ANSSI Active Directory Hardening Compliance Matrix

This document maps the recommendations of the ANSSI (French National Agency for the Security of Information Systems) Active Directory Hardening Guide and related secure administration guides to the technical security controls present in this guidebook.

Mapped ANSSI Recommendations

ID Recommendation Description Category Status Mapped Technical Control(s)
R1 Define and implement a logical partitioning model (Tiering) Tiering / Admin Boundaries Covered REQ-ARCH-001, REQ-ARCH-002, REQ-ARCH-003
R2 Limit and control administrative privileges Account Restrictions Covered REQ-ARCH-001, REQ-END-006, REQ-PAW-003
R3 Use dedicated administrative accounts and secure stations PAW & Admin Accounts Covered REQ-ARCH-001, REQ-PAW-001, REQ-PAW-002, REQ-PAW-003, REQ-PAW-004, REQ-PAW-005, REQ-PAW-006, REQ-PAW-007, REQ-PAW-008, REQ-PAW-009, REQ-PAW-010, REQ-PAW-011, REQ-PAW-012, REQ-PAW-013, REQ-PAW-036
R4 Minimize services and software on Domain Controllers Service Minimization Covered REQ-DC-008, REQ-DC-012
R5 Keep Forest and Domain functional levels up-to-date Functional Levels Covered REQ-ARCH-004
R6 Restrict membership of default administrative groups Privileged Group Audit Covered REQ-ARCH-003, REQ-ID-010
R7 Configure IPsec transport mode for domain isolation Network Cryptography Covered REQ-NET-004, REQ-NET-005
R8 Restrict administration protocols to dedicated subnets and jump hosts Management Ports & Subnets Covered REQ-NET-001, REQ-NET-002, REQ-NET-003, REQ-ARCH-002
R9 Deploy Local Administrator Password Solution (LAPS) Local Admin Passwords Covered REQ-ID-002
R10 Restrict authentication delegation and administrative tool execution AppLocker / Delegation Covered REQ-DC-021, REQ-DC-034, REQ-PAW-001, REQ-PAW-036, REQ-END-011, REQ-END-027
R11 Enforce NTLM restriction policies NTLM Restriction Covered REQ-DC-014
R12 Disable obsolete name resolution protocols (LLMNR/NetBIOS) Name Resolution Covered REQ-DC-002, REQ-END-001
R13 Deprecate legacy protocols and enforce transport security Obsolete Protocols Covered REQ-DC-001, REQ-DC-003, REQ-DC-010
R14 Enforce LSA Protection and Credential Guard Credential Isolation Covered REQ-DC-006, REQ-DC-007, REQ-PAW-002, REQ-PAW-010, REQ-END-010, REQ-END-023
R15 Prohibit unconstrained Kerberos delegation Kerberos Delegation Covered REQ-ID-004
R16 Restrict constrained Kerberos delegation Kerberos Delegation Covered REQ-ID-004
R17 Enforce strong Kerberos encryption algorithms (AES-only) Kerberos Encryption Covered REQ-DC-010, REQ-ID-008
R18 Harden TLS protocols, cipher suites, and elliptic curves (Schannel) TLS / Cryptography Covered REQ-NET-006
R19 Enforce LDAP server signing and client-side resolution settings LDAP Security Covered REQ-DC-004, REQ-DC-024, REQ-NET-009
R20 Enforce LDAP Channel Binding and Kerberos Armoring LDAP Channel Binding Covered REQ-DC-005, REQ-DC-013
R21 Disable SMBv1 on all network nodes SMB Security Covered REQ-DC-001, REQ-END-026
R22 Enforce SMB signing and encryption SMB Security Covered REQ-DC-009, REQ-NET-007
R23 Harden and protect adminSDHolder permissions adminSDHolder Permissions Covered REQ-DC-016, REQ-DC-024, REQ-ID-013
R24 Harden Active Directory Domain Trusts (SID history/filtering) Domain Trusts Covered REQ-ARCH-006
R35 Implement Group Managed Service Accounts (gMSA) Service Account Hardening Covered REQ-ID-003, REQ-ID-014
R36 Harden Active Directory Certificate Services (ADCS) and PKI ADCS / PKI Hardening Covered REQ-ID-015
R37 Revoke obsolete and insecure certificate templates ADCS / PKI Hardening Covered REQ-ID-015
R47 Harden virtualization hosts for Domain Controllers DC Virtualization Covered REQ-DC-018
R48 Configure advanced security audit policies Audit Policies Covered REQ-LOG-001
R50 Configure PowerShell and command-line auditing PowerShell Auditing Covered REQ-LOG-002
R52 Deploy and harden Sysmon and configure SIEM log shipping Monitoring & Shipping Covered REQ-LOG-003, REQ-LOG-004
R54 Establish secure Domain Controller backup and disaster recovery Disaster Recovery Covered REQ-OPS-002, REQ-OPS-008
R57 Perform continuous security assessments and privileged group audits Security Assessments Covered REQ-ARCH-003, REQ-OPS-010
R58 Deploy and harden Privileged Access Workstations (PAWs) PAW Deployment Covered REQ-PAW-001, REQ-PAW-004, REQ-PAW-005, REQ-PAW-006
R64 Configure Active Directory Authentication Silos and Policies Authentication Silos Covered REQ-ID-012
R80 Configure Authentication Policies for administrative groups Authentication Silos Covered REQ-ID-012

Administrative / Operational Recommendations (Out of Scope)

The following ANSSI secure administration recommendations relate to organizational policy, administrative processes, physical security, or user training, which are outside the scope of technical GPO or PowerShell controls:

ID Recommendation Description Category Status Notes
R26 Inform administrators of security policies Governance Not Covered Organizational policy / administrative training.
R27 Maintain an up-to-date registry of administrative actions Operations Not Covered Operational procedure / manual record-keeping.
R30 Periodically audit administration workstations Operations Not Covered Process-based vulnerability scans and compliance checks.
R31 Physically secure administration environments Physical Security Not Covered Server room access controls, locked server racks, etc.
R32 Establish separate domain names for administration zones Architecture Not Covered Organizational DNS design recommendation.

results matching ""

    No results matching ""