← back to theory
AD

Active Directory Hardening & Tiering

Active Directory is the single most valuable asset in most enterprises: it is the trust fabric that decides who can do what, everywhere. Whoever owns the directory owns the organisation — which is why nearly every page in the AD attack-path map ends at Domain Admin or a domain controller. This page is the defensive mirror of that map: for each attack class, the concrete control that breaks it.

None of this is exotic. AD compromise is overwhelmingly a story of configuration and credential hygiene, not zero-days — so hardening is overwhelmingly about closing well-known paths, reducing standing privilege, and watching the directory. Deep privileged-access design has its own page, Privileged Access & the Enterprise Access Model; this page is the broader hardening playbook.

Why AD is the crown jewel

AD authenticates users, issues Kerberos tickets, stores every object and its permissions in LDAP, and pushes configuration through Group Policy. Compromise a domain controller and you can DCSync every credential in the domain, including krbtgt — which lets you forge golden tickets and persist indefinitely. That is why the whole design goal is to keep the attacker away from Tier-0 and to make every step toward it loud.

The foundation: tiering & the Enterprise Access Model

The structural control that underpins everything else is administrative tiering — now expressed as Microsoft's Enterprise Access Model (Control / Management / Data-Workload planes, superseding the legacy Tier 0/1/2 and the old ESAE “Red Forest”). The golden rule: a higher-tier credential never authenticates to a lower-tier, exposed asset, because that downward credential flow is exactly how one phished laptop becomes Domain Admin. The full design — planes, PAWs, PAM, just-in-time — is covered in Privileged Access & the Enterprise Access Model.

Tiering is the control attackers hate most, because it breaks the chain rather than any single technique: even a successful credential theft on a workstation yields a workstation-tier credential that is useless against the domain controllers in Tier-0.

The hardening playbook — attack → control

The most useful way to harden AD is to walk the attack map and close each path. This table is the two-sided reference: each attack links to its page, each control is the thing that stops it.

Attack class (on this site)Hardening control(s)
Credential theft / LSASS dumpingCredential Guard (VBS), run LSASS as PPL, Protected Users group for admins, disable WDigest, no cached creds / interactive admin logon on servers
Pass-the-hash / lateral movementLAPS (unique local-admin passwords), deny network/interactive logon for privileged accounts across tiers, host firewall blocking workstation-to-workstation, segmentation
Coercion & NTLM relay (relay)Enforce SMB signing and LDAP signing + channel binding, enable Extended Protection for Authentication (EPA), disable the WebClient service, remove NTLM where possible
KerberoastinggMSA/dMSA for service accounts (auto-rotated 120-char passwords), long random SPN passwords, AES-only (disable RC4), a honeypot SPN as a tripwire
AS-REP roastingNever set “do not require Kerberos pre-authentication”; audit for it continuously
Kerberos delegation (unconstrained / RBCD)Remove unconstrained delegation; mark admins “account is sensitive and cannot be delegated” (or Protected Users); audit msDS-AllowedToDelegateTo and msDS-AllowedToActOnBehalfOfOtherIdentity; guard SeEnableDelegationPrivilege
ACL / DACL abuse (dangerous ACEs)Run BloodHound against your own estate; remove unjustified GenericAll/WriteDacl/ForceChangePassword; protect Tier-0 object ACLs; enable the AdminSDHolder protections
AD CS abuse (ESC1-ESC8)Harden certificate templates (no client-auth EKU + enrollee-supplied-subject), require manager approval, disable NTLM on the CA and enforce EPA, treat AD CS as a Tier-0 asset
GPO abuse (GPP / edit rights)Restrict who can edit GPOs, monitor SYSVOL for scheduled-task/script writes, remove any legacy Group Policy Preferences passwords (cpassword)
Golden / silver ticketsDouble-rotate krbtgt regularly; AES keys; alert on anomalous TGT lifetimes and on tickets for non-existent accounts
Fast-path CVEs (Zerologon, noPac, PrintNightmare)Patch promptly, enforce DC secure-channel signing, disable the Print Spooler on DCs, monitor for the known exploitation signatures
LLMNR / NBT-NS / mDNS poisoningDisable LLMNR, NBT-NS and mDNS via GPO; this also removes the easiest relay trigger

Baselines & attack-surface reduction

On top of the targeted controls, apply the broad baselines so defaults are safe and drift is visible:

  • Microsoft Security Baselines (via the Security Compliance Toolkit) and CIS Benchmarks / DISA STIGs for DCs, servers, and workstations — unnecessary services off, secure protocols on, with drift monitoring.
  • Attack Surface Reduction (ASR) rules and exploit protection on endpoints to block the common execution and credential-theft behaviours.
  • Remove legacy: SMBv1, unconstrained delegation, RC4, print spooler on DCs, and stale/privileged accounts.
  • Patch the identity plane first — DCs, AD CS, and Entra Connect are Tier-0; their CVEs are domain-ending.

Monitoring: hardening you can't see is hardening you can't trust

Prevention always eventually fails, so AD must be instrumented. The detections live in the SOC and are built by detection engineering on top of Windows auditing: 4769 patterns for kerberoasting, directory-replication from a non-DC for DCSync, anomalous logons for pass-the-hash, and honey-token/decoy-object hits as high-fidelity tripwires. Microsoft Defender for Identity, Semperis, or Tenable Identity Exposure watch the directory specifically.

Assume-breach: tested forest recovery

If the domain is ever fully compromised, rebuilding trust is the critical path — and AD forest recovery is slow and error-prone if practised for the first time during the incident. So it is rehearsed: clean backups of system state, a documented recovery runbook, krbtgt rotation, and tooling (Semperis ADFR) to automate it. This is the AD-specific slice of the broader incident-response plan.

Key takeaways

  • AD is the crown jewel; hardening is mostly closing well-known paths and cutting standing privilege, not chasing zero-days.
  • Tiering / the Enterprise Access Model is the structural control — it breaks the chain, not just one technique.
  • Walk the attack map and close each path: credential theft, relay, roasting, delegation, ACLs, GPO, tickets, fast-path CVEs, legacy protocols.
  • Instrument the directory and rehearse forest recovery — assume the attacker will eventually get a foothold.

Related reading