Skip to main content
AD Academy
Advanced Attacks and Modern Defenses
Intermediate15 minLast updated: Topic 4 of 4

Modern Defenses: LAPS, Credential Guard, MDI

The defense layers that break common attack paths.

Not read

What you will learn here

  • What LAPS solves
  • How Credential Guard protects credentials
  • What MDI detects

Worth reading first:ACL Abuse in Active Directory

Most attacks on rely on an identical local Administrator password across all workstations, on credentials stored in memory, and on lack of monitoring. The following three defenses address exactly that.

  • Windows — a unique, rotating local password on every computer, stored in . Breaks Lateral Movement.
  • — isolates LSASS using virtualization, so a Hash can't be extracted from it.
  • Protected Users + Tiering — prevents admin credentials from being stored on regular workstations.
  • Microsoft Defender for Identity (MDI) — a sensor on the DC that detects , , and suspicious scans.
# Windows LAPS - Prepare Schema and Check Password
Update-LapsADSchema
Get-LapsADPassword -Identity "PC-01" -AsPlainText

# Check that Credential Guard is active
Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard |
  Select-Object SecurityServicesRunning
powershell
Architecture and Theory — Under the Hood

Modern protection is based on three principles: , Tiering, and Assume Breach (assume you're already compromised and detect quickly).

  • Tier 0 — DCs, PKI, accounts that can take over the domain.
  • Tier 1 — Application servers, DBs.
  • Tier 2 — User endpoints.
  • A high-tier account never accesses a lower tier. Never.
Practical Configuration (PowerShell / GUI)
# Protected Users — blocks NTLM, delegation, RC4 for group members
Add-ADGroupMember -Identity "Protected Users" -Members "DomainAdmin1"

# Authentication Policies + Silos (Kerberos Armoring / FAST)
New-ADAuthenticationPolicy -Name "Tier0-Policy" -UserTGTLifetimeMins 240
New-ADAuthenticationPolicySilo -Name "Tier0-Silo" -UserAuthenticationPolicy "Tier0-Policy"

# LAPS
Install-WindowsFeature -Name AdminCenter
Update-LapsADSchema
Set-LapsADComputerSelfPermission -Identity "OU=Workstations,DC=corp,DC=com"
powershell
Real-world scenarios in an organization
  • PAW (Privileged Access Workstation) — A dedicated workstation with a hardened , no internet/email.
  • Just-In-Time Admin — Temporary permission (60 min) via PIM/JIT tools instead of permanent membership.
  • Red / ESAE (old) → Replaced by Azure PIM + Tiering.
Troubleshooting
  • Regular check of Admins — There shouldn't be more than 2-3 accounts there.
  • Attack Surface Reduction (ASR) rules in Defender block LSASS access.
  • PingCastle / Purple Knight — Free hygiene scans.
Glossary and Quick Command Line
  • PAW — Privileged Access Workstation.
  • PIM — Privileged Identity Management.
  • JIT — Just-In-Time.
  • ASR — Attack Surface Reduction.

Check yourself

What problem does Windows LAPS solve?

Was this page helpful?