[{"data":1,"prerenderedAt":424},["ShallowReactive",2],{"blog-\u002Fen\u002Fblog\u002Fdurcissement-optimal-securite-active-directory":3,"blog-\u002Fen\u002Fblog\u002Fdurcissement-optimal-securite-active-directory-surround":306,"blog-\u002Fen\u002Fblog\u002Fdurcissement-optimal-securite-active-directory-certifications":366},{"id":4,"title":5,"body":6,"categories":289,"cover":291,"cover_contain":292,"credly_badge_id":293,"date":294,"description":295,"extension":296,"meta":297,"navigation":298,"path":299,"related_certifications":300,"seo":302,"slug":303,"stem":304,"__hash__":305},"blog\u002Fen\u002Fblog\u002Fdurcissement-optimal-securite-active-directory.md","Optimal Hardening of Active Directory Security",{"type":7,"value":8,"toc":271},"minimark",[9,14,18,21,25,28,34,62,68,71,78,116,122,136,142,156,162,166,183,186,193,198,201,206,209,215,221,233,236,241,246,251,256,261,264,268],[10,11,13],"h2",{"id":12},"real-world-use-case","Real-world use case",[15,16,17],"p",{},"You need to prove how robust your Active Directory is: here's how PurpleKnight and PingCastle helped me harden its security, beyond Microsoft's recommendations.",[15,19,20],{},"Applications and systems are by nature configured with defaults designed, among other things, to ensure maximum compatibility. As a result, it's crucial to understand that the Active Directory directory is exposed to risks, and securing it is a major challenge for any organization. It's essential to implement Microsoft's recommendations, supported by the PurpleKnight and PingCastle audit tools.",[10,22,24],{"id":23},"a-significant-reduction-in-risk","A significant reduction in risk",[15,26,27],{},"Fully implementing the Purple Knight and PingCastle controls provides extensive coverage of the most critical AD vulnerabilities. While it's not a miracle solution, it nonetheless lays the essential foundations of a modern, solid security strategy, drastically reducing exposure to common attacks.",[15,29,30],{},[31,32,33],"strong",{},"Key points of this technical implementation:",[35,36,37,41,44,47,50,53,56,59],"ul",{},[38,39,40],"li",{},"185 Purple Knight indicators (IoE + IoC)",[38,42,43],{},"32 rules: Stale objects",[38,45,46],{},"78 rules: Privileged accounts",[38,48,49],{},"23 rules: Trust relationships",[38,51,52],{},"53 rules: Anomalies",[38,54,55],{},"55 ANSSI rules: compliant (levels 1 to 4)",[38,57,58],{},"26 techniques: MITRE ATT&CK covered",[38,60,61],{},"371 security controls implemented in total",[10,63,65],{"id":64},"implementation-methodology",[31,66,67],{},"Implementation methodology",[15,69,70],{},"Hardening a production Active Directory environment requires careful planning and project management adapted to operational constraints. Effectively applying the 371 controls without impacting users and devices can be complex. This section details the approach I successfully applied.",[72,73,75],"h3",{"id":74},"discovery-phase",[31,76,77],{},"Discovery phase",[79,80,81,91,98,101,104,107,110,113],"ol",{},[38,82,83,84],{},"Reading ",[85,86,90],"a",{"href":87,"rel":88},"https:\u002F\u002Flearn.microsoft.com\u002Ffr-fr\u002Fwindows-server\u002Fidentity\u002Fad-ds\u002Fplan\u002Fsecurity-best-practices\u002Fbest-practices-for-securing-active-directory",[89],"nofollow","Microsoft AD best practices",[38,92,93,94],{},"Learning ",[85,95,90],{"href":96,"rel":97},"https:\u002F\u002Flearn.microsoft.com\u002F",[89],[38,99,100],{},"Audit with Purple Knight",[38,102,103],{},"Audit with PingCastle",[38,105,106],{},"Results analysis",[38,108,109],{},"Prioritization by criticality",[38,111,112],{},"Mapping interdependencies between controls",[38,114,115],{},"Planning maintenance windows with justification",[72,117,119],{"id":118},"technical-implementation-phase",[31,120,121],{},"Technical implementation phase",[79,123,124,127,130,133],{},[38,125,126],{},"Stale objects and inactive accounts: tracking the 32 PingCastle rules",[38,128,129],{},"Privileged accounts and delegations: tracking the 78 PingCastle rules",[38,131,132],{},"Trusts and inter-domain relationships: tracking the 23 PingCastle rules",[38,134,135],{},"Anomalies and advanced configurations: tracking the 53 PingCastle rules and 185 Purple Knight indicators.",[72,137,139],{"id":138},"validation-phase",[31,140,141],{},"Validation phase",[79,143,144,147,150,153],{},[38,145,146],{},"Regression testing across all services",[38,148,149],{},"Functional validation of business applications",[38,151,152],{},"Final compliance audit with both tools",[38,154,155],{},"Documentation of operational procedures",[10,157,159],{"id":158},"purple-knight",[31,160,161],{},"Purple Knight",[72,163,165],{"id":164},"_185-security-indicators","185 Security Indicators",[15,167,168,169,172,173,176,177,182],{},"Purple Knight, developed by Semperis, performs a full scan of the AD environment looking for Indicators of Exposure (",[31,170,171],{},"IoE",") and Indicators of Compromise (",[31,174,175],{},"IoC","). The tool offers about 185 security controls split into several categories, available at ",[85,178,181],{"href":179,"rel":180},"https:\u002F\u002Fwww.semperis.com\u002Ffr\u002Fpurple-knight\u002Fsecurity-indicators\u002F",[89],"the following link",".",[15,184,185],{},"Here's our score as of August 8, 2025 (version 5.0.2506.11001 | Community):",[15,187,188],{},[189,190],"img",{"alt":191,"src":192},"","\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002Fbc6d116211.png",[15,194,195],{},[189,196],{"alt":191,"src":197},"\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002Ff67b40dd12.png",[15,199,200],{},"The Indicators of Exposure found:",[15,202,203],{},[189,204],{"alt":191,"src":205},"\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002F37766c8cd2.png",[15,207,208],{},"Each anomaly can be fixed through standardized procedures, ensuring a gradual improvement of the security score.",[10,210,212],{"id":211},"pingcastle",[31,213,214],{},"PingCastle",[72,216,218],{"id":217},"_186-control-rules",[31,219,220],{},"186 Control Rules",[15,222,223,224,227,228,182],{},"PingCastle, originally developed by Vincent Le Toux and later acquired by Netwrix, offers a methodological approach based on a risk model with 4 main categories, with ",[31,225,226],{},"186 detailed control rules"," ",[85,229,232],{"href":230,"rel":231},"https:\u002F\u002Fpingcastle.com\u002FPingCastleFiles\u002Fad_hc_rules_list.html#",[89],"available at the following link",[15,234,235],{},"Here's our score as of August 8, 2025 (version 3.4.1.38 | Free):",[15,237,238],{},[189,239],{"alt":191,"src":240},"\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002Fbb67079206.png",[15,242,243],{},[189,244],{"alt":191,"src":245},"\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002F5e35f9e1b4.png",[15,247,248],{},[189,249],{"alt":191,"src":250},"\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002Fe26680246b.png",[15,252,253],{},[189,254],{"alt":191,"src":255},"\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002Fa7eaf3be32.png",[15,257,258],{},[189,259],{"alt":191,"src":260},"\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002F82ebf05fba.png",[15,262,263],{},"Here too, these anomalies can be fixed following recommended procedures to improve the security score. A planned outage has so far been acceptable for restoring the primary DC. Deploying a second physical domain controller is needed if we want to ensure redundancy.",[10,265,267],{"id":266},"conclusion","Conclusion",[15,269,270],{},"This experience shows that a rigorous, comprehensive approach to AD hardening, based on official recommendations and complementary tools, makes it possible to reach an optimal level of security while keeping directory services fully operational.",{"title":191,"searchDepth":272,"depth":272,"links":273},2,[274,275,276,282,285,288],{"id":12,"depth":272,"text":13},{"id":23,"depth":272,"text":24},{"id":64,"depth":272,"text":67,"children":277},[278,280,281],{"id":74,"depth":279,"text":77},3,{"id":118,"depth":279,"text":121},{"id":138,"depth":279,"text":141},{"id":158,"depth":272,"text":161,"children":283},[284],{"id":164,"depth":279,"text":165},{"id":211,"depth":272,"text":214,"children":286},[287],{"id":217,"depth":279,"text":220},{"id":266,"depth":272,"text":267},[290],"Sécurité","\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002F9dc4acd9d6.png",false,null,"2025-08-13","Microsoft provides best practices for securing AD, but Purple Knight and PingCastle offer a concrete approach to get started.","md",{},true,"\u002Fen\u002Fblog\u002Fdurcissement-optimal-securite-active-directory",[301],"certificat-microsoft-security-compliance-and-identity-fundamentals",{"title":5,"description":295},"durcissement-optimal-securite-active-directory","en\u002Fblog\u002Fdurcissement-optimal-securite-active-directory","ASLCDA5imYd61o_yt19bUUnDHQhIaV3oCDKi1mktsF0",[307,315,324,331,338,345,352,359],{"title":308,"path":309,"stem":310,"date":311,"cover":312,"categories":313,"children":-1},"Achieving a 0% Exposure Score with Microsoft Defender Vulnerability Management","\u002Fen\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management","en\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management","2025-10-27","\u002Fimages\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management\u002Fe8a06eec09.png",[314,290],"Microsoft",{"title":316,"path":317,"stem":318,"date":319,"cover":320,"categories":321,"children":-1},"GitHub Copilot","\u002Fen\u002Fblog\u002Fcertificat-microsoft-github-copilot","en\u002Fblog\u002Fcertificat-microsoft-github-copilot","2025-08-28","\u002Fimages\u002Fblog\u002Fcertificat-microsoft-github-copilot\u002Fcf8333d63e.png",[322,323],"Certifications","Code",{"title":325,"path":326,"stem":327,"date":328,"cover":329,"categories":330,"children":-1},"Take Back Control of Your Microsoft Directories with an Infrastructure as Code Approach","\u002Fen\u002Fblog\u002Freprenez-controle-annuaires-microsoft-infrastructure-as-code","en\u002Fblog\u002Freprenez-controle-annuaires-microsoft-infrastructure-as-code","2025-08-25","\u002Fimages\u002Fblog\u002Freprenez-controle-annuaires-microsoft-infrastructure-as-code\u002F96c873f6c1.png",[314,290],{"title":332,"path":333,"stem":334,"date":335,"cover":336,"categories":337,"children":-1},"Goal: 100%, Veeam Backup & Replication v12 Security","\u002Fen\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication","en\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication","2025-08-18","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication\u002Ffd1cbd3a9e.png",[290],{"title":339,"path":340,"stem":341,"date":342,"cover":343,"categories":344,"children":-1},"Full Application of the Zero Trust Model in Microsoft 365","\u002Fen\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365","en\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365","2025-08-10","\u002Fimages\u002Fblog\u002Fapplication-complete-modele-zero-trust-microsoft365\u002Fcea858f515.png",[290],{"title":346,"path":347,"stem":348,"date":349,"cover":350,"categories":351,"children":-1},"Goal: 100%, Microsoft 365 Exposure Management","\u002Fen\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365","en\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365","2025-08-09","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365\u002Fe8a06eec09.png",[290],{"title":353,"path":354,"stem":355,"date":356,"cover":357,"categories":358,"children":-1},"Goal: 100% - Microsoft 365 Security at Its Maximum","\u002Fen\u002Fblog\u002Fobjectif-100-securite-microsoft365","en\u002Fblog\u002Fobjectif-100-securite-microsoft365","2025-08-01","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-microsoft365\u002Fac33e55464.jpg",[290],{"title":360,"path":361,"stem":362,"date":363,"cover":364,"categories":365,"children":-1},"Ensuring the Security of Your Secrets in Your Password Manager with Keeper Security","\u002Fen\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security","en\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security","2025-07-25","\u002Fimages\u002Fblog\u002Fgarantir-securite-secrets-mots-de-passe-keeper-security\u002F15b70398a5.png",[290],[367],{"id":368,"title":369,"body":370,"categories":414,"cover":415,"cover_contain":298,"credly_badge_id":416,"date":417,"description":418,"extension":296,"meta":419,"navigation":298,"path":420,"related_certifications":293,"seo":421,"slug":301,"stem":422,"__hash__":423},"blog\u002Fen\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals.md","Microsoft: Security, Compliance, and Identity Fundamentals",{"type":7,"value":371,"toc":410},[372,374,377,380,402,405,407],[10,373,13],{"id":12},[15,375,376],{},"To advise my clients on Microsoft security and compliance, I took the Security, Compliance, and Identity Fundamentals certification.",[15,378,379],{},"The \"Microsoft Security, Compliance, and Identity Fundamentals\" training path is designed for IT professionals in charge of deploying and securing cloud resources.\nThe course catalog covers the following modules:",[35,381,382,387,392,397],{},[38,383,384],{},[31,385,386],{},"Describe security, compliance, and identity concepts",[38,388,389],{},[31,390,391],{},"Describe the capabilities of Microsoft Entra",[38,393,394],{},[31,395,396],{},"Describe the capabilities of Microsoft security solutions",[38,398,399],{},[31,400,401],{},"Describe the capabilities of Microsoft compliance solutions",[15,403,404],{},"The training takes about 3 days.\nYou should then allow around 1h00 for the certification exam itself: Microsoft Security, Compliance, and Identity Fundamentals.",[10,406,267],{"id":266},[15,408,409],{},"This Microsoft course covers security, compliance, and identity management concepts, as well as the main associated Microsoft solutions (Entra, security, and compliance). It complements the Azure fundamentals already acquired by providing a broader view of protecting Microsoft environments. A useful certification for any professional in charge of securing cloud resources.",{"title":191,"searchDepth":272,"depth":272,"links":411},[412,413],{"id":12,"depth":272,"text":13},{"id":266,"depth":272,"text":267},[322,314],"\u002Fimages\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals\u002F70ef935f2a.png","82a09914-e95c-43b6-a371-f308b5ee8185","2022-10-17","Microsoft: Security, Compliance, and Identity Fundamentals: course completed as part of my professional watch in cybersecurity and IT.",{},"\u002Fen\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals",{"title":369,"description":418},"en\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals","pzrV5JRrELrJgaqSoqL2QuFzeb9_7_olBJ4fv_fRsgo",1786644869542]