
Discover practical steps to audit Windows Server Active Directory security, including reviewing group policy, event logs, DNS, TLS, NTP, ports, and using Policy Analyzer, LDAP browser, laps, and Nmap.
Audit group policy objects via group policy management, review computer and user configurations, and compare settings to Windows security baselines, CIS benchmarks, and STIG guidelines.
Audit group policy objects using the Policy Analyzer toolkit to compare current and prior GPOs settings against Microsoft security baselines and STIG recommendations, exporting reports to Excel for analysis.
Audit Active Directory users, groups, and organizational units, and learn how distribution and security groups define access, while Group Policy Objects apply policies within OUs.
Explore how the ldap browser by ldap soft gives auditors read-only remote access to Active Directory, enabling ldap text and sql queries to review users, groups, and organizational units.
Learn to query AD objects using built-in Active Directory features by creating save queries, defining filters to display disabled users, and validating results via the SQL search option.
Audit Active Directory objects created within a custom period by listing today's users and computers, testing with new accounts, and comparing LDAP versus SQL filters for attribute display.
Audit add objects in the administrators group, listing users and groups such as a user account administrator and two groups; explore common LDAP filter examples to review AD objects.
Audit Active Directory administrative accounts by regularly reviewing enterprise admins, domain admins, and administrators groups, verify group memberships, and enforce separate accounts for elevated tasks across the forest root domain.
Audit the 'account is sensitive and cannot be delegated' option in Active Directory to protect privileged accounts and prevent delegation.
Audit the 'access this computer from the network' right by confirming it only includes administrators, authenticated users, and domain controllers, via domain controller and domain server group policy settings.
Master how to restrict the allow log on through Remote Desktop Services to the administrators group on domain controllers, and verify GPO settings to prevent misuse of high level rights.
Audit the enterprise admins group to ensure only dedicated forest management accounts are members and that only approved users belong to the group, mitigating credential theft risks.
Audit local administrator accounts to ensure unique local admin passwords on domain join systems using Microsoft Local Administrator Password Solution (LAPS) to automate password changes and control access.
Audit local administrator accounts using laps by testing domain user and domain admin access, reviewing group policy and gpo settings, and assessing password expiration and complexity.
Audit windows server ports, protocols, and services to identify open TCP/UDP ports and their associated applications, including FTP on 21, SMTP on 25, DNS on 53, and NTP on 123.
Map open ports found by nmap or port query to installed applications and services, such as 80 for web servers and 443 for https.
Run a domain server scan with Nmap to identify open ports and services, including smtp, imap, and pop3 from the mail server, and observe port 80 for the web service.
Audit ports with Microsoft Port Query using templates such as domains and trust or SQL service to scan domain controllers and SQL servers, and interpret codes 0, 1, and 2.
Audit Windows Defender Firewall with Advanced Security by reviewing inbound and outbound rules, group policy, and profiles (domain, private, public), ensuring default inbound block and proper port-based allowances.
Audit and review domain firewall group policy settings in Windows Defender Firewall with Advanced Security. Ensure a dedicated gpo, enable on all profiles, block inbound by default, and allow outbound.
Auditors review inbound firewall rules to justify each enabled port or service, including http 80, https 443, icmp v4, ftp 21, and related web service rules.
Verify icmp v4 firewall rule effectiveness by changing it from allow to block, then ping the domain server to observe a timeout as policy is applied via gpupdate /force.
Audit the http firewall rule by blocking and then permitting port 80 on the domain controller via GPO inbound rules, verifying access to the default IIS page.
Explore Windows logs and Event Viewer to monitor security changes, failed access attempts, and system file modifications across devices via centralized subscriptions and secure log storage.
Compare basic and advanced audit policy configuration in group policy, and control audit categories like account logon and account management, plus event logging for successful, failed, or both events.
Auditors learn to use the auditpol command to view all advanced audit categories and subcategories with enabled settings, test permissions, and compare configurations against policy baselines.
Audit Windows event log file permissions to restrict access to privileged accounts, verify users and groups, justify exceptions, and replicate settings on domain controllers for maximum security.
Configure the manage auditing and security log rights so only administrators can manage the log and change auditing settings, ensuring compliance and preventing tampering with Windows Event IDs to monitor.
Explore how windows server dns acts as name resolution service, translating hostnames to ip addresses and managing zones with records such as a, cname, mx, srv, ldap, kerberos, and ptr.
Review dns manager to inspect forward and reverse lookup zones, mapping domain names to ip addresses and hosts to ip addresses, with ldap, kerberos, and gc on the domain controller.
Audit Windows DNS events via group policy and ADSI edit to log DNS record changes, including add and delete operations, in Windows Event Logs and domain controller security logs.
Audit transport layer security to protect data in transit by encrypting traffic between server and client, and verify support for TLS 1.2 or 1.3 before disabling SSL or early TLS.
Enable TLS 1.3 where supported, enable TLS 1.2 on older Windows, and disable early TLS by using group policy to bulk update TLS settings across non-compliant systems in a domain.
Explore TLS terminologies in Windows, including S channel, cipher suites, TLS protocols, and PKI-based certificate authentication. Review enabled TLS cipher suites on Windows Server 2019 and Windows 10 with PowerShell.
Audit and enforce TLS security via group policy, disable insecure TLS versions, and verify registry settings across OUs, ensuring TLS 1.2 minimum in Edge policies.
Explain how the Windows Time Service uses NTP to synchronize domain-joined computers with domain controllers, detailing stratum, leap indicators, precision, root delay, route dispersion, and poll interval.
Audit Windows NTP event logs on Windows Server 2016 and Windows 10 to verify time service actions and events.
Audit Windows NTP configurations with w32tm to review time service settings, time servers and peers, and confirm Domain Admins requirements for local and remote queries.
Audit ntp group policy configurations in Windows Time Service to ensure domain controllers synchronize with external time sources and clients and servers sync with the domain controller.
The Auditing Windows Server Active Directory Security Course will showcase and demonstrate practical steps, in assessing and reviewing the management and security of Windows Servers and Clients.
In this course, participants will learn the key enterprise principles and practices in auditing a Windows Server Active Directory infrastructure, including how to identify potential security risks and misconfiguration, review Group Policy auditing settings, and analyze Windows event logs.
You will also gain practical experience in using built-in windows features, and free/open source tools to independently verify various Windows Server Active Directory settings and configurations.
Information Technology and Cybersecurity auditors, and general IT enthusiasts, will be better equipped to analyze, test, review and verify the key configurations and security of Windows Systems for compliance.
This course is a sequel to the Creating a Windows Server Active Directory Audit Lab - Udemy Course.
The Course Outline includes:
Auditing Group Policy Objects using Group Policy Management.
Auditing Group Policy Objects using Policy Analyzer.
Auditing Active Directory Users, Groups, and Organizational Units (OUs).
Auditing Administrative Accounts Security.
Auditing Windows Ports, Protocols, and Services.
Auditing Windows Firewall Policies, and Rules.
Auditing Windows Event Logs.
Auditing Windows Server Domain Name System (DNS).
Auditing Windows Transport Layer Security (TLS) Settings.
Auditing Windows Network Time Protocol (NTP).