Cybersecurity GRC 15 items
Active Directory / Entra ID Hardening
Evaluates hardening of on-premises Active Directory and Entra ID, covering the tiered admin model, privileged access, attack-path reduction, and hybrid identity security.
CISNIST 800-53MITRE ATT&CK
Free PDF · enter your email to download.
Privileged Access Model
- Is a tiered administration model (Tier 0/1/2) implemented to isolate privileged credentials? *
- Are Domain Admins and other Tier 0 groups kept to a minimum and reviewed regularly? *
- Are Privileged Access Workstations (PAWs) used for all Tier 0 administration? *
- Is the built-in Administrator account restricted and LAPS/Windows LAPS used for local admin passwords? *
Attack Path Reduction
- Are Kerberoasting risks reduced (managed service accounts, strong SPN account passwords)? *
- Is unconstrained Kerberos delegation eliminated or tightly controlled? *
- Are AD attack paths assessed with tooling (e.g., BloodHound) and Tier 0 exposure reduced?
- Is the AdminSDHolder / SDProp and ACL configuration audited for unauthorized changes? *
Authentication Hardening
- Is NTLM usage minimized and legacy protocols (LM, NTLMv1) disabled? *
- Is SMB signing and LDAP channel binding/signing enforced? *
- Are password policies aligned to NIST 800-63B with a banned-password list? *
Entra ID & Hybrid Identity
- Is Entra ID Connect secured, with the sync account and Seamless SSO configuration protected? *
- Are Conditional Access policies enforcing MFA and device compliance for admins? *
- Is Entra ID Identity Protection enabled to detect risky users and sign-ins?
- Are emergency-access (break-glass) accounts configured, monitored, and excluded from risky policies? *
Download the full Active Directory / Entra ID Hardening checklist
Get it as a clean, printable PDF — free.
