THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Ed Moore, Sr. Director of Identity and Access Management, Carnival CorporationActive Directory (AD) is something that most companies like to set and forget. Meaning that a lot of changes in something like AD is sometimes discouraged because of possible broad impact that could impact the business. However, this is something that cannot go neglected.
There are tools out there today that have saturated the market to do evaluations on Active Directory and find holes, or improvements. Some of the names of the tools in this space include Bloodhound, Purple Knight, PING Castle, and others. These tools run predetermined scripts across your AD environment and find things that the AD administration staff will need to evaluate.
Some of these products are very good. They come with the definition of the issue. Some also provide the AD administrator with the steps on how to remediate the issue. If you have not ran these tools on your environment, then I would strongly encourage you to do so. Your advisories are doing this to you in the reconnaissance phase of the kill chain. Should you know what you need to fix before they find that path way into your AD instance?
If your penetration testing is not telling you the alert on when these tools are run against your active directory instance, then they should. It is fine that your team is running these products, but you should really know if someone else from the outside may be running these products against your environment. Make sure that you have that set up to alert in the security operations center.
You are going to find a lot of worthwhile information here on what to fix. The process of fixing, or remediating, these issues is going to take your team some time. Time is not going to be fixed on a remediation effort where you can it should only take 6 weeks. This is something that you should run in an agile fashion and work this in sprints. The duration depends on the number of forests, domains, sub-domains, total number of issues in the report, and the complexity of each issue.
Microsoft also has a program that you may want to talk to your Microsoft account team about. This service that they offer brings in great people on their incident response team to work with you and scan your forests, domains, and sub-domains in the same way that these others products do with their scanning tool. The value add here is that you these experts from Microsoft to work with and help your AD administrators bounce questions off of along the way of your project.
“Move forward slowly and do risky changes on nights and weekends where you have less impact.”
I have used Microsoft before for this service and the people are what makes the difference. If you need help and do not know which way to get started, then this is your team to help you. If you already have a plan in mind, then they can provide you input into your plan and help you get started.
Now that you have the tools to get started, then how do you start is one question that you may be asking. It is important to start small and then work your way up. You could turn off legacy protocols from active directory point of view like SMBv1, but in doing so you are going impact the applications that are still running SMBv1. The goal is not to impact the end users and the business. Move forward slowly and do risky changes on nights and weekends where you have less impact. If you do not have that choice and you are a global company, then you are going to have to spend more time in setting up your test AD environment just like production and making sure to run through the implementation and backout plans to see if anything is impacted in production. These earlier suggestions are the biggest things that you can do to further harden your active directory environments.
After this effort above is complete, then you will want to ask for a red team or purple team to come in and test your improvements. Spoiler alert, the red or purple teams may still find something else to fix. This is ok. This is what we are trying to do is to improve and get better. Now go back and fix those issues and then have them come back in another 6-months for another attempt using the same process.
Lastly, you need think about recovery. Hardening, or improving, active directory is one thing to deter someone that may get into your environment. However, you need to have a plan to recover from things like ransomware. If everything is encrypted and they want you pay are ransom, then can you recover on your own? How long would that recovery take? Is that from a bare metal restore or something else? When is the last time that this solution was tested?
These are the questions that you as a CISO, or as an IT leader, need to be able to answer before you as asked that question in a live fire fight. Know what are valid options. Know what your team can do because things have been tested.
There are some vendors out there today that offer products in this space. Quest is one vendor that you can speak with and Semperis is another vendor that has very good products in this space. Talk to both of these vendors and see what they can do for your company.
You need a solution that will automate the provisioning and restoration of our AD forests, domains, and sub-domains quickly. You also want to know what your options are on what is done in the product and what needs to be completed by your administrator team. Test it out with them before you purchase in a proof of concept. Make the vendors show you that their products work in your environment.
Thank you for your time today. Please continue to drive hard to harden your overall active directory environments. I hope that you have found this article helpful.