๐ ๏ธ Practical Bits
๐๐ผ ๐๐ผ๐ ๐๐๐ถ๐น๐น ๐ป๐ฒ๐ฒ๐ฑ ๐ฎ ๐ฃ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ ๐ฃ๐ผ๐น๐ถ๐ฐ๐ ๐ป๐ผ๐๐ฎ๐ฑ๐ฎ๐๐?
Yes โ even if you use MFA or passwordless options.
In Active Directory there are always ๐ฒ๐ ๐ฐ๐ฒ๐ฝ๐๐ถ๐ผ๐ป๐: service accounts, temporary accounts, break-glass accounts, newly created usersโฆ and those still rely on passwords. Strong password + lockout policies ๐ฟ๐ฎ๐ถ๐๐ฒ ๐๐ต๐ฒ ๐ฏ๐ฎ๐ฟ against password spraying and brute force.
โ Hereโs a simple checklist you can apply today:
1๏ธโฃ ๐ข๐ป๐ฒ ๐ฏ๐ฎ๐๐ฒ๐น๐ถ๐ป๐ฒ ๐ฝ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ + ๐น๐ผ๐ฐ๐ธ๐ผ๐๐ ๐ฝ๐ผ๐น๐ถ๐ฐ๐ (domain-wide)
Make sure you have one policy for the whole domain (use CIS/NIST as a reference, or your standard).
โ And no โ ๐๐ผ๐ ๐ฐ๐ฎ๐ปโ๐ โ๐๐๐ฎ๐ฐ๐ธโ multiple GPOs for the default domain password/lockout policy.
2๏ธโฃ ๐๐ถ๐ป๐ฒ-๐๐ฟ๐ฎ๐ถ๐ป๐ฒ๐ฑ ๐ฃ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ ๐ฃ๐ผ๐น๐ถ๐ฐ๐ถ๐ฒ๐ (FGPP) for privileged + service accounts
If you can, create one or more FGPPs for:
โข ๐ฝ๐ฟ๐ถ๐๐ถ๐น๐ฒ๐ด๐ฒ๐ฑ admin accounts
โข ๐๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ accounts
These often need stricter settings (especially length). FGPP is scoped to groups/identities, which is exactly what you want.
โDonโt forget the hard part: ๐ฒ๐ป๐ณ๐ผ๐ฟ๐ฐ๐ฒ๐บ๐ฒ๐ป๐
Having a policy is only step one โ you still need to make accounts comply. They will change their passwords as expiration goes. But you also want to make sure there are ๐ป๐ผ ๐๐๐ฎ๐น๐ฒ, ๐ถ๐ป๐ฎ๐ฐ๐๐ถ๐๐ฒ and other kind of accounts with ๐ต๐ถ๐๐๐ผ๐ฟ๐ถ๐ฐ ๐ฝ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ๐.
Start by finding accounts that havenโt changed passwords in a long time (e.g., 1 year+) and review Password Never Expires.
____
๐ฃ๐ผ๐๐ฒ๐ฟ๐ฆ๐ต๐ฒ๐น๐น (๐ฎ๐ฐ๐ฐ๐ผ๐๐ป๐๐ ๐๐ถ๐๐ต ๐ฝ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ ๐ผ๐น๐ฑ๐ฒ๐ฟ ๐๐ต๐ฎ๐ป ๐ญ ๐๐ฒ๐ฎ๐ฟ):
Get-ADUser -Filter ‘enabled -eq $true’ -Properties Name, PwdLastSet,lastlogonTimestamp | select name, @{N=’pwdlastset’ ; E={[DateTime]::FromFileTime($_.PwdLastSet)}}, @{N=’LastLogonTimestamp’ ; E={[DateTime]::FromFileTime($_.lastlogonTimestamp)}} | Where-Object {$_.PwdLastSet -le $(Get-Date -date $(get-date).AddDays(-365))} | Sort-Object -Property PwdLastSet
____
(๐๐ง ๐ช๐จ๐ ๐ข๐ฎ ๐๐ง๐๐ ๐ผ๐ฟ๐๐ง๐ค๐๐ ๐ฉ๐ค๐ค๐ก)
Thatโs it โ one small move, but a real step toward a safer AD.
