Secure Windows Server user accounts

Intermediate
Administrator
Azure
Windows Server

This module covers how to secure user accounts in an Active Directory environment. You learn how to configure user account rights following least privilege, use the Protected Users group and authentication policy silos to limit authentication scope for privileged accounts, configure Windows Defender Credential Guard hardware prerequisites and deployment, implement NTLM blocking by auditing NTLM traffic and then configuring deny policies, and locate and remediate problematic accounts such as inactive users and accounts with permanent passwords.

Learning objectives

After completing this module, you'll be able to:

  • Configure and manage user accounts to limit security threats across an organization
  • Apply Protected Users settings, policies, and authentication silos to protect highly privileged user accounts
  • Describe and configure Windows Defender Credential Guard
  • Configure Group Policy to block the use of NTLM for authentication

Prerequisites

  • Familiarity with managing Active Directory Domain Services security principals
  • Ability to edit Active Directory Group Policy settings
  • Experience performing basic Windows Server administration tasks

Get started with Azure

Choose the Azure account that's right for you. Pay as you go or try Azure free for up to 30 days. Sign up.