Active Directory - Real Defense for Domain Admins
via YouTube
Launch a New Career with Certificates from Google, IBM & Microsoft
MIT Sloan AI Adoption: Build a Playbook That Drives Real Business ROI
Overview
Syllabus
Intro
Active Directory: Real Defense for Domain Admins
Disclaimer
Provide immediately useful content for the defense of your Domain Admins (DAS) and Domain Controllers (DCs)
Test your Domain Admins
Limit the number of DAs
EPIC FAIL
Separate DA accounts from "everyday" accounts
Separate DA password policy
Set DA logon restrictions DCs only!
Disable Cached Creds
Be careful with DA service accounts
Microsoft Security Compliance Manager
A quick word about null sessions
Get offensive security training!
Questions?