and verify authentication audits in Group Policy, enabling success and failure events for account logon and Kerberos authentication, then view event IDs 4771 and 4768 in Event Viewer.
Define the scope of GPOs to apply your audit policies to systems, configuring log on event auditing and account log on event auditing for remote desktop servers and domain controllers.
Explore how managed service accounts and group MSAs in Windows Server 2016 simplify and secure Active Directory service authentication for applications and background processes, with Kerberos, delegation, and SPNs.
Explore built-in local service accounts such as local system, local service, and network service. Contrast them with domain admin accounts and highlight security risks and the need for security analysis.
Explore the challenges of using service accounts for programs like SQL Server and IIS, including domain versus local accounts, password management, SPN administration, and MSA in Windows Server 2016.
Understand managed service accounts (MSAs) for automatic password and SPN management, required Windows Server 2008 R2 or newer, and the KDS root key steps on Server 2016.
Use group MSAs to extend MSA functionality across multiple servers. Requirements include a 2012+ domain controller and Windows 8+ clients, plus a KDS root key.
Demonstrate configuring group managed service accounts in Active Directory, including creating and associating an MSA, installing it on a server, and configuring its logon for a service.
Implement security policies for accounts and passwords, deploy an RODC, establish auditing, and evaluate a group MSA for test-server AD DS authentication.
Configure password policies and restricted groups to protect IT administrators and local administrator accounts. Enable auditing to monitor changes to domain admins and security groups.
This lab guides deploying a read-only domain controller, configuring a password replication policy, and creating a managed service account, then securing an IIS app pool with that account.
Configure a PSO to centrally manage domain and administrator password policies, set a low precedence such as 10, and link it to the domain users group for a single interface.
Emphasize physical security for domain controllers, implement consistent auditing via the default domain controllers policy or a GPO, and assess account lockout considerations for Outlook Web Access.
Explore common attack techniques, including malware (viruses, trojans, ransomware, spyware) and phishing, and learn how social engineering, denial of service, password attacks, insider threats, and advanced persistent threats threaten organizations.
Explore vulnerabilities and attack types that threaten Windows Server security, including ransomware, malware, denial of service attacks, zero-day exploits, and man-in-the-middle attacks, with examples like zero-logon and elevation of privilege.
Explore pass-the-hash attacks as credential theft using password hashes to authenticate across systems, enabling lateral movement, and apply defenses like least privilege, multi-factor authentication, network segmentation, and credential guards.
Install and configure sysmon on the LeadSRV1 server to monitor process creation, network connections, and file creation time, then analyze Windows event logs for correlation across logon sessions.
Learn how Sysmon logs Windows event IDs—process creation, network connections, service state changes, registry value sets, and DNS queries—to monitor and detect malicious activity.
Discover how AutoRuns reveals startup programs and autostart locations on Windows, including startup folders and registry keys, and how to analyze, disable, and verify entries.
install and use logon sessions to view active Windows logon sessions for security analysis and troubleshooting, with details on domain, user, authentication method, and built-in administrator RID 500.
Explore Windows processes with Process Explorer to inspect handles, loaded DLLs, CPU usage, environment variables, and command lines; manage, dump, and analyze processes for troubleshooting.
Retire SMB v1 and deploy SMB v2/v3 with encryption, signing, pre-authentication integrity, and secure dialect negotiation, to guard against man-in-the-middle attacks, configurable via PowerShell or group policy.
Audit SMB v1 usage and learn how to enable it when needed, explore SMB v2/3 security, and implement signing and encryption on shares using group policy and registry settings.
Demonstrates configuring SMB signing and encryption across a domain using group policy and PowerShell to prevent man-in-the-middle attacks, negotiate signing, enable encryption, and reject unencrypted access.
Examine NTLM security, including LAN Manager version 1 and version 2 challenge-response, hash formats, pass-the-hash attacks, and the shift toward Kerberos for stronger network authentication.
Audit ntlm usage across the domain by enabling deep auditing and reviewing event id 4624 for ntlm v1 devices. Enforce ntlm v2 via group policy and audit before restricting ntlm.
Explore DNS vulnerabilities from lack of authentication and integrity, including DNS spoofing and cache poisoning. Learn how dedsec uses digital signatures, rrsig records, and zone signing to validate DNS responses.
implement dnssec to secure the section company dot primary zone between the primary domain controller and dc two, configure signing keys and trust anchors, and verify via powershell.
Manage servers from a Windows Admin Center app, connect on-premises to Azure for monitoring, storage, backup, and disaster recovery, and deploy via local client, gateway, managed server, or failover cluster.
Explore secure server management with Windows Admin Center, connect to the primary domain controller, and manage Active Directory objects, extensions, PowerShell, and remote sessions.
Explore tiered administration model for Active Directory, from tier zero to tier two, including red forest concept, separate admin accounts, and a privileged access workstation to prevent cross-tier credential exposure.
Explore the microsoft tiering model for active directory, from tier 0 domain controllers to tier 2 workstations, and how credential protections and cloud services limit lateral movement.
Add the domain admin to the protected users group to disable ntlm, prevent pass-the-hash attacks, and enforce kerberos authentication with no local credential caching.
Contain high-privileged credentials by configuring authentication policies and silos in Active Directory, using domain services, the Active Directory Administrative Center, or PowerShell, with strict ticket lifetime and access controls.
Protect privileged accounts by creating an authentication policy and silo in the Active Directory Administrative Center, assign domain admins and domain controllers, and enforce logins only to the domain controller.
The local admin password solution (laps) randomizes the local admin password, and only manages that account. It integrates with Active Directory on domain machines via a client-side extension.
Install laps on management server and extend AD schema, granting read and reset rights to admins and readers; then configure a labs policy on the servers OU to enforce laps.
Install the LAPS client side extension via the installer or by registering the DLL, with the installer showing absent features and manual registration activating the extension.
Obtain local admin passwords with LAPS via the Labs UI or PowerShell, view and convert expiration times in AD attributes, and enforce read vs reset permissions with auditing.
Credential Guard uses virtualization based security to isolate secrets, protecting password hashes and Kerberos tickets from pass-the-hash and pass-the-ticket attacks, requiring Hyper-V and hardware like secure boot and TPM 1.2.
Run the Microsoft hardware readiness PowerShell script to assess hardware compatibility for credential guard and device guard, verify TPM, secure boot, and drivers, and enable via script or group policy.
Enable credential guard using group policy to turn on virtualization-based security, secure boot, and DMA protection, configure UEFI lock and secure launch, then verify isolated hash prevents pass the hash.
Configure user rights assignments in group policy to control logon methods and tasks. Deny explicit users or groups and review defaults like backup operators, guest, and everyone to reduce risk.
Explore how to configure user rights assignment in group policy to secure Windows Server, review key policies, defaults, and risks, and follow Microsoft documentation and security baselines.
Operate a privileged access workstation with the highest security configuration to secure extremely sensitive roles, enforcing the clean source principle with restricted apps, no internet, IPsec, VLANs, and firewalls.
Explore how domain functional levels in Active Directory Domain Services unlock security features, authentication policies, and protected users, guiding upgrades and secure authentication planning.
Explore AD DS domain functional levels, migrate sysvol from FRS to DFRS before upgrades, understand functional level rollback limits, and review 2025 improvements like 32k database pages for large environments.
Onboard Windows Server to Microsoft Defender Security Center using a local script or group policy, then tune Defender settings—maps, block at first sight, exclusions, and scan behavior—via policy.
Configure Windows Defender and WSUS to protect Active Directory by enabling attack surface reduction rules, controlled folder access, and network protection, and deploy Defender updates via WSUS with automatic approvals.
Configure an app locker policy via group policy to audit and enforce executable rules on servers. Test on server one and review event logs to confirm blocking when enforced.
Configure Windows Defender Application Control using the policy wizard, create a base policy in default mode, add a deny rule for seven zip, and deploy via group policy.
Copy an existing AD user as a template to quickly create new accounts, with placeholders overwritten and department and manager carried over; adjust password and require reset on first login.
Configure user rights in the default domain policy via the group policy management console, noting undefined rights apply to all domain users and can affect time, remote desktop, and shutdown.
Offline domain joining is a two-step process: provision a text file on a domain machine with join.exe, then apply it on the offline workstation to join the domain.
Unlock user accounts in Active Directory via ADUC and PowerShell, and automate with the search AD account commandlet to unlock multiple accounts quickly.
Discover how to reset Active Directory passwords for a single user with ADUC and for many users with PowerShell, including unlocking accounts and enforcing password changes at login.
Use PowerShell to query active directory, identify stale accounts by password age, disable them, and safely delete after manual review while applying the same workflow to computer accounts.
Learn to sync active directory users and computers from a csv with a powershell script. Import the csv, check existing accounts, create new users and computers, and assign group memberships.
Learn to organize Active Directory by managing containers and organizational units, creating and nesting OUs, setting default placements for users and computers, and creating groups with security or distribution scopes.
Learn to manage group memberships in Active Directory using ADUC, ADAC, and PowerShell. Audit user access, explore nested groups, and apply scopes and restricted groups via group policy and delegation.
Configure service principal names (SPNs) to link a service instance to an account with set SPN, ensuring no duplicates. Learn SPN formats for hostnames or fqdn across service types http.
Explore group managed service accounts (gMSA) and how a password-synced identity serves services across a domain, with Microsoft Key Distribution Service; learn to create and attach gMSAs via PowerShell.
Master Kerberos policy settings and constrained delegation by configuring logon restrictions, ticket lifetimes for new connections, clock synchronization with the PDC emulator, and selecting services via ADUC.
Configure virtual accounts to run local services without passwords, replacing shared local accounts; assign them by prefixing NT service and ensure auditing and cross-service access, noting potential network setup.
Review the default domain policy in the Group Policy Management console and configure history, age, length, complexity, reversible encryption, and lockout settings with ADUC or PowerShell.
Grant delegate control to an IT group to manage password resets. Create and apply fine-grained password policies, called password setting objects or pesos, with unique precedence.
Discover how to monitor and troubleshoot Active Directory replication using the sites and services console, rep admin commands (show ripple, Shoken, rep sum), and PowerShell get replication failure.
Configure password replication policies for an RODC in Active Directory by using the GUI or Rep Admin to allow or deny groups, ensuring passwords aren’t cached on remote domain controllers.
Learn to install Windows Server Backup via GUI or PowerShell, configure a backup policy including SystemState for AD and SYSVOL, specify source and network target, and start the backup.
Learn how to back up and restore Active Directory and SYSVOL using DSM, perform authoritative and non-authoritative restores, and recover the system state with Windows backup.
Enable the Active Directory Recycle Bin via ADAC or PowerShell, view deleted objects, and restore accounts across OUs with replication awareness across domain controllers.
This course is aimed to IT Pros and is supposed to give the viewer the information they need to know to get started with Active Directory (AD DS) and its key concepts. The goal is to provide coverage of AD DS components of advanced AD DS deployments, how to deploy a distributed AD DS environment and· Configure AD DS Security.
The course is targeted to help learning Active Directory and do your job more efficiently.
After completing this course, you will be able to:
· Describe how to Secure domain controllers
· Implementing account security.
· Implementing audit authentication
· Configuring managed service accounts
In your organization’s information technology (IT) infrastructure, securing Active Directory Domain Services (AD DS) domain controllers is a critical task. Domain controllers provide access to many different resources, and they contain information about users and their passwords. If a single domain controller is compromised, any objects in the same Active Directory domain or in any trusted domain are at risk of being compromised, too.
The Windows Server 2016 operating system provides features and apps that you can use to help secure your network against security threats. The operating system provides measures to secure domain controllers by minimizing their attack surface and determining their domain-controller placements. The operating system also determines the AD DS roles that are used for administration and design, and implements password security, in addition to auditing when attacks occur. You also can use domain controllers to deploy security measures to other clients and servers in your Windows-based infrastructure.
AD DS administrators must understand the threats to domain controllers and the methods that they can use to secure AD DS and its domain controllers.
Objectives
After completing this module, you will be able to:
· Secure domain controllers.
· Implement account security.
· Implement audit authentication.
· Configure managed service accounts (MSAs).