Hi @Md. Robayet Ferdous •
I recommend you to be accompanied by an active directory security expert in order to detect vulnerabilities in your directory active configuration and correct them.
I will try to share with you some ideas about best practices for Securing Active Directory.
You can start by reading this link : Best Practices for Securing Active Directory
I recommend you to start by protect your accounts with privilege by implementing a tiers model in order to avoid privilege escalation in case on credential compromise.
You can also implement a bastion forest to enforce the security of privileged accounts.
I invite you to read the following links:
Planning a bastion environment
Tier model for partitioning administrative privileges
You should also check if:
- Password of domain account (Admin and standard user) use a complex password through a password policy
- Disable vulnerable protocols like ntlmv1, smbv1 , RC4 ...ect
- Privileged accounts with SPN (service principal name) configuration can be vulnerable to offline brute-forcing and dictionary attacks
Please don't forget to accept helpful answer