This Active Directory hardening checklist is built from the other side of the table. Every check is something a penetration tester tries early on an internal test, usually from one ordinary domain account, because it is the fastest way from that account to Domain Admin. Closing them removes the shortcuts an attacker counts on. Each check comes with a way to verify it: a PowerShell command, a Group Policy setting or a Microsoft default you can compare against.
Use it as an Active Directory security checklist before an audit, an insurance renewal or a test. It has one limit: it tells you which settings are right, but not which of the settings you missed still chain into a path to Domain Admin. The final section covers how to check that.
The Active Directory hardening checklist on one page
Print it or paste it into a ticket. Each area is explained below.
| # | Check | Area | Done |
|---|---|---|---|
| 1 | List your Tier 0: domain controllers, AD CS, Entra Connect, AD FS and the accounts that control them | Privileged access | ☐ |
| 2 | Keep Domain Admins, Enterprise Admins, Schema Admins and Administrators to named people | Privileged access | ☐ |
| 3 | Give admins a separate account that never reads email or browses | Privileged access | ☐ |
| 4 | Block Tier 0 accounts from signing in to workstations and member servers | Privileged access | ☐ |
| 5 | Put human admin accounts in Protected Users, after testing | Privileged access | ☐ |
| 6 | Set “Account is sensitive and cannot be delegated” on privileged accounts | Privileged access | ☐ |
| 7 | Remove local administrators from Tier 0 servers | Privileged access | ☐ |
| 8 | Remove rights over Tier 0 objects held by anyone outside Tier 0 (GenericAll, WriteDACL, WriteOwner, password reset, add member) | Privileged access | ☐ |
| 9 | Grant replication rights (DCSync) only to domain controllers | Privileged access | ☐ |
| 10 | Clear stale adminCount=1 accounts and review the AdminSDHolder ACL | Privileged access | ☐ |
| 11 | Move service accounts to gMSA or dMSA; otherwise give them long random passwords | Kerberos | ☐ |
| 12 | Configure AES for service accounts and remove RC4 dependencies | Kerberos | ☐ |
| 13 | No accounts with Kerberos pre-authentication disabled | Kerberos | ☐ |
| 14 | Reset the krbtgt password twice, 10 hours apart, on a schedule | Kerberos | ☐ |
| 15 | No unconstrained delegation outside domain controllers | Delegation | ☐ |
| 16 | Review constrained and resource-based constrained delegation | Delegation | ☐ |
| 17 | Set ms-DS-MachineAccountQuota to 0 | Delegation | ☐ |
| 18 | Windows LAPS on every workstation and member server | Passwords | ☐ |
| 19 | Windows LAPS for the DSRM password on domain controllers | Passwords | ☐ |
| 20 | Run a password audit: breached, duplicate and empty passwords | Passwords | ☐ |
| 21 | No accounts with “password not required” or reversible encryption | Passwords | ☐ |
| 22 | Review every account whose password never expires | Passwords | ☐ |
| 23 | No passwords in SYSVOL scripts or Group Policy Preferences | Passwords | ☐ |
| 24 | Disable users and computers inactive for 90 days | Passwords | ☐ |
| 25 | Built-in Guest account disabled | Passwords | ☐ |
| 26 | Treat certificate authority servers as Tier 0 | AD CS | ☐ |
| 27 | No template lets low-privileged users supply the subject for an authentication certificate (ESC1) | AD CS | ☐ |
| 28 | Check template, CA and PKI object permissions (ESC4, ESC5, ESC7) | AD CS | ☐ |
| 29 | Remove the EDITF_ATTRIBUTESUBJECTALTNAME2 flag from CAs (ESC6) | AD CS | ☐ |
| 30 | Protect or remove HTTP web enrollment (ESC8 relay) | AD CS | ☐ |
| 31 | Turn off LLMNR and NetBIOS name service | Relay and coercion | ☐ |
| 32 | Require SMB signing on servers and clients | Relay and coercion | ☐ |
| 33 | Require LDAP signing and channel binding on domain controllers | Relay and coercion | ☐ |
| 34 | Disable the Print Spooler on domain controllers | Relay and coercion | ☐ |
| 35 | Refuse LM and NTLMv1, disable SMBv1 and audit remaining NTLM | Relay and coercion | ☐ |
| 36 | Domain controllers run a supported OS and nothing else | Domain controllers | ☐ |
| 37 | Keep offline backups of domain controllers and rehearse forest recovery | Domain controllers | ☐ |
| 38 | Advanced audit policy on domain controllers, forwarded off the box | Monitoring | ☐ |
| 39 | Alert on changes to Tier 0 groups, GPOs linked to domain controllers and AdminSDHolder | Monitoring | ☐ |
| 40 | Map attack paths with BloodHound after every change, then test them | Verification | ☐ |
Privileged access and Tier 0 (checks 1 to 10)
Tier 0 is everything that can control the domain: domain controllers, certificate authorities, the Entra Connect server that syncs to the cloud, AD FS, and any account or group with rights over them. Microsoft’s Defender for Identity guidance treats every local administrator on a Tier 0 system as an indirect Domain Admin.
- Keep the groups small.
Get-ADGroupMember "Domain Admins" -Recursiveshould return named people, not service accounts or nested groups nobody can explain. Schema Admins and Enterprise Admins can stay empty until needed. - Protected Users (check 5) stops members from using NTLM, from using DES or RC4 in Kerberos pre-authentication and from being delegated, and caps their ticket-granting tickets at four hours (Microsoft Learn). Microsoft warns never to add service or computer accounts, and to test before adding the most privileged admins. For privileged accounts that cannot join the group, the “sensitive and cannot be delegated” flag (check 6) still blocks delegation.
- Rights, not only groups (checks 8 to 10). Most real paths run through permissions: a help-desk group with reset-password rights over an admin, or WriteDACL on the domain object.
Get-ADUser -LDAPFilter "(adminCount=1)"lists accounts that were once protected and may still carry old rights. Only domain controllers should hold “Replicating Directory Changes All” on the domain.
BloodHound is the fastest way to see these rights as paths rather than as a list of ACL entries.
Kerberos and service accounts (checks 11 to 14)
Accounts with a service principal name (SPN) are exposed to Kerberoasting, where any domain user requests a service ticket for the account and cracks its password offline, so the strength of their passwords matters more than for any other account. List them with:
Get-ADUser -Filter 'ServicePrincipalName -like "*"' -Properties ServicePrincipalName, PasswordLastSet, msDS-SupportedEncryptionTypes
Move each one to a group Managed Service Account (gMSA) or delegated Managed Service Account (dMSA) where the application allows it, because the directory then rotates a long random password for you. Where it cannot move, set a long random password and configure AES in msDS-SupportedEncryptionTypes, then reset the password so AES keys exist. Microsoft is phasing out RC4 under CVE-2026-20833: audit events began with the January 13, 2026 update, AES-only became the default for accounts without an explicit setting on April 14, 2026, and updates from July 2026 remove the registry setting that allowed a rollback (Microsoft Support). An account still set to RC4 explicitly will keep working, and it remains the weakest setting in the domain. Event 4769 with ticket encryption type 0x17 means an RC4 service ticket was issued.
For check 13, Get-ADUser -Filter 'DoesNotRequirePreAuth -eq $true' should return nothing. For check 14, Microsoft’s recovery guidance is to reset the krbtgt password twice and wait at least 10 hours (the default maximum ticket lifetime) between resets, because the account keeps its two most recent passwords (Microsoft Learn).
Delegation and machine accounts (checks 15 to 17)
Get-ADComputer -Filter 'TrustedForDelegation -eq $true' should list only domain controllers. Any other server with unconstrained delegation holds the tickets of everyone who connects to it, which makes it a Tier 0 system in practice. Review constrained delegation (msDS-AllowedToDelegateTo) and resource-based constrained delegation (msDS-AllowedToActOnBehalfOfOtherIdentity) for entries nobody owns.
By default any authenticated user can join 10 computer accounts to the domain (Microsoft Learn), which several escalation techniques depend on. Microsoft’s Defender for Identity recommendation is to set ms-DS-MachineAccountQuota to 0 and delegate domain joins to the people who do them.
Passwords, LAPS and the password audit (checks 18 to 25)
Windows LAPS is built into Windows and Windows Server through the April 11, 2023 updates and later releases, backs up passwords to Active Directory or Entra ID, can encrypt them in the directory, and manages the DSRM password on domain controllers. The legacy Microsoft LAPS product is deprecated from Windows 11 23H2 (Microsoft Learn). A shared local administrator password is still one of the quickest ways across a network.
An Active Directory password audit (check 20) compares the stored password hashes against lists of breached and common passwords, and against each other. It finds three things a password policy cannot: users on a password from a public breach, admins whose privileged and everyday accounts share a password, and accounts with empty passwords. The open-source DSInternals module’s Test-PasswordQuality cmdlet runs this comparison. Run it from a Tier 0 machine under change control and protect the output, because the input is every password hash in the domain. Some frameworks already require it: the FBI’s policy for systems holding criminal justice data requires a quarterly comparison against compromised-password lists, as our CJIS compliance checklist explains.
For checks 21 and 22, Get-ADUser -Filter 'PasswordNotRequired -eq $true', -Filter 'AllowReversiblePasswordEncryption -eq $true' and -Filter 'PasswordNeverExpires -eq $true' give the lists. For check 23, search SYSVOL for cpassword and for credentials in logon scripts. For check 24, Search-ADAccount -AccountInactive -TimeSpan 90.00:00:00 finds stale accounts.
Active Directory Certificate Services (checks 26 to 30)
AD CS became a standard escalation path after SpecterOps published Certified Pre-Owned in June 2021, naming eight escalation paths, ESC1 to ESC8. Later research has added more. The most common is ESC1: a template that allows client authentication, lets the requester supply the subject name and is open to Domain Users. That combination lets an ordinary user obtain a certificate that authenticates as someone more privileged. The open-source tools Certify and Certipy both list vulnerable templates. Treat the CA like a domain controller, because whoever controls it can issue credentials for anyone.
Relay, poisoning and coercion (checks 31 to 35)
These settings stop an attacker on the network from capturing and replaying authentication.
- LLMNR and NetBIOS name service. Turn off LLMNR with the Group Policy setting “Turn off multicast name resolution” and disable NetBIOS over TCP/IP on adapters. Our Responder guide shows what they give away when left on.
- SMB signing. Windows 11 24H2 Enterprise, Pro and Education require signing both ways by default, but Windows Server 2025 requires it only for outbound connections (Microsoft Learn), so set inbound signing on servers by policy. Check with
Get-SmbServerConfiguration | Select RequireSecuritySignature. - LDAP signing and channel binding. Set “Domain controller: LDAP server signing requirements” to require signing and enforce channel binding tokens.
- Print Spooler on domain controllers. Any authenticated user can make a domain controller’s spooler connect out to a machine of their choosing, exposing the DC’s credentials. Microsoft recommends disabling it on domain controllers.
- Legacy protocols. Set “Network security: LAN Manager authentication level” to send NTLMv2 only and refuse LM and NTLM, disable SMBv1 and audit what still uses NTLM before restricting it further.
Domain controllers and monitoring (checks 36 to 39)
Domain controllers should run a supported version of Windows Server and nothing else: no agents they do not need, no file shares, no browsing. Keep an offline copy of domain controller backups, because ransomware operators look for backups first, and rehearse forest recovery before you need it. Our ransomware readiness assessment tests whether an attacker who reaches Domain Admin could also reach, alter or delete those backups.
For logging, enable advanced audit policy on domain controllers and forward events off the box. The events that matter most: 4768 and 4769 (Kerberos tickets, including RC4 use), 4662 (directory access, where DCSync shows up), 4728, 4732 and 4756 (members added to security groups) and 5136 (directory objects changed). Alert on any change to Tier 0 groups, to GPOs linked to domain controllers and to AdminSDHolder.
Verify it: map the paths, then test them
Settings drift, and one missed permission can undo the other 39 checks. Run BloodHound after each round of changes and look for any remaining path from Domain Users to Tier 0. Then have someone try.
Our Active Directory security assessment starts from one standard user account and works toward Domain Admin through Kerberos, delegation, ACL, AD CS, relay and hybrid identity paths. It is $6,000 for one domain of up to a few hundred hosts, fixed in writing before work starts, with a free retest of what you fix. If you want the hosts, services and segmentation around the domain tested as well, choose the internal network penetration test, and use our network penetration testing checklist to prepare for either.
Frequently asked questions
What is the most important Active Directory hardening step? Separating Tier 0. Many attack paths end with an admin credential cached on a workstation or server an attacker already reached. Keeping Tier 0 accounts off lower-tier machines, and removing rights over Tier 0 objects, breaks more paths than any single setting.
How often should we run an Active Directory password audit? At least quarterly, and after any breach that may have exposed staff passwords. Compare against a current breached-password list each time and track the number of hits over time.
Do CIS Benchmarks cover Active Directory hardening? The CIS Benchmarks for Windows Server include domain controller settings such as audit policy, SMB signing and LDAP signing. They are Group Policy and registry settings, so they do not look at delegation, ACLs, AD CS templates or service accounts, where many attack paths live. Use them alongside this checklist.
Is this checklist enough for Entra ID? No. It covers the on-premises side and the Entra Connect server. Cloud admin roles, conditional access and app consent need their own review, which our Microsoft 365 security assessment covers.
Can we check all 40 ourselves? Yes. Every check here can be verified with built-in tools and free open-source ones. A test adds the part a checklist cannot: proof of which gaps still chain into a path to Domain Admin, and in what order to fix them.
Fixed price, fixed scope, free retest. Scope your Active Directory assessment and get the price in writing.
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →