Securing Active Directory — Practitioner Course
Harden on-prem and hybrid Active Directory against modern identity attacks
Active Directory remains the single largest blast radius in most Australian enterprises. This practitioner course gives identity engineers a tested playbook to harden domain controllers, contain privileged access, detect Kerberos abuse, and rehearse forest recovery before an attacker forces the issue.

At a Glance
Who it's for
- Active Directory and identity engineers responsible for on-prem and hybrid environments
- Security architects designing tiered administration and privileged access models
- IT managers accountable for identity resilience and Essential Eight Maturity Level 2 recovery controls
- Incident response and detection engineers building Kerberos and DCSync detections
Course Details
Course Overview
Active Directory underpins authentication for the majority of Australian enterprise, government and critical infrastructure environments, yet most forests still run with flat administrative models, unmanaged service accounts and unverified backups. This three-day practitioner course walks identity engineers through the controls Microsoft, the ACSC and incident responders agree actually matter: the tier model and Enterprise Admins isolation, domain controller hardening (LAPS, NTLM removal, SMB signing), Privileged Access Workstations, Kerberos and Golden Ticket detection, AD backup verification and full forest recovery rehearsals, and the risk register for hybrid Entra cutovers. Every module pairs Microsoft and ACSC reference guidance with current attacker tradecraft — Mimikatz, DCSync, Kerberoasting, AdminSDHolder abuse — so participants leave with a tested playbook and the evidence to brief executives on residual identity risk.
What You'll Learn
Course Curriculum
Module 1: AD Tier Model and Enterprise Admins Isolation
4 hours- Microsoft's tier 0/1/2 administrative model — what changed in the "Securing Privileged Access" reference (Microsoft, updated 2024)
- Removing standing Enterprise Admins and Domain Admins membership
- Time-bound elevation patterns using Privileged Identity Management and just-in-time groups
- AdminSDHolder, Protected Users group and authentication policy silos
- Mapping the tier model to the ACSC Essential Eight "restrict administrative privileges" control
Module 2: Hardening Domain Controllers — LAPS, NTLM Removal, SMB Signing
4 hours- ACSC Hardening Microsoft Windows Workstations and Servers (2024 release, re-checked against cyber.gov.au each quarter) applied to domain controllers
- Deploying Windows LAPS (the in-box successor to legacy LAPS, GA April 2023) with Entra ID and on-prem AD backends
- Auditing then disabling NTLMv1 and constraining NTLMv2 — Microsoft's NTLM deprecation roadmap (announced October 2023)
- Enforcing SMB signing and SMB encryption — defaults changed in Windows Server 2025
- LDAP channel binding and signing requirements (Microsoft ADV190023, enforcement guidance as last updated by Microsoft)
Module 3: Privileged Access Workstations
4 hours- PAW architecture per Microsoft's "Why are Privileged Access Workstations important" reference
- Hardware selection, secured-core PC requirements and Windows 11 baseline
- Application allow-listing on PAWs using Windows Defender Application Control
- Network segmentation, jump server patterns and credential isolation
- Operating model: provisioning, patching and decommissioning PAWs at scale
Module 4: Kerberos and Golden Ticket Detection
4 hours- Kerberos attack tradecraft: Kerberoasting, AS-REP roasting, Golden Ticket, Silver Ticket, DCSync
- MITRE ATT&CK T1003 OS Credential Dumping — particularly T1003.006 DCSync detection signals
- krbtgt password rotation procedure and the two-rotation rule
- Detection sources: Windows Security event IDs 4624/4769/4662, Microsoft Defender for Identity, and SIEM queries
- Semperis Purple Knight and Specops research on AD exposure (Semperis "Identity Attack Weather Report" and Specops "Weak Password Report", latest published editions) — using public findings to prioritise hardening
Module 5: AD Backup Verification and Forest Recovery Rehearsals
4 hours- Microsoft "AD Forest Recovery Guide" walkthrough (Microsoft Learn revision, re-checked each quarter)
- System state backups, IFM media and offline domain controller restore
- Tabletop and live-fire forest recovery rehearsals — what "tested backups" means under Essential Eight Maturity Level 2
- Rebuilding trust, DNS, FSMO roles and metadata cleanup after a destructive incident
- Evidence pack for auditors: ASD ISM control mapping for backup integrity and recovery
Module 6: Hybrid AD to Entra Cutover Risk Register
4 hours- Entra Connect Sync vs Entra Cloud Sync — Microsoft guidance as currently published, and the deprecation of legacy Azure AD Connect
- Synchronisation account hardening — the historic MSOL_ account abuse pattern and current mitigations
- Password Hash Sync, Pass-through Authentication and Seamless SSO threat model
- Building a cutover risk register: identity blast radius, rollback plan, break-glass accounts, Conditional Access fail-open scenarios
- Decommissioning on-prem AD safely once workloads are Entra-joined
Who Should Attend
- Active Directory and identity engineers
- Security architects and identity architects
- IT managers responsible for identity resilience
- Incident response and detection engineers
- Hybrid cloud engineers managing AD–Entra synchronisation
Prerequisites
Before enrolling, please ensure you meet these requirements:
- • Working AD DS administration experience
- • PowerShell scripting fluency
- • Lab environment with at least two domain controllers
Delivery, Format and Logistics
Delivery Mode
Three-day live virtual cohort with hands-on labs
Three-day intensive — live virtual cohort with hands-on labs
What You'll Need
- Working knowledge of Active Directory Domain Services, Group Policy and DNS
- Familiarity with PowerShell for administrative tasks
- Access to a lab AD forest (Azure VM or Hyper-V) for hands-on exercises
- Reading familiarity with Microsoft "Securing Privileged Access" reference material
What You'll Receive
- 24 hours of practitioner instruction, roughly 60 per cent of it lab work
- Provided lab AD forest for LAPS rollout, NTLM auditing and Kerberos attack simulation
- Full forest recovery rehearsal against Microsoft's documented procedure
- Tier model design templates and Privileged Access Workstation build standard
- Kerberos and DCSync detection query pack for Windows event logs and SIEM
- Hybrid AD-to-Entra cutover risk register template
- Auditor evidence pack mapping controls to ASD ISM and Essential Eight Maturity Level 2
- Certificate of completion with CPD hours
Frequently Asked Questions
Not Ready to Enrol?
Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.
Early-bird rate — apply your promo code at checkout.
Secure payment via Stripe · Promo codes accepted
Next Intake
September 2026 — register your interest at educ4te.com
Format
Three-day live virtual cohort with hands-on labs
Group & Enterprise Options
Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.
What's Included
- 24 hours of practitioner instruction, roughly 60 per cent of it lab work
- Provided lab AD forest for LAPS rollout, NTLM auditing and Kerberos attack simulation
- Full forest recovery rehearsal against Microsoft's documented procedure
- Tier model design templates and Privileged Access Workstation build standard
- Kerberos and DCSync detection query pack for Windows event logs and SIEM
- Hybrid AD-to-Entra cutover risk register template
- Auditor evidence pack mapping controls to ASD ISM and Essential Eight Maturity Level 2
- Certificate of completion with CPD hours
Have questions about this course?