Active Directory Security Measures

Active Directory Security Measures

To secure Active Directory, one must implement adequate security measures to sufficiently protect all Active Directory assets that comprise the Active Directory attack surface from risks to Active Directory enactable via Active Directory attack vectors.


The following is an asset-focused list of security measures that organizations can enact to protect their Active Directory assets -


  1. Security measures to secure and protect Domain Controllers -

    1. Provide and ensure the highest level of physical security for all Domain Controllers (DCs)
      1. Whether in datacenters or in branch-offices, install all DCs in separate, dedicated, physically secure (locked) racks or cages  How
      2. Configure all DCs with Trusted Platform Module (TPM) chips and protect all volumes with BitLocker Drive Encryption  How
      3. If using virtualized DCs, ensure that they run on physical hosts that are separate from other virtual machines in the environment  How

    2. Configure and ensure the highest levels of system security for all Domain Controllers (DCs)
      1. Establish and implement secure Domain Controller (DC) build practices  How
      2. Operate DCs on the latest version of Windows Server that is supported by your organization to leverage the latest security capabilities  How
      3. Configure secure system policy settings for all DCs by securely configuring the Default Domain Controllers Policy group policy (settings)  How
      4. Minimize and lockdown services running on all DCs, and unless absolutely required, do not install any other service or software on DCs  How
      5. Employ a separate, secure patch management process for DCs and ensure that all DCs are always completely patched, and up-to-date  How
      6. Configure comprehensive security auditing and event monitoring on all DCs to enable the detection of suspicious/nefarious activities  How
      7. Perform all management operations from remote, dedicated SAWs (Secure Admin Workstations) (, aka PAWs (Privileged Access Workstations))  How

    3. Lockdown and ensure the highest levels of network security for all Domain Controllers (DCs)
      1. Entirely restrict Internet access to and from all DCs (; configure firewalls to allow any and all required intersite communications.)  How
      2. Configure perimeter firewalls to block all outbound connections from DCs to the Internet  How
      3. Disable and prevent the use of Web browsers on all DCs  How

    4. Secure access provisioned on the domain computer accounts representing Domain Controllers (DCs) in Active Directory
      1. Assess and ensure that only authorized individuals can change the security permissions on all domain controller computer accounts in Active Directory  How
      2. Assess and ensure that only authorized individuals can change the ownership of all domain controller computer accounts in Active Directory  How
      3. Assess and ensure that only authorized individuals can modify various Kerberos related settings on all domain controller computer accounts in Active Directory  How

      4. Note - To assess who can enact the above administrative tasks on the domain computer accounts of all domain controllers, one needs to determine/calculate Active Directory Effective Permissions on all domain computer accounts in the default Domain Controllers OU.


    5. Secure access provisioned on the default Domain Controllers organizational unit (OU) in Active Directory
      1. Assess and ensure that only authorized individuals can change the security permissions on the default Domain Controllers OU in Active Directory  How
      2. Assess and ensure that only authorized individuals can change the ownership of the default Domain Controllers OU in Active Directory  How
      3. Assess and ensure that only authorized individuals can change the list of group policies linked to the default Domain Controllers OU in Active Directory  How

      4. Note - To assess who can enact the above administrative tasks on the default Domain Controllers OU, one needs to determine/calculate Active Directory Effective Permissions on the default Domain Controllers OU.


    6. Protect all Active Directory domain controller computer accounts from Active Directory Privilege Escalation attacks
      1. Identify and eliminate Active Directory Privilege Escalation paths leading to domain controller computer accounts in Active Directory  How

    7. Protect all Active Directory domain controller computer accounts from various credential theft attacks  How

  2. Security measures to secure and protect Administrative Access -

    1. Designate Active Directory Administrators and provision access for them  How

    2. Identify all accounts and groups that currently possess administrative (privileged) access in Active Directory, and revoke all excessive administrative access in Active Directory
      1. To ensure that only designated Active Directory Admins have privileged access in Active Directory, correctly identify all privileged accounts and groups that currently possess administrative (privileged) access in Active Directory  How
      2. Having correctly identified all accounts and groups that currently have administrative (privileged) access in Active Directory, make the necessary access changes to revoke all identified excessive administrative access in Active Directory i.e. revoke all administrative access in Active Directory that is currently possessed by all such identified accounts and groups that are not the designated Active Directory Admins, and thus should not have admin access in Active Directory  How

    3. Secure all accounts and groups that possess administrative (privileged) access in Active Directory
      1. Secure the access provisioned on all administrative (privileged) accounts and groups in Active Directory

        1. Assess and ensure that only authorized individuals can change security permissions on the AdminSDHolder object (CN=AdminSDHolder,CN=System,DC=...)  How
        2. Assess and ensure that only authorized individuals can change the ownership of the AdminSDHolder object (CN=AdminSDHolder,CN=System,DC=...)  How
        3. Assess and ensure that only authorized individuals can change the security permissions on all administrative (privileged) accounts in Active Directory  How
        4. Assess and ensure that only authorized individuals can change the ownership of all administrative (privileged) accounts in Active Directory  How
        5. Assess and ensure that only authorized individuals can change the security permissions on all administrative (privileged) groups in Active Directory  How
        6. Assess and ensure that only authorized individuals can change the ownership of all administrative (privileged) groups in Active Directory  How
        7. Assess and ensure that only authorized individuals can reset the passwords of all administrative (privileged) accounts in Active Directory  How
        8. If Smart cards are in use, assess and ensure that only authorized individuals can disable the use of smart cards on all administrative (privileged) accounts in Active Directory  How
        9. Assess and ensure that only authorized individuals can enable disabled administrative (privileged) accounts in Active Directory  How
        10. Assess and ensure that only authorized individuals can unlock locked administrative (privileged) accounts in Active Directory  How
        11. Assess and ensure that only authorized individuals can unexpire expired administrative (privileged) accounts in Active Directory  How
        12. Assess and ensure that only authorized individuals can modify various Kerberos related settings on all administrative (privileged) accounts in Active Directory  How
        13. Assess and ensure that only authorized individuals can change the membership of all administrative (privileged) groups in Active Directory  How
        14. Assess and ensure that only authorized individuals can add one's own account to the membership of all administrative (privileged) groups in Active Directory  How

      2. Configure appropriate security settings on all privileged accounts in Active Directory

        1. Ensure that the Account is sensitive and cannot be delegated flag is set on all administrative accounts in Active Directory  How
        2. If Smart cards are in use, enable the Smart card is required for interactive logon flag is set on all administrative accounts in Active Directory  How
        3. Ensure that the Do not require Kerberos pre-authentication setting is unchecked on all administrative accounts in Active Directory  How
        4. Restrict the ability of all Active Directory administrative accounts to be able to logon on any domain-joined computers (except on DCs and SAWs)  How

    4. Protect all Active Directory administrative (privileged) accounts and groups from Active Directory Privilege Escalation attacks
      1. Identify and eliminate Active Directory Privilege Escalation paths leading to the AdminSDHolder object in Active Directory  How
      2. Identify and eliminate Active Directory Privilege Escalation paths leading to all administrative (privileged) accounts in Active Directory  How
      3. Identify and eliminate Active Directory Privilege Escalation paths leading to all administrative (privileged) groups in Active Directory  How

    5. Protect all Active Directory privileged accounts from various credential theft attacks  How
    6. Only allow the use of Active Directory administrative (privileged) accounts on SAWs  How
    7. Ensure that all tools used by Active Directory administrators are highly trustworthy  How
    8. Audit all critical changes made to all Active Directory privileged accounts and groups  How
    9. Optionally, consider auditing the use of all Active Directory privileged accounts  How

  3. Security measures to secure and protect Active Directory Contents -

    1. Secure the domain root object

      1. Identify and lockdown who can change security permissions on the domain root object  How
      2. Identify and lockdown who can change the ownership of the domain root object  How
      3. Identify and lockdown who can replicate secrets from the domain  How
      4. Identify and eliminate Active Directory Privilege Escalation paths leading to the domain root object in Active Directory  How

      5. Note - To identify who can enact the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions on the domain root object in Active Directory.

    2. Secure all organizational units (OU) and containers in Active Directory

      1. Identify and lockdown who can create organizational units and/or containers in Active Directory  How
      2. Identify and lockdown who can change security permissions on organizational units and/or containers in Active Directory  How
      3. Identify and lockdown who can change the ownership of organizational units and/or containers in Active Directory  How
      4. Identify and lockdown who can delete organizational units and/or containers in Active Directory  How
      5. Identify and eliminate Active Directory Privilege Escalation paths leading to organizational units in Active Directory  How

      6. Note - To identify who can enact the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions on the domain root object and on all OU and container objects in Active Directory.

    3. Secure all privileged accounts and groups in Active Directory

      1. Identify and lockdown who can change security permissions on the AdminSDHolder object (CN=AdminSDHolder,CN=System,DC=...)  How
      2. Identify and lockdown who can change the ownership of the AdminSDHolder object (CN=AdminSDHolder,CN=System,DC=...)  How
      3. Identify and lockdown who can change the security permissions on all administrative (privileged) accounts in Active Directory  How
      4. Identify and lockdown who can change the ownership of all administrative (privileged) accounts in Active Directory  How
      5. Identify and lockdown who can change the security permissions on all administrative (privileged) groups in Active Directory  How
      6. Identify and lockdown who can change the ownership of all administrative (privileged) groups in Active Directory  How
      7. Identify and lockdown who can reset the passwords of all administrative (privileged) accounts in Active Directory  How
      8. If Smart cards are in use, identify and lockdown who can disable the use of smart cards on all administrative (privileged) accounts in Active Directory  How
      9. Identify and lockdown who can enable disabled administrative (privileged) accounts in Active Directory  How
      10. Identify and lockdown who can unlock locked administrative (privileged) accounts in Active Directory  How
      11. Identify and lockdown who can unexpire expired administrative (privileged) accounts in Active Directory  How
      12. Identify and lockdown who can modify various Kerberos related settings on all administrative (privileged) accounts in Active Directory  How
      13. Identify and lockdown who can change the membership of all administrative (privileged) groups in Active Directory  How
      14. Identify and lockdown who can add one's own account to the membership of all administrative (privileged) groups in Active Directory  How
      15. Identify and eliminate Active Directory Privilege Escalation paths leading to the AdminSDHolder object in Active Directory  How
      16. Identify and eliminate Active Directory Privilege Escalation paths leading to all administrative (privileged) accounts in Active Directory  How
      17. Identify and eliminate Active Directory Privilege Escalation paths leading to all administrative (privileged) groups in Active Directory  How

      18. Note - To identify who can enact the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions on the domain root object and on all administrative account and group objects in Active Directory.

    4. Secure all identities (domain user accounts) in Active Directory

      1. Configure secure domain user account password, lockout and Kerberos policy settings by securely configuring the Default Domain Policy group policy (settings)  How
      2. Identify and lockdown who can create domain user accounts in Active Directory  How
      3. Identify and lockdown who can change security permissions on all domain user accounts in Active Directory  How
      4. Identify and lockdown who can change the ownership of all domain user accounts in Active Directory  How
      5. Identify and lockdown who can reset the passwords of domain user accounts in Active Directory  How
      6. If Smart cards are in use, identify and lockdown who can disable the use of smart cards on all domain user accounts in Active Directory  How
      7. Identify and lockdown who can disable or enable (disabled) domain user accounts in Active Directory  How
      8. Identify and lockdown who can unlock locked domain user accounts in Active Directory  How
      9. Identify and lockdown who can unexpire expired domain user accounts in Active Directory  How
      10. Identify and lockdown who can change the user principal name (UPN) of domain user accounts in Active Directory  How
      11. Identify and lockdown who can change the logon script of domain user accounts in Active Directory  How
      12. Identify and lockdown who can change the Account is sensitive and cannot be delegated setting on domain user accounts in Active Directory  How
      13. Identify and lockdown who can change the Do not require Kerberos pre-authentication setting on domain user accounts in Active Directory  How
      14. Identify and lockdown who can delete domain user accounts in Active Directory  How
      15. Identify and eliminate Active Directory Privilege Escalation paths leading to domain user accounts in Active Directory  How

      16. Note - To identify who can enact the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions on all domain user account objects and on all OU and container objects in Active Directory.

    5. Secure all hosts (domain computer accounts) in Active Directory

      1. Identify and lockdown who can create domain computer accounts in Active Directory  How
      2. Identify and lockdown who can change security permissions on all domain computer accounts in Active Directory  How
      3. Identify and lockdown who can change the ownership of all domain computer accounts in Active Directory  How
      4. Identify and lockdown who can reset the passwords of domain computer accounts in Active Directory  How
      5. Identify and lockdown who can disable or enable (disabled) domain computer accounts in Active Directory  How
      6. Identify and lockdown who can change the service principal names (SPNs) of domain computer accounts in Active Directory  How
      7. Identify and lockdown who can change the msDS-AllowedToDelegateTo attribute on domain computer accounts in Active Directory  How
      8. Identify and lockdown who can delete domain computer accounts in Active Directory  How
      9. Identify and eliminate Active Directory Privilege Escalation paths leading to domain computer accounts in Active Directory  How

      10. Note - To identify who can enact the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions on all domain computer account objects and on all OU and container objects in Active Directory.

    6. Secure all security groups in Active Directory

      1. Identify and lockdown who can create domain security groups in Active Directory  How
      2. Identify and lockdown who can change security permissions on all domain security groups in Active Directory  How
      3. Identify and lockdown who can change the ownership of all domain security groups in Active Directory  How
      4. Identify and lockdown who can change the membership of domain security groups in Active Directory  How
      5. Identify and lockdown who can change the type of domain security groups in Active Directory  How
      6. Identify and lockdown who can change the scope of domain security groups in Active Directory  How
      7. Identify and lockdown who can change the designated manager of domain security groups in Active Directory  How
      8. Identify and lockdown who can add or remove themselves from domain security groups in Active Directory  How
      9. Identify and lockdown who can change the description of domain security groups in Active Directory  How
      10. Identify and lockdown who can delete domain security groups in Active Directory  How
      11. Identify and eliminate Active Directory Privilege Escalation paths leading to domain security groups in Active Directory  How

      12. Note - To identify who can enact the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions on all domain security group objects and on all OU and container objects in Active Directory.

    7. Secure group policy objects (GPOs) and the ability to link them to the domain, OUs and sites in Active Directory

      1. Identify and lockdown who can create GPOs in Active Directory  How
      2. Identify and lockdown who can change security permissions on all GPOs in Active Directory  How
      3. Identify and lockdown who can change the ownership of all GPOs in Active Directory  How
      4. Identify and lockdown who can link a GPO to a site in Active Directory  How
      5. Identify and lockdown who can link a GPO to the domain root object in Active Directory  How
      6. Identify and lockdown who can link a GPO to organizational units in Active Directory  How
      7. Identify and lockdown who can change the precedence order of GPOs linked to a site in Active Directory  How
      8. Identify and lockdown who can change the precedence order of GPOs linked to the domain root object in Active Directory  How
      9. Identify and lockdown who can change the precedence order of GPOs linked to organizaitonal units in Active Directory  How
      10. Identify and lockdown who can delete GPOs in Active Directory  How

      11. Note - To identify who can enact the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions on all site objects, the domain root object, and on all OUs in Active Directory.

    8. Secure service connection points in Active Directory

      1. Identify and lockdown who can create service connection points in Active Directory  How
      2. Identify and lockdown who can change security permissions on all service connection points in Active Directory  How
      3. Identify and lockdown who can change the ownership of all service connection points in Active Directory  How
      4. Identify and lockdown who can modify keywords on all service connection points in Active Directory  How
      5. Identify and lockdown who can modify binding information on all service connection points in Active Directory  How
      6. Identify and lockdown who can modify the Service DNS Name on all service connection points in Active Directory  How
      7. Identify and lockdown who can delete service connection points in Active Directory  How

      8. Note - To identify who can enact the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions on all service connection point objects, and on all domain computer account objects in Active Directory.

    9. Secure all administrative delegations and all custom provisioned access in Active Directory

      1. Identify and lockdown who can enact delegated administrative tasks in Active Directory  How
      2. Identify and lockdown who has custom-provisioned access in Active Directory  How

      3. Note - To identify who can enact the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions on all relevant objects in Active Directory.

    10. Secure critical Active Directory contents

      1. Identify and lockdown who can change security permissions on of any and all TrustedDomain objects (TDOs) in Active Directory domains  How
      2. Identify and lockdown who can change the owner of any and all TrustedDomain objects (TDOs) in Active Directory domains  How
      3. Identify and lockdown who can modify various attributes of any and all TrustedDomain objects (TDOs) in Active Directory domains  How
      4. Identify and lockdown who can change security permissions on the root object of the Schema partition  How
      5. Identify and lockdown who can change the owner of the root object of the Schema partition  How
      6. Identify and lockdown who can create new Schema classes in the Schema partition  How
      7. Identify and lockdown who can create new Schema attributes in the Schema partition  How
      8. Identify and lockdown who can change security permissions on the root object of the Configuration partition  How
      9. Identify and lockdown who can change the owner of the root object of the Configuration partition  How
      10. Identify and lockdown who can change security permissions on various critical/sensitive objects in the Configuration partition  How
      11. Identify and lockdown who can change the owner of various critical/sensitive objects in the Configuration partition  How
      12. Identify and lockdown who can change the owner of various critical/sensitive objects in the Configuration partition  How

      13. Note - To identify who can enact the above administrative tasks in Active Directory, one needs to determine/calculate Active Directory Effective Permissions on all relevant objects in Active Directory.

      14. Audit changes to critical Active Directory contents  How

    11. Optionally, perform an Active Directory inventory, review important group memberships, review important ACLs, create a domain-wide permissions snapshot, and find and eliminate any glaring ACL misconfigurations in Active Directory

      1. Perform an Active Directory inventory to get a lay of the land, and identify any obvious glaring vulnerabilities e.g. computer accounts trusted for unconstrained delegation or those that may have failed a logon attempt recently.  How
      2. Review important Active Directory group memberships to ensure that only intended individuals (and no others) are members of important security groups  How
      3. Review ACLs of important Active Directory objects to ensure there are no glaring accidental misconfigurations that could result in unauthorized access  How
      4. Create a domain-wide permissions snapshot to capture the domain-wide point-in-time state of all your authorization intent specifications (i.e. ACLs)  How
      5. Find and eliminate any glaring ACL misconfigurations in Active Directory, such as Domain users or Authenticated User possessing any modify access  How

  4. Security measures to secure and protect Active Directory Backups -

    1. Establish and implement secure Active Directory backup and restore practices  How
    2. Provide the highest level of physical security for all Active Directory Backups  How

  5. Security measures to secure and protect Active Directory's Logical Structure -

    1. Ensure that only authorized personnel can create new (external, cross-forest or Kerberos realm) trust relationships  How
    2. Ensure that only authorized personnel can severe (delete) existing trust relationships  How
    3. Ensure that only authorized personnel can change the direction of existing trust relationships  How
    4. Use SID Filtering to prevent escalation of privilege across external and cross-forest trust boundaries  How
    5. Ensure that only authorized personnel can disable SID filtering across a trust relationship  How

  6. A few additional general security measures -

    1. Disable NTLM v1, remove SMBv1, enforce SMB signing and disable RC4 in your Active Directory environment  How
    2. Use LAPS to securely manage local administrator passwords on domain joined machines in an Active Directory environment  How
    3. Use Managed Service Accounts (MSAs) to securely manage the lifecycle of service accounts in an Active Directory environment  How
    4. Use quotas to limit the number of objects that non-privileged users can create in Active Directory  How


  7. Security measures to secure and protect Critical Dependencies -

    The security of critical dependencies is currently out of the scope of this undertaking. Please contact Microsoft for guidance on how to adequately secure and protect critical dependencies.