<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Active Directory | Florian Stosse</title><link>https://me.harvester.fr/tags/active-directory/</link><atom:link href="https://me.harvester.fr/tags/active-directory/index.xml" rel="self" type="application/rss+xml"/><description>Active Directory</description><generator>HugoBlox Kit (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Mon, 20 May 2024 00:00:00 +0000</lastBuildDate><image><url>https://me.harvester.fr/media/icon_hu_59c72f5082cfcb9b.png</url><title>Active Directory</title><link>https://me.harvester.fr/tags/active-directory/</link></image><item><title>ad-hardening</title><link>https://me.harvester.fr/project/ad-hardening/</link><pubDate>Mon, 20 May 2024 00:00:00 +0000</pubDate><guid>https://me.harvester.fr/project/ad-hardening/</guid><description>&lt;p&gt;&lt;strong&gt;ad-hardening&lt;/strong&gt; is a comprehensive guidebook and reference repository dedicated to securing and hardening Active Directory (AD) environments in air-gapped, isolated networks. While physical isolation eliminates many remote threats, it places a heavier security premium on internal access control, endpoint hygiene, and physical media management.&lt;/p&gt;
&lt;p&gt;This project outlines step-by-step guidance, configurations, and templates to establish a resilient security posture inside sensitive, non-internet-connected directory environments.&lt;/p&gt;
&lt;h3 id="core-hardening-pillars"&gt;Core Hardening Pillars&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Tiered Administrative Model:&lt;/strong&gt; Isolating Tier 0 (Domain Controllers/Admins) credentials from Tier 1 (Servers) and Tier 2 (Workstations) to eliminate lateral escalation risks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Offline Authentication &amp;amp; MFA:&lt;/strong&gt; Strategies for deploying local, offline-capable multi-factor authentication without internet-based validation services.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Service Account Securing:&lt;/strong&gt; transitioning legacy service accounts to Group Managed Service Accounts (gMSAs) to enforce automatic password rotation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Audit &amp;amp; Event Analysis:&lt;/strong&gt; Configuration templates for offline Windows Event Forwarding (WEF) and local security log auditing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Removable Media Control:&lt;/strong&gt; Hardening USB and other removable hardware access policies via Group Policy Objects (GPOs) to combat sneakernet malware propagation vectors.&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Security-ADMX</title><link>https://me.harvester.fr/project/security-admx/</link><pubDate>Sun, 19 May 2024 00:00:00 +0000</pubDate><guid>https://me.harvester.fr/project/security-admx/</guid><description>&lt;p&gt;&lt;strong&gt;Security-ADMX&lt;/strong&gt; is a collection of custom Administrative Templates (&lt;code&gt;.admx&lt;/code&gt; and &lt;code&gt;.adml&lt;/code&gt;) specifically designed for hardening Windows 10 and Windows 11 workstations. It allows system administrators and security engineers to configure advanced security settings via local or domain Group Policy (GPO) that are otherwise difficult or tedious to manage.&lt;/p&gt;
&lt;p&gt;Developed out of the need to streamline security compliance across embedded and workstation deployments, this project packages several security controls into easily manageable policies.&lt;/p&gt;</description></item></channel></rss>