What It Delivers
Full AD Identity Census
Every user, computer, service account, and admin group enumerated and assessed. Stale accounts (no logon in 90+ days), orphaned objects (owner departed), and service accounts with non-expiring passwords flagged. The privilege map you didn't know you had.
Compromised Credential Audit
AD password hashes compared against known-breached credential databases (Elysium / Have I Been Pwned corpus). Accounts using passwords that appear in breach databases identified and forced to reset โ before an attacker uses them. This consistently surfaces accounts that have been silently compromised for months.
KRBTGT Rotation and Golden Ticket Invalidation
KRBTGT account rotated twice in sequence (required to invalidate any existing Kerberos tickets, including forged golden tickets). Procedure documented for future rotations. A non-rotated KRBTGT is a persistent attacker foothold that survives every other remediation you run.
LAPS and Privileged Access Workstations
Local Administrator Password Solution deployed so every machine has a unique, rotating local admin password โ eliminating the lateral movement path of a shared local admin credential. PAW architecture designed for admin tasks to prevent credential theft from the workstations used to manage Tier 0 systems.
Sysmon Deployment and Entra Connect Hardening
Sysmon deployed to endpoints for detailed process creation, network connection, and registry change logging โ the telemetry source that turns a security incident from "we don't know what happened" to "we have the full timeline." Entra Connect sync account permissions tightened and sync server isolated: the bridge between on-premises and cloud is a Tier 0 asset and must be protected as one.
The Hybrid Identity Risk
In a hybrid environment, the on-premises AD and the cloud tenant are linked. Compromise of the Entra Connect sync account โ a common, often overlooked target โ gives an attacker the ability to manipulate cloud identities from on-premises. The on-premises security posture is a cloud security question. This module treats it as one.
Scope and Prerequisites
| Duration | 45โ60 days |
| Environment | On-premises AD with or without hybrid M365 |
| Prerequisites | Domain Admin access; Module 2 (Identity) for cloud-side alignment if hybrid |
| Natural follow-on | Module 12 (T0 Asset Protection) for crown-jewel isolation; Module 13 (Privileged Access Architecture) for PAM |
The cloud is only as secure as the AD behind it
Most kill chains pass through on-premises AD even when the target is cloud resources. Module 6 closes the path.