<aside>

Security in Active Directory

</aside>

image.png

General Active Directory Hardening Measures

Defense-in-Depth Concept

Security should be implemented in multiple layers. No single control is sufficient on its own. AD hardening must be combined with asset management, patching, endpoint protection, monitoring, and security awareness.


Key Active Directory Hardening Measures

1. Microsoft LAPS (Local Administrator Password Solution)


2. Audit Policy (Logging & Monitoring)


3. Group Policy Security Settings (GPOs)