Related Ingenix tool
Assess ransomware resilience in the browser.
Engineering principle: Treat directory services as a critical control plane. Separate administrator accounts, minimise standing privilege and review privileged groups.
Domain controllers
Place them in tightly controlled network segments and restrict administrative access.
Group Policy
Monitor unexpected policy changes and restrict who can modify policy.
Administration
Use hardened administrative workstations for high-privilege operations.
Monitoring
Watch privileged group changes, new administrators and unusual domain authentication.
Implementation checklist
- Document the intended control.
- Apply least privilege and minimise unnecessary exposure.
- Centralise useful logs.
- Test the control rather than assuming configuration equals protection.
- Record exceptions and review them regularly.