IntermediateAD-SEC-001

Securing Active Directory — Practitioner Course

Harden on-prem and hybrid Active Directory against modern identity attacks

Active Directory remains the single largest blast radius in most Australian enterprises. This practitioner course gives identity engineers a tested playbook to harden domain controllers, contain privileged access, detect Kerberos abuse, and rehearse forest recovery before an attacker forces the issue.

24 hours
New course
Certificate Included
Securing Active Directory — Practitioner Course

At a Glance

Who it's for

  • Active Directory and identity engineers responsible for on-prem and hybrid environments
  • Security architects designing tiered administration and privileged access models
  • IT managers accountable for identity resilience and Essential Eight Maturity Level 2 recovery controls
  • Incident response and detection engineers building Kerberos and DCSync detections

Course Details

Duration:24 hours
Format:Three-day live virtual cohort with hands-on labs
Next intake:September 2026 — register your interest at educ4te.com
Alignment:Aligned to ASD Essential Eight Maturity Level 2 (regular backups, restrict admin privileges) and ACSC Hardening Microsoft Windows guidance

Course Overview

Active Directory underpins authentication for the majority of Australian enterprise, government and critical infrastructure environments, yet most forests still run with flat administrative models, unmanaged service accounts and unverified backups. This three-day practitioner course walks identity engineers through the controls Microsoft, the ACSC and incident responders agree actually matter: the tier model and Enterprise Admins isolation, domain controller hardening (LAPS, NTLM removal, SMB signing), Privileged Access Workstations, Kerberos and Golden Ticket detection, AD backup verification and full forest recovery rehearsals, and the risk register for hybrid Entra cutovers. Every module pairs Microsoft and ACSC reference guidance with current attacker tradecraft — Mimikatz, DCSync, Kerberoasting, AdminSDHolder abuse — so participants leave with a tested playbook and the evidence to brief executives on residual identity risk.

What You'll Learn

Design and implement Microsoft's administrative tier model and isolate Enterprise Admins from daily operations
Harden domain controllers using ACSC Windows hardening guidance, including SMB signing, LDAP signing and NTLM auditing then removal
Deploy Windows LAPS to rotate local administrator credentials and eliminate shared-password lateral movement
Build and operate Privileged Access Workstations (PAWs) for tier-0 administration
Detect and respond to Kerberos abuse including Golden Ticket, Silver Ticket, Kerberoasting and DCSync (MITRE ATT&CK T1003.006)
Verify Active Directory backups and rehearse a full forest recovery against Microsoft's documented procedure
Build a hybrid AD-to-Entra cutover risk register covering password hash sync, seamless SSO, and synchronisation account exposure
Map identity controls to ASD Essential Eight Maturity Level 2 and the ASD Information Security Manual (ISM)

Course Curriculum

Module 1: AD Tier Model and Enterprise Admins Isolation

4 hours
  • Microsoft's tier 0/1/2 administrative model — what changed in the "Securing Privileged Access" reference (Microsoft, updated 2024)
  • Removing standing Enterprise Admins and Domain Admins membership
  • Time-bound elevation patterns using Privileged Identity Management and just-in-time groups
  • AdminSDHolder, Protected Users group and authentication policy silos
  • Mapping the tier model to the ACSC Essential Eight "restrict administrative privileges" control

Module 2: Hardening Domain Controllers — LAPS, NTLM Removal, SMB Signing

4 hours
  • ACSC Hardening Microsoft Windows Workstations and Servers (2024 release, re-checked against cyber.gov.au each quarter) applied to domain controllers
  • Deploying Windows LAPS (the in-box successor to legacy LAPS, GA April 2023) with Entra ID and on-prem AD backends
  • Auditing then disabling NTLMv1 and constraining NTLMv2 — Microsoft's NTLM deprecation roadmap (announced October 2023)
  • Enforcing SMB signing and SMB encryption — defaults changed in Windows Server 2025
  • LDAP channel binding and signing requirements (Microsoft ADV190023, enforcement guidance as last updated by Microsoft)

Module 3: Privileged Access Workstations

4 hours
  • PAW architecture per Microsoft's "Why are Privileged Access Workstations important" reference
  • Hardware selection, secured-core PC requirements and Windows 11 baseline
  • Application allow-listing on PAWs using Windows Defender Application Control
  • Network segmentation, jump server patterns and credential isolation
  • Operating model: provisioning, patching and decommissioning PAWs at scale

Module 4: Kerberos and Golden Ticket Detection

4 hours
  • Kerberos attack tradecraft: Kerberoasting, AS-REP roasting, Golden Ticket, Silver Ticket, DCSync
  • MITRE ATT&CK T1003 OS Credential Dumping — particularly T1003.006 DCSync detection signals
  • krbtgt password rotation procedure and the two-rotation rule
  • Detection sources: Windows Security event IDs 4624/4769/4662, Microsoft Defender for Identity, and SIEM queries
  • Semperis Purple Knight and Specops research on AD exposure (Semperis "Identity Attack Weather Report" and Specops "Weak Password Report", latest published editions) — using public findings to prioritise hardening

Module 5: AD Backup Verification and Forest Recovery Rehearsals

4 hours
  • Microsoft "AD Forest Recovery Guide" walkthrough (Microsoft Learn revision, re-checked each quarter)
  • System state backups, IFM media and offline domain controller restore
  • Tabletop and live-fire forest recovery rehearsals — what "tested backups" means under Essential Eight Maturity Level 2
  • Rebuilding trust, DNS, FSMO roles and metadata cleanup after a destructive incident
  • Evidence pack for auditors: ASD ISM control mapping for backup integrity and recovery

Module 6: Hybrid AD to Entra Cutover Risk Register

4 hours
  • Entra Connect Sync vs Entra Cloud Sync — Microsoft guidance as currently published, and the deprecation of legacy Azure AD Connect
  • Synchronisation account hardening — the historic MSOL_ account abuse pattern and current mitigations
  • Password Hash Sync, Pass-through Authentication and Seamless SSO threat model
  • Building a cutover risk register: identity blast radius, rollback plan, break-glass accounts, Conditional Access fail-open scenarios
  • Decommissioning on-prem AD safely once workloads are Entra-joined

Who Should Attend

  • Active Directory and identity engineers
  • Security architects and identity architects
  • IT managers responsible for identity resilience
  • Incident response and detection engineers
  • Hybrid cloud engineers managing AD–Entra synchronisation

Prerequisites

Before enrolling, please ensure you meet these requirements:

  • • Working AD DS administration experience
  • • PowerShell scripting fluency
  • • Lab environment with at least two domain controllers

Delivery, Format and Logistics

Delivery Mode

Three-day live virtual cohort with hands-on labs

Three-day intensive — live virtual cohort with hands-on labs

What You'll Need

  • Working knowledge of Active Directory Domain Services, Group Policy and DNS
  • Familiarity with PowerShell for administrative tasks
  • Access to a lab AD forest (Azure VM or Hyper-V) for hands-on exercises
  • Reading familiarity with Microsoft "Securing Privileged Access" reference material

What You'll Receive

  • 24 hours of practitioner instruction, roughly 60 per cent of it lab work
  • Provided lab AD forest for LAPS rollout, NTLM auditing and Kerberos attack simulation
  • Full forest recovery rehearsal against Microsoft's documented procedure
  • Tier model design templates and Privileged Access Workstation build standard
  • Kerberos and DCSync detection query pack for Windows event logs and SIEM
  • Hybrid AD-to-Entra cutover risk register template
  • Auditor evidence pack mapping controls to ASD ISM and Essential Eight Maturity Level 2
  • Certificate of completion with CPD hours

Frequently Asked Questions

Not Ready to Enrol?

Join our mailing list to receive updates about courses, resources, and cybersecurity insights tailored for Australian organisations.

By subscribing, you agree to receive email updates from Educ4te. You can unsubscribe at any time. We respect your privacy and will never share your information.

$999AUD
$1299EARLY BIRD

Early-bird rate — apply your promo code at checkout.

1

Secure payment via Stripe · Promo codes accepted

Next Intake

September 2026 — register your interest at educ4te.com

Format

Three-day live virtual cohort with hands-on labs

Group & Enterprise Options

Discounted rates available for teams of 3+ delegates. Contact us for in-house delivery options.

What's Included

  • 24 hours of practitioner instruction, roughly 60 per cent of it lab work
  • Provided lab AD forest for LAPS rollout, NTLM auditing and Kerberos attack simulation
  • Full forest recovery rehearsal against Microsoft's documented procedure
  • Tier model design templates and Privileged Access Workstation build standard
  • Kerberos and DCSync detection query pack for Windows event logs and SIEM
  • Hybrid AD-to-Entra cutover risk register template
  • Auditor evidence pack mapping controls to ASD ISM and Essential Eight Maturity Level 2
  • Certificate of completion with CPD hours

Have questions about this course?