Applying security to AD
While there is not an official guideline or standard for securing AD, here is a compilation of the industry best practices that you can leverage to enhance the security of your AD servers:
- Never install additional software, roles, or services on domain controllers.
- Never create local users on domain controllers (user management must be carefully handled on domain controllers).
- Make sure accounts are created based on PoLP.
- Maintain a record (list) of AD privilege accounts that includes owners, rights, and other relevant data about the account (to prevent ghost accounts).
Tip
Ghost account is a term used for accounts in which the ownership or usage is unclear. While this may not be an issue on small infrastructures, it can become a huge problem in big environments in which best practices are not followed and you may have dozens of those accounts, which represents a significant risk to your infrastructure.
- AD privilege accounts should not...