Active Directory provides efficiency, security, and centralized management for organizations.

Default Accounts
Default accounts are created by the OS or applications with a unique username and password, such as Administrator and Guest. They come with basic security settings and frequently used passwords; create accounts for specific needs and disable or delete default accounts.
Authorized Groups
Domain Admins and Enterprise Admins are powerful groups. Ordinary user accounts should not belong to these groups.
Audit Policy
Audit policy monitors, controls, and records network events.
Open Computer Configuration → Policies → Windows Settings → Security Settings → Advanced Audit Policy Configuration.
Local Admin Password Solution (LAPS)
LAPS regularly and automatically manages local administrator passwords.
Open Windows + R → gpmc.msc, edit the relevant GPO, then navigate to Computer Configuration → Policies → Administrative Templates → System → LAPS.
Lockout Policy
Lockout policy prevents account access for a period after incorrect password attempts, slowing brute-force attacks.
Open Computer Configuration → Policies → Windows Settings → Security Settings → Account Policies → Account Lockout Policy.
Secure Admin Workstation (SAW)
A SAW restricts a computer to privileged administration, keeping administrator credentials away from everyday software.
Service Accounts
Service accounts support systems, applications, and services.
- Use a separate account for each service or application.
- Grant only the minimum required privileges.
- Change passwords.
Events
User Activities

Group Activities

Local Admin Group Membership Control
Standard users should not belong to the local administrator group.