CyberLabs
Penetration Testing Hub · cyberlabs.ie
Active Directory Hardening Checklist
Nine checks that close the paths attackers walk to domain admin. Run BloodHound against your own domain first — then work this list.
Before you test — Only test Active Directory environments you own or have explicit written permission to test. Unauthorised access is a criminal offence in Ireland under the Criminal Justice (Offences Relating to Information Systems) Act 2017.
Privilege
Domain Admins membership is tiny — ideally single digits, and no service accounts. Tier-0 assets (DCs, admin workstations) are isolated from ordinary user machines. Unconstrained delegation is removed or tightly justified. Credentials
Service accounts have long, random passwords and use managed service accounts (gMSA) where possible. LAPS (or equivalent) randomises the local admin password on every machine — no reuse. No accounts have Kerberos pre-authentication disabled without good reason. Protocols & hygiene
LLMNR and NBT-NS are disabled; SMB signing is enforced. Old, disabled and stale accounts are cleaned up regularly. You've run BloodHound against your own domain and looked at the shortest paths to Domain Admins.