Configuring Change Notification Replication for faster replication and DNS Netmask ordering for use with subnets other than Class C
Deploy & Configure AGPM
Deploy AGPM using Group Managed Service Account and Least Privileged model.
Enable Recycle Bin & Get ready for GMSA
Before we get too deep in to configuring our nice domain service, we will enable a useful feature. The Recycle Bin. This allows us to quickly and easily restore an object we accidentally delete. Enabling the recycle bin just requires…
NetBIOS and SMB1 – Kill them with fire
Using GPO to disable SMB1 and NetBIOS.
Security Logs – Archive them off
Keep a backup copy of your event logs in case something happens to your SEIM.
Starting to harden the environment
The first thing we will tackle are the issues raised by the Microsoft Best Practice Analyser. A lot of these issues are more generic to Windows devices so what we will do is create a new “Default Domain Policy” which…
Active Directory – Back It Up!
Before we get too far in to configuring Active Directory, we should sort out the backups so that we can restore the environment in the event of corruption, compromise or even our own mis-configuration. You have a choice of backup…
Alerting – Operations Management Suite
So far, we have the domain & forest set up. I’ve already configured an OMS workspace, and added the VMs to it. We’ve cranked up the auditing via GPO after setting all the time correctly, now lets get some alerts…
DNS – Block malware sites
When we set up our domain controllers, we installed the DNS role. DNS is key to how Active Directory works. It is possible to move DNS on to dedicated servers, however it’s common place to leave DNS on the Domain…
Auditing – and a little housework
First of all, I would like to point you at my GitHub repository. The GPOs I create as part of this blog will be backed up and uploaded to the following repository: https://github.com/1800Zeta/ActiveDirectory Feel free to download from here and…