From the course: Configuring Windows Server Hybrid Advanced Services (AZ-801) Cert Prep by Microsoft Press
Unlock this course with a free trial
Join today to access over 25,200 courses taught by industry experts.
Harden domain controllers
From the course: Configuring Windows Server Hybrid Advanced Services (AZ-801) Cert Prep by Microsoft Press
Harden domain controllers
Even with protected users and read-only domain controllers in place, DCs themselves remain high-value targets, hardening them directly as a non-negotiable. Here we highlight key techniques that limit credential theft and keep attackers from moving laterally. Restricted Admin Mode prevents credential exposure via the Remote Desktop Protocol, RDP. When you remote into a DC using Remote Desktop Protocol, your credentials normally get stored in memory. Restricted Admin Mode stops this by authenticating with the machine account instead of your user account, so nothing reusable is left behind. Protected Process Light, PPL, protects LSAS from memory attacks. LSAS stands for Local Security Authority Subsystem Service, and it's where Windows stores cached credentials. Tools like Mimikatz target it directly. Running LSAS as a protected process means only trusted, signed code can access it, shutting down many common credential dumping attacks. LSA protection blocks unauthorized code injection…
Download courses and learn on the go
Watch courses on your mobile device without an internet connection. Download courses using your iOS or Android LinkedIn Learning app.
Contents
-
-
(Locked)
Learning objectives40s
-
(Locked)
Configure and manage exploit protection1m 50s
-
(Locked)
Configure and manage Windows Defender Application Control1m 31s
-
(Locked)
Configure and manage Windows Defender Credential Guard1m 47s
-
(Locked)
Configure SmartScreen1m 6s
-
(Locked)
Implement operating system security by using Group Policies1m 6s
-
(Locked)
Manage Windows Server security baseline by using OSConfig1m 1s
-
(Locked)
Configure secured-core Server features for high-security workloads17m 16s
-
(Locked)
-
-
(Locked)
Learning objectives39s
-
(Locked)
Configure authentication policy silos4m 30s
-
(Locked)
Restrict access to domain controllers1m 47s
-
(Locked)
Configure security options for user accounts1m 21s
-
(Locked)
Configure security options for built-in administrative groups1m 46s
-
(Locked)
Manage AD delegation2m 54s
-
(Locked)
Implement Just Enough Administration (JEA) and Just-In-Time (JIT) privileged access17m 7s
-
(Locked)
-
-
(Locked)
Learning objectives42s
-
(Locked)
Implement and manage Microsoft Defender for Identity3m 5s
-
(Locked)
Audit usage of and disable NTLM2m 40s
-
(Locked)
Implement ingestion of Windows Server data into Microsoft Sentinel3m 23s
-
(Locked)
Manage security for Windows Server by using Microsoft Defender for Cloud3m 49s
-
(Locked)
Manage security for Windows Server by using Microsoft Defender for Servers2m 44s
-
(Locked)
Implement hotpatching for Windows Server Azure Edition virtual machines18m 44s
-
(Locked)
-
-
(Locked)
Learning objectives42s
-
(Locked)
Manage Windows BitLocker Drive Encryption2m 32s
-
(Locked)
Enable storage encryption by using Azure Disk Encryption2m 26s
-
(Locked)
Manage and recover encrypted volumes1m 34s
-
(Locked)
Manage disk encryption keys for IaaS virtual machines2m 55s
-
(Locked)
Configure File Server Resource Manager (FSRM) and Storage QoS for workload governance25m 51s
-
(Locked)
-
-
(Locked)
Learning objectives41s
-
(Locked)
Implement a failover cluster on-premises, hybrid, or cloud-only1m 49s
-
(Locked)
Create a Windows failover cluster, including workgroup clusters1m 28s
-
(Locked)
Implement a stretch cluster across datacenters or Azure regions, including Storage Spaces Direct (S2D) campus clusters2m 16s
-
(Locked)
Configure storage for failover clustering1m 56s
-
(Locked)
Modify quorum options1m 20s
-
(Locked)
Configure network adapters for failover clustering17m 58s
-
(Locked)
-
-
(Locked)
Learning objectives41s
-
(Locked)
Deploy and troubleshoot deployment, validation and cluster networking with Network ATC4m 36s
-
(Locked)
Configure cluster workload options2m 43s
-
(Locked)
Configure Scale-Out File servers2m 35s
-
(Locked)
Configure an Azure witness2m 31s
-
(Locked)
Configure a floating IP address for the cluster14m 5s
-
(Locked)
-
-
(Locked)
Learning objectives37s
-
(Locked)
Implement cluster-aware updating2m 27s
-
(Locked)
Recover a failed cluster node2m 49s
-
(Locked)
Upgrade failover cluster nodes3m 7s
-
(Locked)
Failover workloads between nodes3m 2s
-
(Locked)
Install Windows updates on cluster nodes2m 56s
-
(Locked)
Use Windows Admin Center as the primary management tool for hybrid and cluster operations12m 43s
-
(Locked)
-
-
(Locked)
Learning objectives43s
-
(Locked)
Backup and restore files and folders to Azure Recovery Services Vault5m 22s
-
(Locked)
Deploy and manage Azure Backup Server3m 2s
-
(Locked)
Back up and recover using Azure Backup Server2m 40s
-
(Locked)
Manage backups in Azure Recovery Services Vault2m 11s
-
(Locked)
Create an Azure Recovery Services Vault backup policy2m 20s
-
(Locked)
Implement ransomware-aware backup and recovery strategies, including immutable storage and recovery testing15m 28s
-
(Locked)
-
-
(Locked)
Learning objectives40s
-
(Locked)
Configure Azure Site Recovery network mapping4m 54s
-
(Locked)
Configure Site Recovery for on-premises servers3m 31s
-
(Locked)
Configure a recovery plan in Azure Site Recovery3m 3s
-
(Locked)
Configure Site Recovery for Azure VMs2m 54s
-
(Locked)
Implement VM replication to secondary datacenter or Azure region3m 11s
-
(Locked)
Configure Azure Site Recovery replication policies17m 10s
-
(Locked)
-
-
(Locked)
Learning objectives33s
-
(Locked)
Transfer files, file shares, and security configurations by using Storage Migration Service (SMS)3m 55s
-
(Locked)
Cut over to a new server by using Storage Migration Service (SMS)2m 44s
-
(Locked)
Use Storage Migration Service to migrate to Azure VMs5m
-
(Locked)
Migrate to Azure file shares16m 18s
-
(Locked)
-
-
(Locked)
Learning objectives37s
-
(Locked)
Choose an appropriate migration method4m 12s
-
(Locked)
Implement a forest restructure2m 13s
-
(Locked)
Migrate AD DS objects, including users, groups and Group Policies using AD Migration Tool2m 34s
-
(Locked)
Migrate to a new Active Directory forest2m 39s
-
(Locked)
Upgrade an existing forest, including setting functional levels11m 47s
-
(Locked)
-
-
(Locked)
Learning objectives34s
-
(Locked)
Monitor Windows Server by using Performance Monitor4m 49s
-
(Locked)
Create and configure Data Collector Sets2m 56s
-
(Locked)
Monitor servers and configure alerts by using Windows Admin Center2m 57s
-
(Locked)
Analyze Windows Server system data by using System Insights2m 59s
-
(Locked)
Manage event logs20m 26s
-
(Locked)
-
-
(Locked)
Learning objectives35s
-
(Locked)
Configure data collection rules for Azure Monitor5m 9s
-
(Locked)
Create alerts1m 53s
-
(Locked)
Monitor Azure VM performance by using VM Insights2m 26s
-
(Locked)
Manage Windows Server resources with Azure Arc extensions and policies1m 46s
-
(Locked)
Configure Azure Update Manager for hybrid patch orchestration17m 5s
-
(Locked)
-
-
(Locked)
Learning objectives43s
-
(Locked)
Restore objects from AD recycle bin4m 8s
-
(Locked)
Recover Active Directory database using Directory Services Restore Mode2m 11s
-
(Locked)
Recover system volume (SYSVOL)2m 23s
-
(Locked)
Troubleshoot Active Directory replication2m 28s
-
(Locked)
Troubleshoot hybrid authentication and synchronization issues2m 38s
-
(Locked)
Troubleshoot on-premises Active Directory2m 37s
-
(Locked)
Troubleshoot hybrid identity synchronization with Microsoft Entra Connect20m 1s
-
(Locked)