Protecting the directory.
WHY IT MATTERS MOST
Compromise of the directory is compromise of everything it authenticates.
WHAT TO PROTECT MOST TIGHTLY
Domain administrative accounts.
WHAT TO ESTABLISH
Separate accounts for administrative work No administrative account used for mail or browsing A tiered model, so credentials for high-value systems are never exposed on lower-value ones
WHY THAT TIERING MATTERS
Credentials used on a compromised workstation are harvested from it.
WHAT TO MONITOR
Changes to privileged groups Account lockouts Authentication failures in volume Creation of accounts and service accounts
WHAT TO RESTRICT
Where administrative accounts may sign in.
WHAT TO ELIMINATE
Accounts with passwords never expiring Service accounts with excessive rights Legacy protocols no longer required
WHAT TO PATCH PROMPTLY
Domain controllers.
WHY
Directory vulnerabilities are exploited quickly and comprehensively.
WHAT TO BACK UP
System state on domain controllers.
WHAT TO PRACTISE
Recovering the directory, since it is complex and rarely attempted until required.
WHAT TO KEEP OFFLINE
Recovery credentials and documentation.