simpl.
Cybersecurity GRC 15 items

Active Directory / Entra ID Hardening

Evaluates hardening of on-premises Active Directory and Entra ID, covering the tiered admin model, privileged access, attack-path reduction, and hybrid identity security.

CISNIST 800-53MITRE ATT&CK

Free PDF · enter your email to download.

Privileged Access Model

  • Is a tiered administration model (Tier 0/1/2) implemented to isolate privileged credentials? *
  • Are Domain Admins and other Tier 0 groups kept to a minimum and reviewed regularly? *
  • Are Privileged Access Workstations (PAWs) used for all Tier 0 administration? *
  • Is the built-in Administrator account restricted and LAPS/Windows LAPS used for local admin passwords? *

Attack Path Reduction

  • Are Kerberoasting risks reduced (managed service accounts, strong SPN account passwords)? *
  • Is unconstrained Kerberos delegation eliminated or tightly controlled? *
  • Are AD attack paths assessed with tooling (e.g., BloodHound) and Tier 0 exposure reduced?
  • Is the AdminSDHolder / SDProp and ACL configuration audited for unauthorized changes? *

Authentication Hardening

  • Is NTLM usage minimized and legacy protocols (LM, NTLMv1) disabled? *
  • Is SMB signing and LDAP channel binding/signing enforced? *
  • Are password policies aligned to NIST 800-63B with a banned-password list? *

Entra ID & Hybrid Identity

  • Is Entra ID Connect secured, with the sync account and Seamless SSO configuration protected? *
  • Are Conditional Access policies enforcing MFA and device compliance for admins? *
  • Is Entra ID Identity Protection enabled to detect risky users and sign-ins?
  • Are emergency-access (break-glass) accounts configured, monitored, and excluded from risky policies? *

Download the full Active Directory / Entra ID Hardening checklist

Get it as a clean, printable PDF — free.