Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Microsoft Ignite 2015 9/21/2018 5:56 PM Righting the Right Rights: Active Directory & Domain Security, Administration & Maintenance M354 Jess Dodson © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Security Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Accounts Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Accounts – you need more than one! Microsoft Ignite 2015 9/21/2018 5:56 PM Accounts – you need more than one! © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Different Accounts Standard account Desktop admin account Microsoft Ignite 2015 9/21/2018 5:56 PM Different Accounts Standard account Desktop admin account Server admin account Domain admin account © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Domain admin accounts never logon to workstations OR servers Microsoft Ignite 2015 9/21/2018 5:56 PM Domain admin accounts never logon to workstations OR servers © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Limit access to your accounts Microsoft Ignite 2015 9/21/2018 5:56 PM Limit access to your accounts © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Keep accounts out of your admin groups Microsoft Ignite 2015 9/21/2018 5:56 PM Keep accounts out of your admin groups © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Who actually needs to be a Microsoft Ignite 2015 9/21/2018 5:56 PM Who actually needs to be a Domain Admin anyway? © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Passwords Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Do not use the default Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Don’t use the same password…for everything Microsoft Ignite 2015 9/21/2018 5:56 PM Don’t use the same password…for everything © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Make sure passwords EXPIRE Microsoft Ignite 2015 9/21/2018 5:56 PM Make sure passwords EXPIRE © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
longer time between changes Microsoft Ignite 2015 9/21/2018 5:56 PM Longer password = longer time between changes XKCD.com https://telepathwords.research.microsoft.com/ © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Use fine-grained password policies Microsoft Ignite 2015 9/21/2018 5:56 PM Use fine-grained password policies (FGPPs) © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Passwords do not belong in GPP’s… EVER Microsoft Ignite 2015 9/21/2018 5:56 PM Passwords do not belong in GPP’s… EVER (MS14-025) © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Microsoft Ignite 2015 9/21/2018 5:56 PM Randomise your local admin passwords – Local Administrator Password Solution (LAPS)! © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Prevent local admin accounts from remotely accessing other systems Microsoft Ignite 2015 9/21/2018 5:56 PM Prevent local admin accounts from remotely accessing other systems © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Servers Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Patch your servers! Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Limit RDP ability Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Only DA’s can access the console of DC’s Microsoft Ignite 2015 9/21/2018 5:56 PM Only DA’s can access the console of DC’s © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Trusts – who actually needs access? Microsoft Ignite 2015 9/21/2018 5:56 PM Trusts – who actually needs access? © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Security Compliance Manager (SCM) – your new bestest friend Microsoft Ignite 2015 9/21/2018 5:56 PM Security Compliance Manager (SCM) – your new bestest friend © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Workstations Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Admin workstation =/= user workstation Microsoft Ignite 2015 9/21/2018 5:56 PM Admin workstation =/= user workstation © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Administration & Maintenance Microsoft Ignite 2015 9/21/2018 5:56 PM Administration & Maintenance © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Account Administration Azure – AADC & AADC Health Microsoft Ignite 2015 9/21/2018 5:56 PM Replication FSMO Roles Time Synchronization Trusts DNS & Networking Event Logs Account Administration Azure – AADC & AADC Health © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Replication Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
repadmin /replsummary Microsoft Ignite 2015 9/21/2018 5:56 PM repadmin /replsummary © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
repadmin /showrepl * /errorsonly Microsoft Ignite 2015 9/21/2018 5:56 PM repadmin /showrepl * /errorsonly © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
repadmin /showutdvec * dc=<domain>,dc=<com> Microsoft Ignite 2015 9/21/2018 5:56 PM repadmin /showutdvec * dc=<domain>,dc=<com> © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
repadmin /queue * Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
repadmin /failcache Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
FSMO Roles Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
netdom query fsmo Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Time Settings Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
W32tm /config /syncfromflags:domhier /update Microsoft Ignite 2015 9/21/2018 5:56 PM w32tm /config /manualpeerlist:<list of time servers> /syncfromflags:manual /reliable:yes /update W32tm /config /syncfromflags:domhier /update © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
w32tm /query /configuration Microsoft Ignite 2015 9/21/2018 5:56 PM w32tm /query /configuration © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Trusts Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
nltest /domain_trusts Microsoft Ignite 2015 9/21/2018 5:56 PM nltest /domain_trusts © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
DNS & Networking Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
type %systemroot%\debug\netlogon.log | findstr NO_CLIENT_SITE Microsoft Ignite 2015 9/21/2018 5:56 PM type %systemroot%\debug\netlogon.log | findstr NO_CLIENT_SITE © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Ports 53 – DNS 389 – LDAP 88 – Kerberos 636 – LDAP SSL 445 – SMB/IP Microsoft Ignite 2015 9/21/2018 5:56 PM Ports 389 – LDAP 636 – LDAP SSL 3268 – LDAP GC 3269 – LDAP GC SSL 135 – EPC, EPM 53 – DNS 88 – Kerberos 445 – SMB/IP 139 – NetBIOS Session Port 123 – NTP Time Services © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Event Logs Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
System Events 29: Time synchronization failure Microsoft Ignite 2015 9/21/2018 5:56 PM System Events 29: Time synchronization failure 55: Possible file system corruption 1056: DHCP service is running on a DC without credentials 16645: RID Pool depleted 16650: Account-identifier failed to initialize © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
DNS Events 5774: DNS registration failure Microsoft Ignite 2015 9/21/2018 5:56 PM DNS Events 5774: DNS registration failure 5775: DNS de-registration failure 5781: DNS registration or deregistration failure © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Security & Directory Service events Microsoft Ignite 2015 9/21/2018 5:56 PM Security & Directory Service events ALL events © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Advanced Audit Policies (GPO) Microsoft Ignite 2015 9/21/2018 5:56 PM Advanced Audit Policies (GPO) Computer Configuration – Windows Settings – Security Settings – Advanced Audit Configuration © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Account Monitoring & Administration Microsoft Ignite 2015 9/21/2018 5:56 PM Account Monitoring & Administration © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Account lockout failures & failed login attempts Microsoft Ignite 2015 9/21/2018 5:56 PM Account lockout failures & failed login attempts © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Microsoft Ignite 2015 9/21/2018 5:56 PM Check admin group memberships & monitor addition/removal from security groups Enterprise Admins Schema Admins Domain Admins Administrators Backup Operators Event Log Readers Remote Management Users Server Operators © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
ALL THE THINGS! Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
dcdiag /c Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Azure Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Azure Active Directory Connect - Synchronization Service Manager Microsoft Ignite 2015 9/21/2018 5:56 PM Azure Active Directory Connect - Synchronization Service Manager © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Azure Active Directory Connect - Synchronization Service Manager Microsoft Ignite 2015 9/21/2018 5:56 PM Azure Active Directory Connect - Synchronization Service Manager status = success Office 365 - Settings - > Organization profile -> Technical Contact © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Azure Active Directory Connect Health Microsoft Ignite 2015 9/21/2018 5:56 PM Azure Active Directory Connect Health Requires Azure AD Premium Requires agent on each identity server Out-of-the-box monitoring – very little configuration Monitors AD DS & AD FS + AADC sync info https://azure.microsoft.com/en-us/documentation/articles/active-directory-aadconnect-health/ © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Azure Active Directory Connect Health Microsoft Ignite 2015 Azure Active Directory Connect Health 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Continue your Ignite learning path Microsoft Ignite 2015 9/21/2018 5:56 PM Continue your Ignite learning path Pass-the-Hash Attacks http://bit.ly/2dVT0ng Securing Active Directory: Best Practices http://aka.ms/bpsad Microsoft Security Compliance Manager http://aka.ms/scm Advanced Audit Policies http://bit.ly/2dMctaU LAPS https://adsecurity.org/?p=1790 © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Continue your Ignite learning path Microsoft Ignite 2015 9/21/2018 5:56 PM Continue your Ignite learning path AD Security & Administration http://girl-germs.com/?p=459 Regular AD Maintenance & Checks http://girl-germs.com/?p=564 FGPP’s & PSO’s http://girl-germs.com/?p=967 Advanced Audit Policy EventID info https://girl-germs.com/?p=363 DC Security Logs http://girl-germs.com/?p=1538 © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Contact me! Twitter: @girlgerms (best way!) Microsoft Ignite 2015 9/21/2018 5:56 PM Contact me! Twitter: @girlgerms (best way!) Email: jess@girl-germs.com Linkedin: https://au.linkedin.com/in/jrdodson Blog: http://girl-germs.com © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Questions? Microsoft Ignite 2015 9/21/2018 5:56 PM © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.