Skip to content

Lab 01 — Active Directory

Active Directory remains one of the most important identity technologies in enterprise environments.

It commonly provides centralized management for:

Users
Computers
Groups
Authentication
Authorization
Group Policy
Enterprise Resources

For a security professional, Active Directory is not simply:

User Management

It is a critical security control plane.

A useful mental model is:

IDENTITY
AUTHENTICATION
GROUP MEMBERSHIP
PRIVILEGE
POLICY
RESOURCE ACCESS

Lab: Active Directory
Level: Beginner → Intermediate
Estimated Time: 150–210 minutes
Environment: Authorized Windows Server / Active Directory lab
Primary Role: Windows / Identity Administrator
Secondary Roles: Security Engineer, SOC Analyst, IAM Engineer, Incident Responder, Microsoft Security Engineer

Your organization is preparing a Windows Active Directory environment for a security review.

The environment contains:

Domain Controller
Users
Administrators
Security Groups
Organizational Units
Workstations
Service Accounts
Group Policies

The security team wants to know:

How Is the Domain Structured?
Who Has Access?
Who Has Administrative Privilege?
Which Groups Control Access?
How Are Users Organized?
Which Policies Apply?
Are Service Accounts Controlled?
Can Important Changes Be Audited?

Your task is to inspect the Active Directory environment and create a basic security assessment.

By completing this lab, you should be able to:

  • Explain Active Directory architecture
  • Identify the domain
  • Understand domain controllers
  • Review organizational units
  • Create and review users
  • Create and review security groups
  • Understand group scopes conceptually
  • Understand authentication in a domain
  • Review privileged groups
  • Understand domain administration
  • Review service accounts
  • Understand Group Policy
  • Identify computer objects
  • Understand account lifecycle
  • Review password and lockout concepts
  • Review authentication events
  • Understand Active Directory security risks
  • Produce security findings
  • Build a professional Active Directory assessment report
+----------------------+
| Domain Controller |
| |
| Active Directory DS |
| DNS |
| Group Policy |
+----------+-----------+
|
|
Corporate Domain
|
+----------------+----------------+
| | |
v v v
Users Groups Computers
| | |
+----------------+----------------+
|
v
Resources

Active Directory Domain Services provides centralized identity and resource management.

It helps answer:

Who Are You?
Which Groups Are You In?
What Can You Access?
Which Policies Apply?

You will commonly work with:

Users
Groups
Computers
Organizational Units
Policies
Domains

A domain represents an administrative and identity boundary within Active Directory.

Example:

corp.example.local

Conceptually:

Domain
Users
Groups
Computers
Policies

Ask:

What Is the Domain Name?
How Many Domain Controllers Exist?
Who Administers the Domain?
Which Systems Depend on It?

On a domain-joined Windows system, use approved administrative tools such as PowerShell.

For example:

Terminal window
$env:USERDOMAIN

You can also inspect domain information using the Active Directory administrative tools available in your lab.

A domain controller provides critical Active Directory services.

It can participate in:

Authentication
Directory Queries
Group Policy
Domain Services

Domain controllers should be treated as:

Highly Critical Assets

because compromise may affect:

Users
Groups
Credentials
Policies
Enterprise Access
Who Can Log In?
Who Can Administer It?
Which Services Run?
Is It Patched?
Is Logging Enabled?
Is Network Access Restricted?

Organizational Units, or OUs, help organize directory objects.

Example:

corp.example.local
|
+-- Users
|
+-- Workstations
|
+-- Servers
|
+-- Admins
|
+-- Service Accounts

OUs support:

Administration
Delegation
Policy Application
Logical Organization

Do not create an OU structure based only on:

Company Org Chart

Think also about:

Administration
Security Requirements
Policy Boundaries
Delegation

Using Active Directory Users and Computers or approved PowerShell tooling, identify existing OUs.

Record:

OU Name
Purpose
Objects
Delegated Administrators
Policies
OU Purpose Object Type Security Relevance
Users Employee identities Users Account policy
Workstations User devices Computers Endpoint policy
Servers Server systems Computers Server hardening
Admins Privileged users Users High privilege
Service Accounts Workloads Users Credential security

Users represent human identities or, in some environments, workload identities.

A user object may contain:

Username
Display Name
Group Membership
Account Status
Password Properties
Login Restrictions

Use:

JOIN
CREATE
ASSIGN ACCESS
MONITOR
REVIEW
DISABLE
REMOVE

The most common identity problems include:

Dormant Accounts
Excessive Group Membership
Shared Accounts
Weak Password Controls
Unreviewed Privilege

In an authorized training environment, create a test identity.

Example PowerShell workflow where the Active Directory module is available:

Terminal window
New-ADUser `
-Name "Alice Student" `
-GivenName "Alice" `
-Surname "Student" `
-SamAccountName "alice.student" `
-UserPrincipalName "alice.student@corp.example.local" `
-Enabled $true

Depending on your environment, password configuration may be handled separately using your lab’s approved process.

Do not use production names, credentials, or domains in a training environment.

For a lab user:

Terminal window
Get-ADUser alice.student -Properties *

For a more focused review:

Terminal window
Get-ADUser alice.student -Properties Enabled,LastLogonDate,PasswordLastSet

Ask:

Is the Account Enabled?
When Was Password Changed?
When Was It Last Used?
Which Groups Does It Belong To?
Does It Still Need Access?

Important account states include:

Enabled
Disabled
Locked
Expired

Security teams should understand why an account is in each state.

For an authorized test identity:

Terminal window
Disable-ADAccount -Identity alice.student

Verify:

Terminal window
Get-ADUser alice.student -Properties Enabled

Re-enable only if required:

Terminal window
Enable-ADAccount -Identity alice.student

When access must be removed quickly:

Disable

can be safer than immediately deleting the account because it preserves:

Object History
Ownership Context
Investigation Context

until the appropriate lifecycle process is complete.

Groups allow access to be assigned based on role.

Poor model:

Alice → Folder
Bob → Folder
Charlie → Folder

Better:

Alice
Bob
Charlie
Finance-Users
Finance Resource

Groups provide:

Consistency
Scalability
Centralized Authorization
Simpler Reviews

At a high level, Active Directory groups may be used for:

Security
Distribution

Security groups can participate in access control.

Common group scopes include:

Domain Local
Global
Universal

You do not need to memorize only definitions.

Understand the design question:

Where Can Members Come From?
Where Will Permissions Be Used?

Example:

Terminal window
New-ADGroup `
-Name "GHC-Security-Analysts" `
-GroupScope Global `
-GroupCategory Security

Example:

Terminal window
Add-ADGroupMember `
-Identity "GHC-Security-Analysts" `
-Members "alice.student"

Verify:

Terminal window
Get-ADGroupMember "GHC-Security-Analysts"

Always ask:

Does This User Need This Group?

because group membership often translates directly into:

Access

Example:

Terminal window
Get-ADPrincipalGroupMembership alice.student |
Select-Object Name

Document:

Normal Groups
Privileged Groups
Application Groups
Legacy Groups

Privilege creep occurs when:

User Changes Role
Old Groups Remain
New Groups Added
Access Accumulates

Certain groups should receive special security attention.

Examples may include:

Domain Admins
Enterprise Admins
Administrators
Account Operators
Server Operators

depending on environment and domain structure.

Do not treat every built-in group as equally dangerous.

Assess:

Actual Privilege
Membership
Delegation
Business Requirement

Example:

Terminal window
Get-ADGroupMember "Domain Admins"

Document:

Member
Account Type
Business Owner
Reason for Membership
Last Review

Membership in highly privileged groups should be:

Rare
Justified
Reviewed
Strongly Authenticated
Monitored
Finding:
Excessive Domain Administrative Membership
Observation:
A standard operational user retains
membership in a highly privileged
administrative group despite not requiring
domain-wide administrative access.
Risk:
Compromise or misuse of the account could
result in broad control over enterprise
identity and domain resources.
Recommendation:
Remove unnecessary high-level privilege
and assign the minimum role required for
the user's responsibilities.

A mature environment may separate:

Normal User Identity

from:

Administrative Identity

Example:

alice.student

for normal work and:

adm-alice

for approved privileged activity.

This can reduce exposure of:

High-Privilege Credentials

during ordinary activities such as:

Email
Web Browsing
Document Work

Avoid:

DomainAdmin

shared by multiple administrators.

Shared accounts reduce:

Accountability
Auditability
Attribution

Prefer:

Individual Admin Identity
Privileged Role
Audited Activity

Domain-joined Windows systems are represented by computer objects.

Example:

PC-001$
SERVER-01$
Is the Computer Still Active?
Who Owns It?
Which OU Is It In?
Which Policies Apply?
Is It a Server or Endpoint?
Is the Object Stale?

Example:

Terminal window
Get-ADComputer -Filter * |
Select-Object Name,Enabled

For a focused view:

Terminal window
Get-ADComputer -Filter * -Properties LastLogonDate |
Select-Object Name,Enabled,LastLogonDate

Old computer objects may represent:

Retired Systems
Rebuilt Systems
Unused Devices
Inventory Problems

They should be reviewed rather than ignored.

Applications and services may need dedicated identities.

Examples:

Database Service
Backup Agent
Scheduled Task
Application Pool
Integration Service
Application
Employee Account

or:

Application
Domain Administrator
Application
Dedicated Service Identity
Minimum Required Access

For every service account ask:

Who Owns It?
Which Application Uses It?
Does It Need Interactive Login?
Does It Need Domain Access?
Does It Need Administrative Privilege?
How Is Its Credential Managed?
When Was It Last Reviewed?
Finding:
Service Account Has Excessive Privilege
Observation:
A service identity is a member of a
highly privileged administrative group
although its application requires only
limited resource access.
Risk:
Compromise of the application or service
credential could result in broad domain
privilege.
Recommendation:
Remove excessive membership and grant
only the permissions required by the
application.

Part 26 — Managed Service Accounts Concept

Section titled “Part 26 — Managed Service Accounts Concept”

Where appropriate, organizations may use managed service-account technologies to reduce manual password-management burden.

The security goal is:

Service
Dedicated Managed Identity
Controlled Privilege
Reduced Credential Management

Domain environments commonly define password-related policies.

Security areas may include:

Password Length
Password History
Password Age
Account Lockout
Authentication Requirements

Do not assume:

Very Frequent Password Changes
=
Better Security

Password strategy should align with modern organizational policy and authentication architecture.

Lockout controls can reduce repeated password guessing.

But aggressive settings can also create:

User Lockouts
Helpdesk Load
Potential Denial-of-Service Conditions

Security configuration must balance:

Protection
+
Availability

Part 29 — Authentication in Active Directory

Section titled “Part 29 — Authentication in Active Directory”

Active Directory environments commonly use authentication protocols such as:

Kerberos
NTLM

Modern domain authentication prefers stronger and more current mechanisms where possible, while legacy applications may still create compatibility requirements.

At a high level:

USER
DOMAIN AUTHENTICATION
TICKET
SERVICE ACCESS

Identity administrators should understand:

Authentication Source
Account
Service
Ticket / Session
Privilege

without treating authentication as a black box.

Active Directory depends heavily on DNS.

A simplified model:

Client
DNS
Locate Domain Service
Domain Controller
Authentication

Many Active Directory problems that appear to be:

Authentication Problems

can actually involve:

DNS

Group Policy provides centralized Windows configuration.

Conceptually:

DOMAIN / OU
GROUP POLICY OBJECT
USERS / COMPUTERS
CONFIGURATION
Security Settings
Desktop Configuration
Firewall
Authentication
Scripts
Administrative Templates
Windows Components

Part 32 — Why Group Policy Matters for Security

Section titled “Part 32 — Why Group Policy Matters for Security”

A single policy can influence:

Hundreds
Thousands
Tens of Thousands

of systems.

Therefore:

GPO Modification

can be a high-impact administrative action.

Using Group Policy Management in your authorized lab, identify:

GPO Name
Linked Location
Purpose
Security Relevance
Owner
GPO Linked To Purpose Security Impact
Domain Baseline Domain Baseline settings High
Workstation Security Workstations OU Endpoint policy High
Server Security Servers OU Server policy High
Admin Policy Admin OU Privileged controls High

Policies may apply at different levels.

Conceptually:

Site
Domain
OU
Nested OU

Actual policy processing can also involve:

Inheritance
Enforcement
Security Filtering
WMI Filtering

When a setting is unexpected, ask:

Which GPO Applied It?

Not every policy must necessarily apply to every object.

Security filtering and targeting should be controlled carefully.

A GPO that is:

Correctly Configured

but:

Incorrectly Scoped

may still create security problems.

Active Directory administration can be delegated.

Example:

Helpdesk Team
Reset User Passwords
Users OU

without granting:

Domain Admin

Use:

RIGHT TASK
RIGHT ADMINISTRATOR
RIGHT SCOPE

Ask:

Who Can Create Users?
Who Can Reset Passwords?
Who Can Modify Groups?
Who Can Manage Computers?
Who Can Modify GPOs?
Who Can Change Privileged Accounts?

Part 38 — Least Privilege in Active Directory

Section titled “Part 38 — Least Privilege in Active Directory”

Poor model:

IT Team
Domain Admin

Better:

Helpdesk
Password Reset Delegation
Endpoint Team
Computer Management Delegation
Identity Team
User / Group Administration
Domain Admins
Restricted High-Level Administration

Security teams need visibility into:

Authentication
Account Creation
Account Disablement
Group Membership Changes
Privilege Changes
Policy Changes
IDENTITY EVENT
WINDOWS SECURITY EVENT
LOG COLLECTION
SIEM
ALERT / INVESTIGATION

On an authorized domain controller, use Event Viewer or approved PowerShell tooling to review security events.

Focus on categories such as:

Logon
Account Management
Group Changes
Policy Changes
Privilege Use

Do not memorize event IDs without understanding:

What Happened
Which Identity
Which System
When
What Changed

Part 41 — Account Creation Investigation

Section titled “Part 41 — Account Creation Investigation”

When a new user appears, ask:

Who Created It?
When?
Why?
Which Groups Were Assigned?
Was It Approved?
ACCOUNT CREATED
CREATOR
TIME
GROUP MEMBERSHIP
PRIVILEGE
BUSINESS CONTEXT

Part 42 — Group Membership Investigation

Section titled “Part 42 — Group Membership Investigation”

A privileged group change deserves particular attention.

Example:

User Added
Domain Admins
Privilege Increase

Ask:

Who Made the Change?
Was It Approved?
How Long Did Membership Last?
What Did the User Do Afterwards?

When a user repeatedly locks out, investigate:

Current Password
Old Stored Credentials
Mapped Drives
Services
Scheduled Tasks
Mobile Devices
Applications

Do not assume:

Lockout
=
Attack

Part 44 — Authentication Failure Scenario

Section titled “Part 44 — Authentication Failure Scenario”

Scenario:

User Cannot Log In

Use:

Account Exists?
Enabled?
Locked?
Password Correct?
DNS Working?
Domain Controller Reachable?
Policy?
Authentication Logs?

Scenario:

User Authenticates
but Cannot Access Shared Resource

This may indicate:

Authorization

rather than authentication.

Check:

Group Membership
Resource Permission
Token Refresh / Session
Policy
Resource Availability

Scenario:

Security Setting Applies
to Some Computers
but Not Others

Investigate:

OU Location
GPO Link
Security Filtering
Inheritance
Device Membership
Policy Refresh
Resultant Policy

Scenario:

Employee Left Organization
60 Days Ago
Account Still Enabled

Potential risk:

Unauthorized Future Access

Remediation:

Validate Employment Status
Disable Account
Remove Access
Preserve Required Data
Complete Offboarding

Scenario:

Helpdesk User
Is Domain Admin

Ask:

Is Domain-Wide Access Required?

If not:

Remove Excessive Privilege
Delegate Required Task

Scenario:

Backup Service Uses
Personal Employee Account

Risk:

Credential Lifecycle Problem
Ownership Problem
Password Change Failure
Accountability Problem

Better:

Dedicated Service Identity
Documented Owner
Minimum Access

Part 50 — Active Directory Security Assessment

Section titled “Part 50 — Active Directory Security Assessment”

Your assessment should review:

Domain Structure
Domain Controllers
Users
Groups
Privileged Accounts
Service Accounts
Computers
OUs
Delegation
Group Policy
Authentication
Logging
DOMAIN
IDENTITIES
GROUPS
PRIVILEGE
POLICIES
COMPUTERS
AUTHENTICATION
LOGGING
FINDINGS

Create:

Identity Type Enabled Privileged Owner Review
alice.student User Yes No Training Current
adm-bob Admin Yes Yes IT Review
svc-backup Service Yes Review Backup Team Review

Part 52 — Build a Privileged Group Matrix

Section titled “Part 52 — Build a Privileged Group Matrix”
Group Members Purpose Review Frequency
Domain Admins Review Domain administration Frequent
Administrators Review Administrative access Frequent
Custom Admin Group Review Delegated role Periodic

Part 53 — Build a Service Account Matrix

Section titled “Part 53 — Build a Service Account Matrix”
Account Application Owner Privileged Interactive Login
svc-backup Backup Infra No/Review No
svc-app Application App Team No/Review No
Computer OU Enabled Last Seen Owner
PC-001 Workstations Yes Current User Team
SRV-001 Servers Yes Current Infra
OLD-PC Workstations Yes Old Review
GPO Scope Security Purpose Owner
Domain Baseline Domain Baseline Security
Workstation Baseline Workstations Endpoint security Endpoint Team
Server Baseline Servers Server security Infra
Finding:
Dormant Active Directory Account
Observation:
An account associated with a user who no
longer requires domain access remains
enabled.
Risk:
Unused credentials may provide an
unnecessary path into enterprise resources.
Recommendation:
Validate business ownership and disable
accounts promptly when access is no longer
required.
Finding:
Excessive Privileged Group Membership
Observation:
A user has membership in a high-privilege
group beyond the requirements of their
documented role.
Risk:
Account compromise or misuse could provide
broader control over domain resources than
necessary.
Recommendation:
Remove unnecessary privileged membership
and use delegated administration aligned
to least privilege.
Finding:
Shared Administrative Identity
Observation:
Multiple administrators use a common
privileged domain account.
Risk:
Administrative activity cannot be reliably
attributed to an individual and credential
exposure affects multiple administrators.
Recommendation:
Use individually attributable privileged
accounts with controlled administrative
permissions.

Part 59 — Finding: Stale Computer Object

Section titled “Part 59 — Finding: Stale Computer Object”
Finding:
Stale Active Directory Computer Object
Observation:
An enabled computer object has not shown
expected activity and no current owner can
be identified.
Risk:
Stale directory objects can weaken asset
inventory and may retain unnecessary trust
or policy relationships.
Recommendation:
Validate ownership and retire or disable
unused computer objects through the
approved asset lifecycle process.

Part 60 — Finding: Weak Service Account Governance

Section titled “Part 60 — Finding: Weak Service Account Governance”
Finding:
Service Account Governance Gap
Observation:
A service account does not have a clearly
documented owner, purpose, or periodic
access review.
Risk:
The identity may retain unnecessary access
or credentials beyond the lifecycle of the
application.
Recommendation:
Assign an owner, document purpose, enforce
least privilege, restrict interactive use,
and review periodically.

Part 61 — Active Directory Security Report

Section titled “Part 61 — Active Directory Security Report”

Your report should contain:

Document:

Domain Assessed
Overall Identity Posture
Highest-Risk Issues
Priority Recommendations

Include:

Domain Name
Domain Controllers
Environment Purpose
Criticality

Include:

Active Users
Disabled Users
Dormant Users
Administrative Users

Document:

Security Groups
Privileged Groups
Group Ownership
Excessive Membership

Document:

Account
Application
Owner
Privilege
Authentication Requirement

Document:

Active Computers
Stale Computers
Server Objects
Workstation Objects

Document:

Structure
Purpose
Delegation
Policy Alignment

Document:

GPO Name
Scope
Purpose
Owner
Security Relevance

Document:

Domain Authentication
Password / Lockout Controls
Authentication Issues
Logging

Document:

Domain Admins
Other High-Privilege Groups
Delegated Administration
Shared Accounts

For each:

Title
Severity
Observation
Evidence
Risk
Recommendation
  • Identified domain
  • Identified domain controllers
  • Understood domain purpose
  • Documented criticality
  • Reviewed OU structure
  • Reviewed object placement
  • Reviewed delegated administration
  • Reviewed policy alignment
  • Reviewed user inventory
  • Reviewed enabled users
  • Reviewed disabled users
  • Reviewed stale accounts
  • Reviewed account ownership
  • Reviewed security groups
  • Reviewed group membership
  • Reviewed privileged groups
  • Reviewed privilege creep
  • Reviewed group ownership
  • Reviewed Domain Admins
  • Reviewed other privileged groups
  • Reviewed administrative identities
  • Reviewed shared privileged accounts
  • Applied least-privilege thinking
  • Identified service accounts
  • Identified owners
  • Reviewed privilege
  • Reviewed login requirement
  • Reviewed lifecycle
  • Reviewed computer inventory
  • Reviewed server objects
  • Reviewed workstation objects
  • Identified stale computer objects
  • Understood domain authentication
  • Understood Kerberos concept
  • Reviewed password policy concepts
  • Reviewed lockout concepts
  • Understood DNS dependency
  • Identified GPOs
  • Reviewed GPO links
  • Reviewed security purpose
  • Reviewed scope
  • Understood policy inheritance
  • Reviewed authentication events
  • Reviewed account-management events
  • Reviewed group changes
  • Reviewed privileged activity concepts
  • Understood SIEM integration
  • Created identity inventory
  • Created privileged group matrix
  • Created service account matrix
  • Created computer inventory
  • Created GPO inventory
  • Documented findings
  • Produced final report

This lab supports roles such as:

Windows Administrator
Active Directory Administrator
IAM Engineer
Identity Security Engineer
SOC Analyst
Security Engineer
Microsoft Security Engineer
Incident Responder

What is Active Directory?

A centralized directory and identity-management platform commonly used to manage:

Users
Computers
Groups
Authentication
Authorization
Policies

Why are Domain Admin accounts sensitive?

Because they can have broad administrative authority over domain resources and identity infrastructure.

What is the purpose of an OU?

To organize objects and support:

Administration
Delegation
Group Policy

Why use groups instead of assigning permissions directly to users?

Groups improve:

Scalability
Consistency
Access Reviews
Role-Based Authorization

Why is DNS important to Active Directory?

Active Directory relies heavily on DNS for locating domain services and supporting domain operations.

  1. What is Active Directory?
  2. What is a domain?
  3. What is a domain controller?
  4. Why are domain controllers critical?
  5. What is an OU?
  6. Why are OUs used?
  7. What is a user object?
  8. What is a computer object?
  9. What is a group?
  10. What is a security group?
  11. What is group scope?
  12. What is privilege creep?
  13. What is Domain Admins?
  14. Why should Domain Admin membership be limited?
  15. Why should shared admin accounts be avoided?
  16. What is delegated administration?
  17. What is least privilege?
  18. What is a service account?
  19. Why should service accounts be dedicated?
  20. What is a managed service-account concept?
  21. What is domain authentication?
  22. What is Kerberos?
  23. What is NTLM?
  24. Why is DNS important for Active Directory?
  25. What is Group Policy?
  26. What is a GPO?
  27. How do OUs relate to Group Policy?
  28. What is GPO inheritance?
  29. What is security filtering?
  30. What is account lockout?
  31. Why are stale accounts risky?
  32. Why are stale computer objects important?
  33. What is an administrative identity?
  34. Why separate admin and normal user accounts?
  35. What should be logged in Active Directory?
  36. How would you investigate a new account?
  37. How would you investigate a privileged group change?
  38. How would you troubleshoot user authentication?
  39. How would you review service-account security?
  40. How would you assess Active Directory security?

Remember:

DOMAIN
DOMAIN CONTROLLER
USERS + COMPUTERS
GROUPS
AUTHENTICATION
AUTHORIZATION
GROUP POLICY
LOGGING
SECURITY REVIEW

For identity security:

WHO EXISTS?
WHO CAN LOGIN?
WHICH GROUPS?
WHO IS PRIVILEGED?
WHICH POLICIES APPLY?
WHO CHANGED WHAT?

You have completed the first Microsoft security lab.

You can now connect:

Active Directory Architecture
Users
Groups
Computers
Organizational Units
Authentication
Privilege
Service Accounts
Group Policy
Security Logging

into a single enterprise identity-security model.

The key lesson is:

Active Directory Security
Is Primarily About
Controlling Identity and Privilege

not merely creating users.

➡️ Lab 02 — Endpoint Security

In the next lab, you will move from centralized directory identity into the devices users actually work from.

You will assess:

Windows Endpoint
Device Identity
Accounts
Local Administrators
Updates
Disk Encryption
Firewall
Endpoint Protection
Applications
Security Logs
Compliance
Security Findings

Your Microsoft lab sequence continues:

Lab 01 — Active Directory
Lab 02 — Endpoint Security
Lab 03 — Identity Security
Lab 04 — Microsoft 365 Security
Lab 05 — Windows Security
Runbook 01 — Active Directory Assessment
Runbook 02 — Microsoft 365 Security Review
Runbook 03 — Windows Security Assessment