Active Directory Hardening Playbook

Immediate Wins from Hacker

Core Architectural Hardening

Domain Controller Security

Kerberos and Credential Protection

Monitoring & Detection

Ongoing Assessment

Incident Response & Recovery

Policy and Administrative Controls

Top 6-Step Checklist

  1. Centralize and retain DC logs (≥30 days).

  2. Enforce MFA on all admin accounts.

  3. Enable LAPS and gMSA for service accounts.

  4. Reduce Domain Admin membership and enable JIT elevation.

  5. Disable NTLMv1 and weak encryption.

  6. Test offline AD restore monthly.