Skip to main content
AD Academy
Defense and Monitoring
Intermediate20 minLast updated: Topic 1 of 3

Best Practices for Protecting AD

Key steps for reducing risk.

Not read

What you will learn here

  • The most important steps to protect AD
  • How to limit admin accounts
  • What to check regularly

Protecting is a set of complementary measures. The more layers of defense (Defense in Depth), the harder it is for an attacker to reach critical assets. Below are the main recommendations.

Tier 0 — Domain Controllers, חשבון krbtgt ו־Domain Admins. Tier 1 — שרתים ואפליקציות ארגוניות. Tier 2 — תחנות עבודה ומשתמשי קצה. הכלל: אין להתחבר עם חשבון Tier 0 למכונות בשכבות נמוכות יותר, כדי שלא יישארו אישורים לגניבה.

Key steps

  • The principle — grant only the permissions that are necessary.
  • Unique, strong passwords for privileged accounts and service accounts.
  • Multi-factor authentication (MFA) for system administrators.
  • Regular updates for Windows Server and workstations.
  • Auditing security events and analyzing logs in a .
  • Backup and a Recovery Plan for .
Architecture and Theory — Under the Hood

The protection model is based on two principles: and Tiering. Each admin account must be limited to its level — Tier 0 (DCs), Tier 1 (Servers), Tier 2 (Workstations).

  • Do not use a Admin account for daily work — separation between a regular account (u.smith) and an admin account (a.smith).
  • Interactive login for Tier 0 is only allowed for PAW (Privileged Access Workstation).
  • — Unique local Administrator password for each computer, stored encrypted in .
  • isolates LSASS and prevents on Windows 10/11 and 2019+.
Practical Configuration (PowerShell / GUI)
# LAPS Deployment (Windows LAPS built-in from 2023)
Set-LapsADComputerSelfPermission -Identity 'OU=Workstations,DC=corp,DC=com'
Set-LapsADPasswordExpirationTime -Identity PC-01
Get-LapsADPassword PC-01 -AsPlainText

# Enable Credential Guard using GPO / Registry
reg add HKLM\System\CurrentControlSet\Control\LSA /v RunAsPPL /t REG_DWORD /d 1 /f

# Emergency Accounts - Disable until needed
Set-ADUser break-glass -Enabled $false
Set-ADUser break-glass -PasswordNeverExpires $true
powershell
Real-world Scenarios in an Organization
  • Israeli bank: Separate PAW + mandatory Smart Card for every DA.
  • Industrial plant: Partial Tiering — at least separation between OT servers and IT servers.
  • Startup company: + MFA on VPN as a first step before full Tiering.
Troubleshooting
  • Admin user cannot connect to a server that should be in their Tiering → Check Authentication Policy Silo and Logon Restriction in the Protected Users group.
  • is not syncing → Check Get-LapsDiagnostics and domain password policy (length/complexity).
Glossary and Quick Command Line
  • PAW — Clean administration workstation, without email and without a browser.
  • Tier 0/1/2 — Mandatory separation.
  • Break-Glass — Two emergency accounts in a physical Vault.
  • MFA for every admin — not just for RDP.

Check yourself

What does the Least Privilege principle mean?

Was this page helpful?