--- title: "Module 6 — On-Premises AD & Endpoint Hardening" description: "Full AD identity census, password audit of compromised credentials, KRBTGT rotation, LAPS, Sysmon, PAW architecture, and Entra Connect hardening for hybrid environments." eyebrow: "Consulting Module" lead: "The cloud gets the headlines. Active Directory gets compromised. Most AD forests carry a decade of accumulated privilege, service accounts with passwords that predate the organisation's current security team, and group policies nobody dares to touch. This module fixes the kill chain in the on-premises layer." actions: - label: "Get in Touch" url: "/about/#contact" primary: true - label: "View All Modules" url: "/consulting/skills/" --- ## What It Delivers
Every user, computer, service account, and admin group enumerated and assessed. Stale accounts (no logon in 90+ days), orphaned objects (owner departed), and service accounts with non-expiring passwords flagged. The privilege map you didn't know you had.
AD password hashes compared against known-breached credential databases (Elysium / Have I Been Pwned corpus). Accounts using passwords that appear in breach databases identified and forced to reset — before an attacker uses them. This consistently surfaces accounts that have been silently compromised for months.
KRBTGT account rotated twice in sequence (required to invalidate any existing Kerberos tickets, including forged golden tickets). Procedure documented for future rotations. A non-rotated KRBTGT is a persistent attacker foothold that survives every other remediation you run.
Local Administrator Password Solution deployed so every machine has a unique, rotating local admin password — eliminating the lateral movement path of a shared local admin credential. PAW architecture designed for admin tasks to prevent credential theft from the workstations used to manage Tier 0 systems.
Sysmon deployed to endpoints for detailed process creation, network connection, and registry change logging — the telemetry source that turns a security incident from "we don't know what happened" to "we have the full timeline." Entra Connect sync account permissions tightened and sync server isolated: the bridge between on-premises and cloud is a Tier 0 asset and must be protected as one.
Most kill chains pass through on-premises AD even when the target is cloud resources. Module 6 closes the path.