Module 3: Identities & Services Hardening
This directory contains security requirements and policies designed to protect administrative identities, user credentials, and critical network service accounts in the Active Directory domain.
Technical Hardening Controls
REQ-ID-001 - Enforce Fine-Grained Password Policies Enforces Password Settings Objects (PSOs) with strong password length and lockout settings for administrative groups.
REQ-ID-002 - Enable Local Administrator Password Solution (LAPS) Implements Windows LAPS or Classic LAPS to rotate local administrator passwords periodically.
REQ-ID-003 - Implement Group Managed Service Accounts (gMSA) Replaces static passwords with auto-managed complex service account credentials.
REQ-ID-004 - Restrict Kerberos Delegation Bans unconstrained delegation and mandates constrained/resource-based constrained delegation.
REQ-ID-005 - Configure and Populate Protected Users Group Enforces strict caching and authentication restrictions on high-privilege identities to prevent credential theft.
REQ-ID-006 - Rename and Disable Default Administrator and Guest Accounts Mitigates automated scanning and brute-force attempts on built-in OS accounts.
REQ-ID-007 - Restrict Interactive Logons for Service Accounts Blocks interactive local and remote desktop logons for service accounts via User Rights Assignment GPOs.
REQ-ID-008 - Enforce User and Service Account Kerberos Encryption (AES-Only) Sets the msDS-SupportedEncryptionTypes attribute to AES-only to mitigate Kerberoasting and session hijacking.
REQ-ID-009 - Enforce Kerberos Pre-Authentication Mandates Kerberos pre-authentication on all active user accounts to mitigate AS-REP Roasting attacks.
REQ-ID-010 - Restrict Schema Administrators Group Membership Automates Schema Admins membership audit and locking using Restricted Groups GPO to minimize the attack surface.
REQ-ID-011 - Enforce Accidental Deletion Protection on Organizational Units Safeguards OUs from deletion errors or malicious administrative actions via the
ProtectedFromAccidentalDeletionattribute.REQ-ID-012 - Configure Active Directory Authentication Silos and Policies Enforces logical boundaries restricting where Tier 0 administrator and host accounts can authenticate, preventing credential theft.
REQ-ID-013 - Clean Up adminCount Attribute Orphans Identifies and remediates orphan accounts with disabled security descriptor inheritance, resetting adminCount to 0 and re-enabling inheritance.
REQ-ID-014 - Renew KDS Root Keys and gMSA Secrets Enforces KDS root key rotation and triggers password regeneration for Group Managed Service Accounts to mitigate exfiltration backdoors.
REQ-ID-015 - Harden Active Directory Certificate Services (ADCS) and PKI Hardens ADCS templates to block ESC1 SAN enrollment bypasses, mandates manager approval, and secures CA Web Enrollment endpoints.
REQ-ID-016 - Configure Logon Screen and Credentials Delegation Restricts logon screen user enumeration, and hardens CredSSP/credentials delegation.
REQ-ID-017 - Disable Machine Account Quota Restricts the ms-DS-MachineAccountQuota attribute to 0 and limits the SeMachineAccountPrivilege user right to prevent unauthorized computer object creation by standard domain users.
REQ-ID-018 - Restrict Pre-Windows 2000 Compatible Access Group Limits the memberships of the legacy "Pre-Windows 2000 Compatible Access" group and restricts anonymous query options to prevent directory enumeration.
REQ-ID-019 - Enforce Smart Card Authentication for Privileged Users Enforces the 'Smart card is required for interactive logon' setting on administrative accounts to invalidate password hashes and force Kerberos PKINIT.
REQ-ID-020 - Clean Up Legacy Group Policy Preferences and SYSVOL Passwords Identifies and remediates Group Policy Preferences (GPP) XML files with
cpasswordproperties and legacy scripts containing cleartext credentials inside SYSVOL.