Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Active Directory: Securing Active Directory Domain Services
Highest Rated
Rating: 4.6 out of 5(784 ratings)
5,562 students

Active Directory: Securing Active Directory Domain Services

AD DS Security with Lab: domain controllers, account security, audit authentication, managed service accounts, PSO
Created byVitalii Shumylo
Last updated 9/2026
English
EnglishJapanese [Auto],

What you'll learn

  • Securing domain controllers
  • Security risks that can affect domain controllers
  • Modifying the security settings of domain controllers
  • What are RODCs?
  • Deploying an RODC
  • Configuring a password replication policy
  • Implementing account security
  • Password policies
  • Account lockout policies
  • Configuring a fine-grained password policy
  • Tools for creating PSOs
  • Implementing audit authentication
  • Account logon and logon events
  • Configuring managed service accounts

Course content

11 sections • 129 lectures • 13h 12m total length
  • Security risks that can affect domain controllers12:54

    Assess threat landscape for domain controllers and implement network protections, authentication defenses, and measures against denial of service, OS and application attack surfaces, to secure your Active Directory.

  • Kerberoasting Attack Demonstration Example: Service Account Configuration9:44

    Experience a hands-on kerberoasting attack demonstration creating a vulnerable service account with SPN, using PowerShell and Mimikatz to export, analyze, and crack Kerberos tickets offline, with detection strategies.

  • Demo: Kerberoasting Attack Example: Ticket Extraction with Mimikatz11:41

    Demonstrates a kerberoasting attack using Mimikatz to extract a Kerberos service ticket, convert it to a crackable hash, and crack offline, while auditing and tracing Kerberos activity in Active Directory.

  • Demo: Kerberoasting Prevention via AES Encryption and GMSA Implementation9:09

    Prevent kerberoasting by enforcing aes encryption for kerberos tickets and deploying gmsa, while monitoring event logs and using PowerShell to detect suspicious ticket requests.

  • Demo: Network Security Assessment on Domain Controllers Using Nmap10:41

    Install and use nmap to assess a domain controller's security by listing open ports and services, performing OS fingerprinting and vulnerability scanning to reveal Windows Server 2022 risks.

  • Knowledge Check: Security risks that can affect domain controllers7:15

    Explore key security risks facing Active Directory domain controllers and learn to identify and mitigate threats, including authentication credentials, denial-of-service, elevation of privilege, wireless certificates, updates, and physical security.

  • Domain Controller Security Fundamentals via GPO Management9:19

    Centralize domain controller security management with group policy objects, applying default domain policy and custom gpos, audit and account policies, plus standardized event log retention.

  • Advanced Security Controls for Enterprise Infrastructure11:56

    Enforce restricted groups and system service controls via group policy; implement consistent firewall rules, PKI policies, and advanced audit policy configuration across Windows Server 2025 domain controllers.

  • Knowledge Check: Modifying the security settings of domain controllers7:49

    Explore knowledge-check questions on configuring Active Directory domain controller security with GPOs, covering default domain controllers policy, custom GPOs, account policies, restricted groups, auditing, and identical security log retention.

  • Demo Example 1: Configuring and Verifying Domain Controller Security Policies5:14

    Configure and verify domain controller security policies by practicing password length, audit settings, and log size adjustments, updating policies, and reviewing security events in Event Viewer.

  • Demo Example 2: Configuring Custom Security Policies for Domain Controllers7:07

    Configure a custom GPO for domain controllers to enforce restricted groups and restrict remote desktop access to selected users, while disabling unnecessary services like the printer spooler.

  • Demo Example 3: Windows Server 2025 Practical Implementation of DC Security11:47

    Explore practical domain controller security with a custom GPO in Windows Server 2025, configuring advanced audit policies, security options, interactive logon, and Kerberos enhancements.

  • Knowledge Check: Configuring and Verifying Domain Controller Security Policies6:42

    Configure domain controller security in Active Directory with Group Policy Management Console, enforce minimum password length, monitor logon events (4624), apply restricted groups, use gpupdate /force, and disable unnecessary services.

  • Scripts to create lab users1:19
  • Benefits of Custom GPOs for Domain Controllers: Best Practices and Consideration3:36

    Create a new custom GPO for domain controllers instead of modifying the default policy, to easily revert changes, improve organization, preserve defaults, and support change management.

  • Knowledge Check: Benefits of Custom GPOs for Domain Controllers: Best Practices7:42

    Understand the benefits of custom GPOs for domain controllers, including preserving default settings and simplifying troubleshooting. Learn the GPO processing order and why documentation aids change management.

  • Implementing secure authentication8:04

    Implement secure authentication in Active Directory by securing user accounts and passwords, managing elevated groups, and enabling multi-factor authentication, audit controls, and deprovisioning workflows.

  • Knowledge Check: Implementing secure authentication9:41

    Reinforce secure authentication in a domain environment by evaluating two-factor authentication, secure admin practices, deprovisioning, IPsec, client security updates, and device health attestation.

  • Securing physical access to domain controllers3:48

    Secure physical access to domain controllers to safeguard credentials in Active Directory; deploy only in secure rooms, use RAW DCs where possible, enable BitLocker, and secure backups.

  • Knowledge Check: Securing physical access to domain controllers8:35

    Learn the importance of securing physical access to domain controllers, protect credentials stored in Active Directory, and apply safeguards like read-only domain controllers, BitLocker, and secure backups.

  • What are RODCs?11:36

    Explore why branch offices deploy a read-only domain controller (RoDC) to localize authentication and limit credential exposure. Note password replication policy, unidirectional replication, one RoDC per site, and key limitations.

  • Knowledge Check: What is RODC?9:07

    Explore the security advantages of read-only domain controllers in branch offices, including password replication policies, inbound replication only, and deployment considerations for authentication.

  • Deploying an RODC3:32

    Deploy a read-only domain controller (RODC) using the Active Directory Domain Services configuration wizard remotely or via PowerShell, with two-step deployment and delegated promotion, and plan a password replication policy.

  • Planning and configuring an RODC password replication policy6:17

    Explore how read-only domain controllers cache credentials using the password replication policy, detailing allowed and denied lists, per-RODC and domain-wide groups, and the RODC filtered attribute set.

  • Demonstration: Configuring a password replication policy7:56

    Demonstrates staging a delegated rodc installation, viewing and configuring a rodc-specific password replication policy, and verifying the resulting policy within Active Directory Domain Services.

  • Separating RODC local administration2:44

    Delegate RoDC local administrators using admin role separation to perform maintenance without granting domain rights. Configure delegation during RoDC installation or on the Delegation of RoDC Installation and Administration pages.

  • Best Practices for Securing Active Directory10:36

    Apply best practices for securing active directory by reducing entry points and safeguarding against credential theft. Enforce least-privilege administration, secure domain controllers, and use multi-factor authentication and secure administrative hosts.

  • Knowledge Check: Best Practices for Securing Active Directory7:32

    Develop best practices for securing Active Directory by enforcing least privilege, securing administrative hosts, ensuring up-to-date antivirus deployments, and monitoring sensitive objects to reduce attack surfaces.

Requirements

  • Familiarity with general Windows and Microsoft server administration and technologies

Description

This course is aimed to IT Pros and is supposed to give the viewer the information they need to know to get started with Active Directory (AD DS) and its key concepts. The goal is to provide coverage of AD DS components of advanced AD DS deployments, how to deploy a distributed AD DS environment and· Configure AD DS Security.

The course is targeted to help learning Active Directory and do your job more efficiently. 

After completing this course, you will be able to:

· Describe how to Secure domain controllers

· Implementing account security.

· Implementing audit authentication

· Configuring managed service accounts


In your organization’s information technology (IT) infrastructure, securing Active Directory Domain Services (AD DS) domain controllers is a critical task. Domain controllers provide access to many different resources, and they contain information about users and their passwords. If a single domain controller is compromised, any objects in the same Active Directory domain or in any trusted domain are at risk of being compromised, too.

The Windows Server 2016 operating system provides features and apps that you can use to help secure your network against security threats. The operating system provides measures to secure domain controllers by minimizing their attack surface and determining their domain-controller placements. The operating system also determines the AD DS roles that are used for administration and design, and implements password security, in addition to auditing when attacks occur. You also can use domain controllers to deploy security measures to other clients and servers in your Windows-based infrastructure.

AD DS administrators must understand the threats to domain controllers and the methods that they can use to secure AD DS and its domain controllers.


Objectives

After completing this module, you will be able to:

· Secure domain controllers.

· Implement account security.

· Implement audit authentication.

· Configure managed service accounts (MSAs).

Who this course is for:

  • Active Directory Administrators
  • Windows Server Administrators
  • IT Specialists
  • Security Specialists