Summary
In this chapter, we learned how to secure a hybrid AD infrastructure. This included configuration of password policies, Azure AD Connect Sync, and SSPR with custom banned password lists, additional hardening of domain controllers, additional hybrid features for the protection of passwords and identities, and the administration of protected users and administrative groups. We also discussed implementing and managing Microsoft Defender for Identity.
In the next chapter, we will be learning how to identify and remediate Windows Server security issues by using Azure services, learning how to monitor on-premises servers and Azure IaaS virtual machines with Microsoft Sentinel, and utilizing the power of Microsoft Defender for Cloud to identify and remediate security issues for hybrid servers.