Protecting is a set of complementary measures. The more layers of defense (Defense in Depth), the harder it is for an attacker to reach critical assets. Below are the main recommendations.
Tier 0 — Domain Controllers, חשבון krbtgt ו־Domain Admins. Tier 1 — שרתים ואפליקציות ארגוניות. Tier 2 — תחנות עבודה ומשתמשי קצה. הכלל: אין להתחבר עם חשבון Tier 0 למכונות בשכבות נמוכות יותר, כדי שלא יישארו אישורים לגניבה.
Key steps
- The principle — grant only the permissions that are necessary.
- Unique, strong passwords for privileged accounts and service accounts.
- Multi-factor authentication (MFA) for system administrators.
- Regular updates for Windows Server and workstations.
- Auditing security events and analyzing logs in a .
- Backup and a Recovery Plan for .