SIEM

Domain Controller Redundancy

Ensure Regular Backup of GPO’s

Ensure the Directory Services Restore Mode (DSRM) password is Set

To a known value on all Domain Controllers. The steps will need to be initiated on each Domain Controller:

   PS C:\Windows\system32> ntdsutil
   C:\Windows\System32\ntdsutil.exe: set drsm password
   Reset DRSM Administrator Password: reset password on server null
   Please type password for DS Restore Mode Administrator Account: ***
   Please confirm new password: ***
   Password has been set successfully.

Windows Firewall

RDP

Microsoft Local Administrator Password Solution (LAPS)

Least Privilege and Tiered Admin

Service Account Restrictions

Protected Users Security Group

Eliminate Older Operating Systems

Set GPO to Reprocess Even if Not Changed

Group Managed Service Accounts

Additional Resources