Observed arrival · 2026-09-29
Active Directory Hardening, from Tier 0 to recovery
A practical hardening map and guide collection for securing Active Directory, with configuration details, verification commands, and a phased rollout plan.
- For
- Active Directory administrators and security teams
- Worth noticing
- Guides include compatibility fallout and staged audit-before-enforce advice for changes that can affect legacy systems.
Field notes
The map groups controls by attack surface, including delegation, certificate services, Group Policy and SYSVOL, trusts, and recovery. Its examples show the practical tradeoffs: it flags RC4-only NAS appliances, LDAP simple binds on port 389, and NTLMv1 print servers as compatibility concerns. The homepage describes a staged Measure–Audit–Enforce–Verify rollout and advertises 50 guides; the supplied evidence does not establish the access conditions for every guide.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue