Chapter 11: Securing Active Directory
From a business perspective, Active Directory needs to be an available, confidential attribute store with absolute integrity. The security measures in this chapter detail how to achieve a higher level of confidentiality and integrity.
The following recipes are covered in this chapter:
- Applying fine-grained password and account lockout policies
- Backing up and restoring GPOs
- Backing up and restoring the Active Directory database
- Working with Active Directory snapshots
- Managing the DSRM passwords on domain controllers
- Protecting important objects from accidental deletion
- Implementing Local Administrator Password Solution (LAPS)
- Managing deleted objects
- Working with group Managed Service Accounts (gMSAs)
- Configuring diagnostic logging
- Configuring the advanced security audit policy
- Resetting the KRBTGT secret
- Using the Security Configuration Wizard (SCW) to secure domain controllers
- Leveraging...