Proper AD hardening can keep attackers contained and prevent lateral movement, privilege escalation, and access to sensitive data and resources. One of the essential steps in AD hardening is understanding everything present in your AD environment. An audit of everything listed below should be done annually, if not every few months, to ensure your records are up to date. We care about:
Naming conventions of OUs, computers, users, groupsDNS, network, and DHCP configurationsAn intimate understanding of all GPOs and the objects that they are applied toAssignment of FSMO rolesFull and current application inventoryA list of all enterprise hosts and their locationAny trust relationships we have with other domains or outside entitiesUsers who have elevated permissionsIn even the most hardened environment, users remain the weakest link. Enforcing security best practices for standard users and administrators will prevent "easy wins" for pentesters and malicious attackers. We should also strive to keep our users educated and aware of threats to themselves. The measures below are a great way to start securing the Human element of an AD environment.
RID-500 local admin account and create a new admin account for administration subject to LAPS password rotation.Does the organization need 50+ Domain/Enterprise Admins? Restrict group membership in highly privileged groups to only those users who require this access to perform their day-to-day system administrator duties.