Active Directory Security Basics

Active Directory Security Basics


The following are some basic concepts related to Active Directory Security that one must possess intimate knowledge of -

Forests   Domains   Partitions   Schema   DCs   rootDSE   Administrator account   Default Administrative Groups   User Rights and Privileges   Active Directory Security Permissions   Active Directory Effective Permissions   Active Directory Auditing

Authentication   Authorization   Auditing   Privileged Access   Default Access   Inheritance of Permissions   Administrative Delegation   Custom Access Provisioning   AdminSDHolder   Active Directory ACLs and ACEs   Allow and Deny Permissions

Domain Root   Organizational Units   Active Directory Contents (Domain User Accounts, Computer Accounts, Managed Service Accounts, Security Groups etc.)   Passwords (Rotation, Resets etc.)   Group Membership Changes   ACL Modifications

Replication   Replication Topology   Sites   KCC   Replication Access Control   DCSync   Trust relationships   Trust accounts   Trust types   SID History   dsHeuristics   FSMOs   Query Policies   SMB   Group Policy   SYSVOL   DFS   DNS   Backups


In addition, one should also be well-versed with the network authentication protocols in Windows Server environments the mechanisms of which are integrated with Active Directory -

Kerberos   NTLM   KDCs   Authentication Service   Ticket Granting Service   TGTs   Session Tickets   krbtgt   Pre-authentication   Password Hashes   Delegation of Authentication   Unconstrained and Constrained Delegation   S4U   Protocol Transition


Finally, at organizations that utilize one or more of the following related technologies, the basic concepts of these technologies are also important to understand -

Active Directory integrated applications (access provisioning)    Active Directory Certificate Services (Certificate Authorities, Templates, Enrollment, EKUs etc.)    Active Directory Federation Services    3rd-party Identity Provider (e.g. Azure) Integration