Securing Active Directory Domain Services
Securing Active Directory Domain Services
Securing Active Directory Domain Services
AD DS AD DS
What are RODCs?
Prerequisites:
ADPrep /RODCPrep
Sufficient Windows Server 2008 or newer replication partners for
the RODCs
For a one-step deployment, perform either of the following steps:
In Server Manager, open Add Roles and Features, and then use
Active Directory Domain Services Configuration Wizard
Windows PowerShell: Install-ADDSDomainController
ReadOnlyReplica
For a two-step deployment, perform the following steps:
1. Prestaging: Create the account by using Active Directory
Administrative Center or Add-
ADDSReadOnlyDomainControllerAccount
2. Delegated promotion: Join the RODC as delegated admin: Server
Manager or Install-ADDSDomainController -ReadOnlyReplica
Planning and configuring an RODC password
replication policy
Restricted groups:
You can control membership for local groups on
workstations and servers by using the following
attributes:
Members
Member of
You cannot use these with domain groups
Protected Users group:
Provides additional protection against the compromise
of credentials during authentication processes
Members of this group automatically have
nonconfigurable protection applied to their accounts
Fine-grained password and lockout policies
Add-FineGrainedPasswordPolicySubject
Active Directory Administrative Center
Demonstration: Configuring a fine-grained
password policy
Authentication policies:
Configured as authentication policy object in AD DS, applied to user,
service, or computer accounts
Custom TGT
Uses claims (DAC) for custom conditions
Server
PIN
TPM
Windows
Hello
Enhancing password authentication with
Windows Hello and MFA
Phone call
Mobile app
Lesson 3: Implementing audit authentication
AD DS
Account logon events:
The system that authenticates the
account registers these events
For domain accounts: domain Account logon
controllers event
For local accounts: local computer
Logon
Logon events: event
The machine at or to which a user
logged on registers these events
Interactive logon: user's system
Network logon: server
Logon
event
Demonstration: Configuring authentication-related
audit policies
Account Logon
logon events
events
Remote
Domain HR clients
Desktop
controllers OU
Server OU
Demonstration: Viewing logon events
Logon Information
Virtual machines: 20742B-LON-DC1
20742B-LON-SVR1
User name: Adatum\Administrator
Password: Pa55w.rd
Review Questions
Tools
Common Issues and Troubleshooting Tips