Skip to main content
AD Academy

Cheat Sheet

All key commands, ports and settings in one place. One click to copy.

Active Directory comparison tables

A quick comparison of similar concepts without repeating the full topic text.

FSMO roles

Who owns each unique operation and what fails when unavailable

RoleScopePurposeWhen unavailable
Schema MasterForestSchema changesSchema updates stop
Domain Naming MasterForestAdd and remove domainsForest structure cannot change
PDC EmulatorDomainTime, passwords and GPOTime and password changes may fail
RID MasterDomainAllocate RID pools to DCsNew SIDs stop after pools run out
Infrastructure MasterDomainCross-domain referencesCross-domain references become stale

AD group scopes

Who can join and where permissions apply

ScopeMembersWhere usedExample
GlobalAccounts and global groups from its domainAny trusted domainG_Finance_Users
Domain LocalAccounts and groups from trusted domainsResources in its local domainDL_Finance_Modify
UniversalAccounts and groups across the forestAny domain in its forestU_All_IT

Kerberos vs NTLM

Identify the protocol and know what to troubleshoot

FeatureKerberosNTLM
MechanismTickets: TGT then TGSChallenge–Response
RequirementsHealthy DNS, time and SPNName or IP; often fallback
Mutual authenticationYesIncomplete
Events4768 / 4769NTLM Operational, 4624
Main riskKerberoasting / ticket theftRelay / Pass-the-Hash

GPO processing order — LSDOU

The later policy normally wins

OrderLevelWhat appliesImportant exception
1LocalThe computer's local policyOverwritten first
2SiteGPO linked to the AD SiteDepends on correct subnet mapping
3DomainDomain-wide policyBlock Inheritance may stop it
4OUParent OU to child OUEnforced overrides blocking

Users and Groups

Everyday commands for managing users in AD

Create a new user

New-ADUser -Name "Dana Levi" -SamAccountName dlevi -UserPrincipalName dlevi@corp.local -Path "OU=Users,DC=corp,DC=local" -AccountPassword (Read-Host -AsSecureString) -Enabled $true

Search for a user

Get-ADUser -Filter "Name -like '*levi*'" -Properties LastLogonDate,Enabled

Reset password

Set-ADAccountPassword -Identity dlevi -Reset -NewPassword (Read-Host -AsSecureString)

Lock / unlock account

Disable-ADAccount -Identity dlevi
Unlock-ADAccount -Identity dlevi

Add to group

Add-ADGroupMember -Identity "IT-Admins" -Members dlevi

All members of a group (including nested)

Get-ADGroupMember -Identity "Domain Admins" -Recursive

Health and security checks

Commands worth running once a month

Accounts with a password that never expires

Get-ADUser -Filter "PasswordNeverExpires -eq $true" -Properties PasswordNeverExpires | Select Name

Dormant accounts (90 days)

Search-ADAccount -AccountInactive -TimeSpan 90.00:00:00 -UsersOnly

Accounts with an SPN (Kerberoasting targets)

Get-ADUser -Filter "ServicePrincipalName -like '*'" -Properties ServicePrincipalName

Unconstrained Delegation — locate and neutralize

Get-ADComputer -Filter "TrustedForDelegation -eq $true" -Properties TrustedForDelegation

💡 Any result here is a high risk

Check replication between DCs

repadmin /replsummary
dcdiag /v

krbtgt password age

Get-ADUser krbtgt -Properties PasswordLastSet

💡 Recommended to change twice a year

Group Policy

Managing and diagnosing policies

Immediate policy refresh

gpupdate /force

Which policies apply to the user

gpresult /h C:\report.html /f

List of all GPOs

Get-GPO -All | Select DisplayName,ModificationTime

Backup all policies

Backup-GPO -All -Path "C:\GPOBackup"

Application order

💡 Local → Site → Domain → OU (LSDOU). The last one wins, unless Enforced is set.

DNS and DHCP

The infrastructure AD can't live without

Check the domain's DC records

nltest /dsgetdc:corp.local
nslookup -type=SRV _ldap._tcp.dc._msdcs.corp.local

Clear the DNS cache on a workstation

ipconfig /flushdns
ipconfig /registerdns

List of Scopes in DHCP

Get-DhcpServerv4Scope

Which DHCP servers are authorized in the domain

Get-DhcpServerInDC

💡 A server not on the list = suspected Rogue DHCP

Important ports

What needs to be open between a workstation and a DC

DNS

53 TCP/UDP

Kerberos

88 TCP/UDP

LDAP / LDAPS

389 TCP/UDP  |  636 TCP

Global Catalog

3268 / 3269 TCP

SMB (file shares, SYSVOL)

445 TCP

Kerberos Password Change

464 TCP/UDP

Event IDs for identifying events

What to look for in the DC's logs

Successful logon

4624

💡 Pay attention to Logon Type: 3=network, 10=RDP

Failed logon

4625

💡 Many in a row = password-guessing attempt

Kerberos ticket request (TGT)

4768

Service ticket request (TGS)

4769

💡 With RC4 encryption = suspected Kerberoasting

Change in sensitive group membership

4728 / 4732 / 4756

Account lockout

4740

Security log cleared

1102

💡 Almost always a bad sign

Recommended hardening settings

The settings that prevent most common attacks

Reset machine account creation by users

Set-ADDomain -Identity corp.local -Replace @{"ms-DS-MachineAccountQuota"="0"}

💡 Prevents RBCD attacks

Require LDAP signing

💡 GPO: Domain controller: LDAP server signing requirements → Require signing

Disable NTLMv1 and LM

💡 GPO: Network security: LAN Manager authentication level → Send NTLMv2 response only. Refuse LM & NTLM

Enable LAPS

Get-LapsADPassword -Identity PC-01 -AsPlainText

💡 A different local admin password on every computer

Protected Users + Credential Guard

💡 For admin accounts: prevents credentials from being kept in memory

Tier Model

💡 A domain admin never logs into an end-user workstation