Summary
In this chapter, we expanded our lab setup to include an AD Domain Controller, a Windows Server 2022 File Server, and reviewed both default security configurations as well as identified some best practices. We then learned about some of the more advanced attack mitigation features such as exploit protection, WDAC, Microsoft Defender for Endpoint, Windows Defender Credential Guard, SmartScreen, and the implementation of additional security protections using security baselines within Group Policy.
In the next chapter, we will be learning how to secure a hybrid AD infrastructure. This will include the configuration of password policies, additional hardening of domain controllers, additional hybrid features for the protection of passwords and identities, and the administration of protected users and administrative groups.