Pick only 3 security controls for your AD

๐Ÿ”’ย Secure Bits ๐Ÿ’ก

๐—œ๐—ณ ๐˜†๐—ผ๐˜‚ ๐—ฐ๐—ผ๐˜‚๐—น๐—ฑ ๐—ธ๐—ฒ๐—ฒ๐—ฝ ๐—ผ๐—ป๐—น๐˜† ๐Ÿฏ ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฐ๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐˜€ ๐—ถ๐—ป ๐—ฎ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐—ฒ๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜ – ๐˜„๐—ต๐—ฎ๐˜ ๐˜„๐—ผ๐˜‚๐—น๐—ฑ ๐˜†๐—ผ๐˜‚ ๐—ฝ๐—ถ๐—ฐ๐—ธ?

Iโ€™m curious what your โ€œtop 3โ€ are (I know it depends a lot on what we are protecting, but let’s try).

๐—œ๐—ณ ๐—œ ๐—ต๐—ฎ๐—ฑ ๐˜๐—ผ ๐—ฐ๐—ต๐—ผ๐—ผ๐˜€๐—ฒ (๐—ป๐—ผ๐˜ ๐—ฎ ๐˜€๐—ถ๐—บ๐—ฝ๐—น๐—ฒ ๐—ฐ๐—ต๐—ผ๐—ถ๐—ฐ๐—ฒ), ๐—บ๐—ถ๐—ป๐—ฒ ๐˜„๐—ผ๐˜‚๐—น๐—ฑ ๐—ฏ๐—ฒ:

1๏ธโƒฃย ๐—ง๐—ถ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด ๐— ๐—ผ๐—ฑ๐—ฒ๐—น (๐—Ÿ๐—ฒ๐—ฎ๐˜€๐˜ ๐—ฃ๐—ฟ๐—ถ๐˜ƒ๐—ถ๐—น๐—ฒ๐—ด๐—ฒ)

Separate roles and assets into tiers and useย separate admin accounts.

โœ… Goal: make it hard/impossible to steal high-privilege creds from lower tiers (workstations, file servers, etc.).

I consider removing local admin rights for users being part of this measure, as you are creating separated accounts and mapping the admin rights in general.

2๏ธโƒฃ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—•๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€

Defaults on modern Windows are getting better (Server 2025 / Win11), but environments arenโ€™t always new – and settings drift over time.

โœ… Baselines give you aย known secure standardย and help prevent common abuse like credential harvesting/coercion, responder-style issues, and other โ€œeasy winsโ€.

3๏ธโƒฃ ๐—”๐—ฝ๐—ฝ๐—น๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—”๐—น๐—น๐—ผ๐˜„๐—น๐—ถ๐˜€๐˜๐—ถ๐—ป๐—ด

Hard to roll out at scale, but worth it.

โœ… Allow only what you need, and you stop a huge class of malware by default – without chasing every new threat.

(๐˜ ๐˜ฆ๐˜ด, ๐˜โ€™๐˜ฅ ๐˜ด๐˜ต๐˜ช๐˜ญ๐˜ญ ๐˜ธ๐˜ข๐˜ฏ๐˜ต ๐˜Œ๐˜‹๐˜™/๐˜ค๐˜ฆ๐˜ฏ๐˜ต๐˜ณ๐˜ข๐˜ญ ๐˜ท๐˜ช๐˜ด๐˜ช๐˜ฃ๐˜ช๐˜ญ๐˜ช๐˜ต๐˜บ โ€” ๐˜ฃ๐˜ถ๐˜ต ๐˜ช๐˜ง ๐˜โ€™๐˜ฎ ๐˜ญ๐˜ช๐˜ฎ๐˜ช๐˜ต๐˜ฆ๐˜ฅ ๐˜ต๐˜ฐ ๐˜ต๐˜ฉ๐˜ณ๐˜ฆ๐˜ฆ, ๐˜โ€™๐˜ฎ ๐˜จ๐˜ฐ๐˜ช๐˜ฏ๐˜จ ๐˜ง๐˜ฐ๐˜ณ ๐˜ฑ๐˜ณ๐˜ฆ๐˜ท๐˜ฆ๐˜ฏ๐˜ต๐˜ช๐˜ท๐˜ฆ ๐˜ค๐˜ฐ๐˜ฏ๐˜ต๐˜ณ๐˜ฐ๐˜ญ๐˜ด, ๐˜ฏ๐˜ฐ๐˜ต ๐˜ณ๐˜ฆ๐˜ข๐˜ค๐˜ต๐˜ช๐˜ท๐˜ฆ ๐˜ฐ๐˜ฏ๐˜ฆ๐˜ด.)

๐Ÿงฉย ๐—ฌ๐—ผ๐˜‚๐—ฟ ๐˜๐˜‚๐—ฟ๐—ป:ย pick your top 3 from the image (or create your own) and commentย your three choices + why.