<aside>
Security in Active Directory
</aside>

General Active Directory Hardening Measures
Defense-in-Depth Concept
Security should be implemented in multiple layers. No single control is sufficient on its own. AD hardening must be combined with asset management, patching, endpoint protection, monitoring, and security awareness.
Key Active Directory Hardening Measures
1. Microsoft LAPS (Local Administrator Password Solution)
- Randomizes and automatically rotates local Administrator passwords on Windows hosts.
- Each device has a unique local admin password stored securely in AD.
- Prevents lateral movement if a single machine is compromised.
- Effective when combined with other security controls.
2. Audit Policy (Logging & Monitoring)
- Enables visibility into AD and system activity.
- Helps detect:
- Unauthorized user or computer creation
- Object modifications in AD
- Password changes
- Suspicious login behavior
- Password spraying attacks
- Advanced Kerberos-based attacks
- Essential for incident detection, investigation, and response.
3. Group Policy Security Settings (GPOs)