Skip to main content
AD Academy
Open knowledge base for absolute beginners

Active Directory that finally makes sense

A reference before and during your studies: from networking and DNS to building a domain, daily administration, protocols, attacks and defense. No fixed order — come in, search, find.

Illustration of a corporate network with a central Domain Controller connected to workstations and users

Plain-language explanations

Every topic is split into short blocks: explanation, example and ready-to-copy commands.

Fast search

A search bar on every page: type a term and land straight on the answer.

Attacks and defense

Understand how attacks work and learn how to protect the domain.

Understand through diagrams

Instead of long text — visual diagrams showing how AD is built and how authentication really works.

An interactive hierarchy from Forest through Tree and Domain to OU and objects. Color identifies the level type and labels keep the diagram understandable without color perception.

1. הלקוח שולח AS-REQ ל־KDC. 2. ה־KDC מחזיר TGT. 3. הלקוח מבקש כרטיס שירות עם TGS-REQ הכולל SPN. 4. ה־KDC מחזיר כרטיס TGS. 5. הלקוח פונה לשירות עם AP-REQ. 6. השירות מאשר גישה. הסיסמה עצמה לא עוברת ברשת — רק כרטיסים מוצפנים.

FortiGate — a full standalone section

Everything about FortiGate in one place: from FortiOS to firewall policies, NAT, VPN, security profiles, logs, and Active Directory integration.

Infrastructure security devices

Defense in depth, L2/L3/L7 and the CIA triad.

Firewall evolution — from stateless to NGFW

State tables, proxy firewalls, IDS/IPS and FortiGate.

What are FortiGate and FortiOS?

Intro to Fortinet's NGFW, the FortiOS operating system and the Security Fabric concept.

Firewall policies and objects

How a policy is built, the order it is evaluated in, and why objects save dozens of rules.

NAT on FortiGate: SNAT and VIP

Outbound address translation, IP pools and publishing an internal server with a Virtual IP.

VPN: IPsec site-to-site and SSL VPN

Connecting two offices and remote employee access, including the IPsec negotiation phases.

Security profiles and SSL inspection

AntiVirus, IPS, web filter, application control and Certificate vs Deep Inspection.

Logs and troubleshooting

A clear workflow: from the GUI log to CLI sniffer and debug flow.

FSSO — how the firewall knows who is who in AD

Mapping user-to-IP from DC logon events and firewall policies driven by AD groups.

FortiAuthenticator — RADIUS, TACACS+ and MFA with AD

An AAA server synced with AD: RADIUS for users, TACACS+ for admins, plus a second factor.

802.1X and NAC — only authenticated devices get in

Port-level authentication, EAP-TLS vs PEAP, dynamic VLAN assignment and the Evil Twin trap.

A network view of the course attacks — what Fortinet adds

What the network layer sees versus DC logs, and how segmentation limits lateral movement.

The ICAO/NATO spelling alphabet

Accurate voice communication of technical identifiers.

Envario lab rules

Session planning, RDP, protecting the environment and support.

All topics

Pick a topic — there is no required order.

CCNA — Cisco Networking Fundamentals

OSI/TCP-IP model, Switching and VLAN, Routing, IPv4/IPv6 addresses, Network services and security — The basis for the CCNA 200-301 exam.

0 / 12 topics0%
Start module

Active Directory Basics

What is AD, what are Domains, Forests and Trees. Main objects and general structure.

0 / 2 topics0%
Start module

Protocols and Authentication

LDAP, Kerberos, NTLM and how login to the domain actually happens.

0 / 2 topics0%
Start module

Attacks on AD

How attackers may attack the domain and why these methods actually work.

0 / 7 topics0%
Start module

Delegation in Active Directory

Permission Delegation: Unconstrained, Constrained and Resource-Based — how it works, how it's exploited and how to defend against it.

0 / 4 topics0%
Start module

Defense and Monitoring

Practices, policies and tools for protecting the Domain.

0 / 3 topics0%
Start module

Tools

What system administrators and information security professionals use.

0 / 4 topics0%
Start module

Incident Response

What to do once the Domain has already been breached: detection, containment and recovery.

0 / 1 topics0%
Start module

Practice and Learning

A home lab and hands-on practice of user management in AD.

0 / 2 topics0%
Start module

DHCP and Network Preparation

How DHCP integrates with AD and DNS, what threats exist, and how to manage it all with PowerShell.

0 / 5 topics0%
Start module

From Zero: Network, Server and Domain

No prior background needed: what is a network, IP, DNS, what is Windows Server, and how to set up your first Domain Controller.

0 / 4 topics0%
Start module

Day-to-day administration of AD

OUs and groups, NTFS and Share permissions, password policy, RSAT and AD backup — the routine work of a system administrator.

0 / 4 topics0%
Start module

Advanced Protocols and Infrastructure

NTLM, SMB, LDAPS, SPN, Trusts, and Sites & Replication.

0 / 4 topics0%
Start module

Advanced Attacks and Modern Defenses

AS-REP Roasting, Golden and Silver Ticket, ACL abuse — and against them LAPS, Credential Guard, Tiering, and MDI.

0 / 4 topics0%
Start module

SOC Analyst — Read traffic, logs, and attacks

Anatomy of a network packet in Wireshark, Windows Event ID map, interactive Cyber Kill Chain, and how SIEM connects everything.

0 / 3 topics0%
Start module

Cloud Computing: Architecture and Security

Public versus Private Cloud, IaaS/PaaS/SaaS service models, and Azure's Shared Responsibility Model.

0 / 8 topics0%
Start module

Microsoft Entra ID (Azure AD)

Cloud identity: how it differs from AD DS, how to connect an on-prem domain to the cloud, and how to protect access.

0 / 6 topics0%
Start module

Not sure where to start?

Start with networking basics, or just search for a term. Everything is open and free.

Go to topics