ANSSI Active Directory Hardening Compliance Matrix
This document maps the recommendations of the ANSSI (French National Agency for the Security of Information Systems) Active Directory Hardening Guide and related secure administration guides to the technical security controls present in this guidebook.
Mapped ANSSI Recommendations
| ID | Recommendation Description | Category | Status | Mapped Technical Control(s) |
|---|---|---|---|---|
| R1 | Define and implement a logical partitioning model (Tiering) | Tiering / Admin Boundaries | Covered | REQ-ARCH-001, REQ-ARCH-002, REQ-ARCH-003 |
| R2 | Limit and control administrative privileges | Account Restrictions | Covered | REQ-ARCH-001, REQ-END-006, REQ-PAW-003 |
| R3 | Use dedicated administrative accounts and secure stations | PAW & Admin Accounts | Covered | REQ-ARCH-001, REQ-PAW-001, REQ-PAW-002, REQ-PAW-003, REQ-PAW-004, REQ-PAW-005, REQ-PAW-006, REQ-PAW-007, REQ-PAW-008, REQ-PAW-009, REQ-PAW-010, REQ-PAW-011, REQ-PAW-012, REQ-PAW-013, REQ-PAW-036 |
| R4 | Minimize services and software on Domain Controllers | Service Minimization | Covered | REQ-DC-008, REQ-DC-012 |
| R5 | Keep Forest and Domain functional levels up-to-date | Functional Levels | Covered | REQ-ARCH-004 |
| R6 | Restrict membership of default administrative groups | Privileged Group Audit | Covered | REQ-ARCH-003, REQ-ID-010 |
| R7 | Configure IPsec transport mode for domain isolation | Network Cryptography | Covered | REQ-NET-004, REQ-NET-005 |
| R8 | Restrict administration protocols to dedicated subnets and jump hosts | Management Ports & Subnets | Covered | REQ-NET-001, REQ-NET-002, REQ-NET-003, REQ-ARCH-002 |
| R9 | Deploy Local Administrator Password Solution (LAPS) | Local Admin Passwords | Covered | REQ-ID-002 |
| R10 | Restrict authentication delegation and administrative tool execution | AppLocker / Delegation | Covered | REQ-DC-021, REQ-DC-034, REQ-PAW-001, REQ-PAW-036, REQ-END-011, REQ-END-027 |
| R11 | Enforce NTLM restriction policies | NTLM Restriction | Covered | REQ-DC-014 |
| R12 | Disable obsolete name resolution protocols (LLMNR/NetBIOS) | Name Resolution | Covered | REQ-DC-002, REQ-END-001 |
| R13 | Deprecate legacy protocols and enforce transport security | Obsolete Protocols | Covered | REQ-DC-001, REQ-DC-003, REQ-DC-010 |
| R14 | Enforce LSA Protection and Credential Guard | Credential Isolation | Covered | REQ-DC-006, REQ-DC-007, REQ-PAW-002, REQ-PAW-010, REQ-END-010, REQ-END-023 |
| R15 | Prohibit unconstrained Kerberos delegation | Kerberos Delegation | Covered | REQ-ID-004 |
| R16 | Restrict constrained Kerberos delegation | Kerberos Delegation | Covered | REQ-ID-004 |
| R17 | Enforce strong Kerberos encryption algorithms (AES-only) | Kerberos Encryption | Covered | REQ-DC-010, REQ-ID-008 |
| R18 | Harden TLS protocols, cipher suites, and elliptic curves (Schannel) | TLS / Cryptography | Covered | REQ-NET-006 |
| R19 | Enforce LDAP server signing and client-side resolution settings | LDAP Security | Covered | REQ-DC-004, REQ-DC-024, REQ-NET-009 |
| R20 | Enforce LDAP Channel Binding and Kerberos Armoring | LDAP Channel Binding | Covered | REQ-DC-005, REQ-DC-013 |
| R21 | Disable SMBv1 on all network nodes | SMB Security | Covered | REQ-DC-001, REQ-END-026 |
| R22 | Enforce SMB signing and encryption | SMB Security | Covered | REQ-DC-009, REQ-NET-007 |
| R23 | Harden and protect adminSDHolder permissions | adminSDHolder Permissions | Covered | REQ-DC-016, REQ-DC-024, REQ-ID-013 |
| R24 | Harden Active Directory Domain Trusts (SID history/filtering) | Domain Trusts | Covered | REQ-ARCH-006 |
| R35 | Implement Group Managed Service Accounts (gMSA) | Service Account Hardening | Covered | REQ-ID-003, REQ-ID-014 |
| R36 | Harden Active Directory Certificate Services (ADCS) and PKI | ADCS / PKI Hardening | Covered | REQ-ID-015 |
| R37 | Revoke obsolete and insecure certificate templates | ADCS / PKI Hardening | Covered | REQ-ID-015 |
| R47 | Harden virtualization hosts for Domain Controllers | DC Virtualization | Covered | REQ-DC-018 |
| R48 | Configure advanced security audit policies | Audit Policies | Covered | REQ-LOG-001 |
| R50 | Configure PowerShell and command-line auditing | PowerShell Auditing | Covered | REQ-LOG-002 |
| R52 | Deploy and harden Sysmon and configure SIEM log shipping | Monitoring & Shipping | Covered | REQ-LOG-003, REQ-LOG-004 |
| R54 | Establish secure Domain Controller backup and disaster recovery | Disaster Recovery | Covered | REQ-OPS-002, REQ-OPS-008 |
| R57 | Perform continuous security assessments and privileged group audits | Security Assessments | Covered | REQ-ARCH-003, REQ-OPS-010 |
| R58 | Deploy and harden Privileged Access Workstations (PAWs) | PAW Deployment | Covered | REQ-PAW-001, REQ-PAW-004, REQ-PAW-005, REQ-PAW-006 |
| R64 | Configure Active Directory Authentication Silos and Policies | Authentication Silos | Covered | REQ-ID-012 |
| R80 | Configure Authentication Policies for administrative groups | Authentication Silos | Covered | REQ-ID-012 |
Administrative / Operational Recommendations (Out of Scope)
The following ANSSI secure administration recommendations relate to organizational policy, administrative processes, physical security, or user training, which are outside the scope of technical GPO or PowerShell controls:
| ID | Recommendation Description | Category | Status | Notes |
|---|---|---|---|---|
| R26 | Inform administrators of security policies | Governance | Not Covered | Organizational policy / administrative training. |
| R27 | Maintain an up-to-date registry of administrative actions | Operations | Not Covered | Operational procedure / manual record-keeping. |
| R30 | Periodically audit administration workstations | Operations | Not Covered | Process-based vulnerability scans and compliance checks. |
| R31 | Physically secure administration environments | Physical Security | Not Covered | Server room access controls, locked server racks, etc. |
| R32 | Establish separate domain names for administration zones | Architecture | Not Covered | Organizational DNS design recommendation. |