Enterprise Active Directory Administration & SecurityProfessional Workshop Windows Server 2025

หลักสูตรการบริหารจัดการและรักษาความปลอดภัย Active Directory สำหรับองค์กร

Deploy / Manage / Secure / Monitor / Troubleshoot / Recover

Active Directory Domain Services (AD DS) ยังคงเป็นโครงสร้างพื้นฐานด้าน Identity, Authentication และ Authorization ที่สำคัญขององค์กรที่ใช้ระบบ Microsoft Windows โดยทำหน้าที่เป็นศูนย์กลางในการบริหาร User, Computer, Group, Group Policy และทรัพยากรภายในองค์กร

หลักสูตรนี้ออกแบบสำหรับผู้ที่รับผิดชอบ Active Directory โดยตรง ครอบคลุมทั้งการติดตั้ง การบริหารจัดการ การแก้ไขปัญหา การรักษาความปลอดภัย การตรวจสอบเหตุการณ์ และการกู้คืนระบบบน Windows Server 2025 พร้อม Lab ที่จำลองงานจริงขององค์กร

จุดเด่นของหลักสูตร

หลักสูตรนี้ไม่ได้สอนเพียง “วิธีสร้าง Domain และ User” แต่สอนให้ผู้เรียนสามารถบริหาร Active Directory ขององค์กรให้ทำงานได้อย่างถูกต้อง ปลอดภัย ตรวจสอบได้ และสามารถกู้คืนระบบเมื่อเกิดเหตุการณ์ผิดปกติ จึงเหมาะกับผู้ที่ต้องรับผิดชอบ Active Directory และ Windows Server Infrastructure ขององค์กรโดยตรง

วัตถุประสงค์ของหลักสูตร

  • ติดตั้งและ Configure Active Directory Domain Services บน Windows Server 2025
  • ออกแบบ Forest, Domain, OU และ Administrative Structure
  • บริหาร User, Group, Computer และ Service Accounts
  • จัดการ Active Directory ด้วย GUI และ PowerShell
  • ติดตั้งและ Troubleshoot DNS สำหรับ Active Directory
  • บริหาร Replication, Sites, Subnets และ FSMO Roles
  • ออกแบบและ Implement Group Policy สำหรับองค์กร
  • Delegate สิทธิ์ตามหลัก Least Privilege
  • ติดตั้งและใช้งาน Windows LAPS
  • เข้าใจและ Hardening Kerberos, NTLM และ LDAP
  • ป้องกัน Privileged Accounts และ Credential Theft
  • Configure Active Directory Auditing และวิเคราะห์ Security Events
  • ตรวจสอบสุขภาพ AD ด้วย dcdiag, repadmin และ PowerShell
  • Backup, Object Recovery และ Domain Controller Recovery
  • รับมือเหตุการณ์ผิดปกติที่เกี่ยวข้องกับ Identity Infrastructure

ผู้ที่เหมาะสมเข้ารับการอบรม

  • System Administrator
  • Windows Server Administrator
  • Active Directory Administrator
  • IT Infrastructure Administrator
  • Network & System Engineer
  • IT Support ระดับ Intermediate-Advanced
  • Cybersecurity Administrator / Security Engineer
  • IT Operation Engineer
  • IT Manager และผู้ที่ได้รับมอบหมายให้ดูแล AD ขององค์กร

พื้นฐานของผู้เข้ารับการอบรม

  • พื้นฐาน Windows Operating System
  • พื้นฐาน TCP/IP Networking, IP Address และ Subnet
  • พื้นฐาน DNS
  • พื้นฐาน Windows Server
  • ไม่จำเป็นต้องมีความรู้ Cybersecurity ระดับสูงมาก่อน

DAY 1: Building & Managing Enterprise Active Directory

Module 1: Modern Active Directory Fundamentals

1.1 Active Directory in Modern Enterprise

  • Active Directory Domain Services
  • Identity Infrastructure
  • Authentication and Authorization
  • Centralized Administration
  • Active Directory Security Boundary

1.2 Logical and Physical Components

  • Forest, Tree, Domain, Organizational Unit
  • Schema and Global Catalog
  • Domain Controller
  • Sites, Subnets and Site Links
  • Replication

1.3 Active Directory Objects

  • Users
  • Computers
  • Groups
  • Service Accounts
  • Printers, Contacts and Shared Resources

Module 2: Deploying Windows Server 2025 Active Directory

2.1 Preparing Windows Server 2025

  • Server Naming
  • Static IP and DNS Configuration
  • Time Synchronization
  • Security Considerations

2.2 Installing AD DS

  • Installing AD DS Role
  • Creating a New Forest and Domain
  • Domain Controller Promotion
  • Directory Services Restore Mode (DSRM)

2.3 Domain Controller Components

  • NTDS.DIT
  • SYSVOL
  • NETLOGON
  • Global Catalog

2.4 Functional Levels

  • Domain Functional Level
  • Forest Functional Level
  • Windows Server 2025 Compatibility Planning

Hands-on Lab 2: Building Windows Server 2025 Active Directory

  • Install AD DS Role
  • Create New Forest
  • Promote Domain Controller
  • Verify AD DS, SYSVOL, NETLOGON and DNS
  • Join Windows Client to Domain

Module 3: Designing Enterprise Active Directory

3.1 Forest and Domain Design

  • Single Forest vs Multiple Forests
  • Single Domain vs Multiple Domains
  • Security Boundaries

3.2 Organizational Unit Design

  • Department-Based Design
  • Geographic-Based Design
  • Functional and Hybrid OU Design
  • OU vs Group

3.3 Administration Design

  • Administrative Boundaries
  • Delegation of Control
  • Least Privilege

Hands-on Lab 3: Designing Enterprise OU Infrastructure

  • Create Enterprise OU Structure
  • Move AD Objects
  • Protect OU from Accidental Deletion
  • Design Administrative Structure

Module 4: Managing Users, Groups and Computers

4.1 User Account Administration

  • Create, Modify, Disable and Remove Users
  • Password Reset
  • Account Expiration
  • Logon Restrictions

4.2 Group Administration

  • Security Groups and Distribution Groups
  • Domain Local, Global and Universal
  • AGDLP / AGUDLP Models
  • Role-Based Access

4.3 Computer Accounts

  • Domain Join
  • Reset Computer Account
  • Secure Channel
  • Computer Account Troubleshooting

Hands-on Lab 4: Enterprise User and Group Administration

  • Create Users and Security Groups
  • Implement AGDLP
  • Assign Resource Permissions
  • Disable/Re-enable Accounts
  • Reset Passwords

Module 5: Active Directory Administration with PowerShell

5.1 PowerShell AD Module

  • Get-ADUser / New-ADUser / Set-ADUser
  • Get-ADComputer
  • Get-ADGroup / Get-ADGroupMember

5.2 Bulk Administration

  • CSV Import
  • Bulk User Creation
  • Bulk Account Modification
  • Account Reporting

5.3 Security-Oriented Queries

  • Disabled Users
  • Expired Accounts
  • Inactive Accounts
  • Password Never Expires
  • Dormant Accounts

Hands-on Lab 5: Automated AD Administration with PowerShell

  • Create Users from CSV
  • Assign OU and Group Membership
  • Modify Accounts in Bulk
  • Generate Administrative Report

Module 6: DNS for Active Directory

6.1 DNS Role in AD

  • Domain Name Resolution
  • Domain Controller Discovery
  • Kerberos Service Discovery

6.2 AD Integrated DNS

  • Forward Lookup Zone
  • Reverse Lookup Zone
  • Secure Dynamic Updates

6.3 DNS Records

  • A, PTR, CNAME and SRV Records

6.4 DNS Troubleshooting

  • nslookup
  • Resolve-DnsName
  • ipconfig
  • dcdiag DNS Tests

Hands-on Lab 6: Configure and Troubleshoot Active Directory DNS

  • Create Reverse Lookup Zone
  • Examine SRV Records
  • Test DC Discovery
  • Simulate DNS Failure
  • Diagnose Domain Join Failure

DAY 2: Enterprise AD Operations, Group Policy & Security

Module 7: Active Directory Replication

7.1 Replication Architecture

  • Multi-Master Replication
  • Replication Partners
  • Knowledge Consistency Checker (KCC)
  • Intra-Site and Inter-Site Replication

7.2 Monitoring Replication

  • repadmin
  • dcdiag
  • Event Viewer
  • PowerShell

Hands-on Lab 7: Deploy Second Domain Controller & Test Replication

  • Install Additional Domain Controller
  • Verify Replication
  • Create Objects on DC1 and Verify on DC2
  • Use repadmin
  • Simulate and Troubleshoot Replication Failure

Module 8: Active Directory Sites and Subnets

8.1 AD Sites Architecture

  • Sites
  • Subnets
  • Site Links

8.2 Enterprise Placement

  • Domain Controller Placement
  • Branch Office Design
  • Client Domain Controller Selection

Hands-on Lab 8: Configure Active Directory Sites

  • Create Bangkok and Branch Sites
  • Configure IP Subnets
  • Configure Site Links
  • Verify DC Selection

Module 9: FSMO Roles

9.1 Forest-Wide Roles

  • Schema Master
  • Domain Naming Master

9.2 Domain-Wide Roles

  • RID Master
  • PDC Emulator
  • Infrastructure Master

9.3 Failure and Recovery

  • FSMO Failure Scenarios
  • Transfer vs Seizure

Hands-on Lab 9: FSMO Management & Recovery

  • Identify FSMO Holders
  • Transfer FSMO Roles
  • Simulate DC Failure
  • Seize FSMO Roles
  • Verify Domain Health

Module 10: Enterprise Group Policy Management

10.1 Group Policy Architecture

  • GPO
  • Group Policy Container
  • Group Policy Template

10.2 Processing and Inheritance

  • LSDOU Processing
  • Enforced
  • Block Inheritance
  • Policy Conflict

10.3 Filtering and Troubleshooting

  • Security Filtering
  • WMI Filtering
  • gpupdate
  • gpresult
  • RSOP
  • Group Policy Event Logs

Hands-on Lab 10: Enterprise Security Group Policy

  • Configure Password and Account Lockout Policies
  • Configure Windows Firewall
  • Configure Administrative / USB Restrictions
  • Configure Security Audit and Microsoft Defender Policies
  • Verify with gpresult and RSOP

Module 11: Delegation & Privileged Administration

11.1 Least Privilege

  • Delegation of Control
  • Help Desk Permission Model
  • Administrative Role Separation

11.2 Privileged Groups

  • Domain Admins
  • Enterprise Admins
  • Schema Admins
  • Administrators

11.3 Administrative Account Model

  • Normal User Account
  • Server Administrator Account
  • Domain Administrator Account

Hands-on Lab 11: Implement Least-Privilege AD Administration

  • Create HelpDesk Admin, Server Admin and AD Admin Roles
  • Delegate Password Reset and Account Unlock
  • Verify Restricted Privileges

Module 12: Windows LAPS

12.1 Local Administrator Security

  • Risk of Shared Local Admin Passwords
  • Password Rotation

12.2 Windows LAPS Architecture

  • AD Password Backup
  • Password Encryption
  • Automatic Account Management
  • DSRM Password Management

12.3 LAPS Permission Model

  • Password Retrieval
  • Password Reset
  • Auditing

Hands-on Lab 12: Deploy Windows LAPS

  • Prepare Active Directory and Update Schema
  • Configure Permissions
  • Create and Apply LAPS GPO
  • Retrieve and Rotate Password
  • Verify LAPS Event Logs

Module 13: Kerberos, NTLM & Authentication Security

13.1 Kerberos Authentication

  • KDC
  • Authentication Service
  • Ticket Granting Service
  • TGT and Service Ticket

13.2 NTLM Authentication

  • NTLM Architecture
  • Legacy Compatibility
  • Security Risks

13.3 Authentication Hardening

  • Prefer Kerberos
  • Reduce NTLM Dependency
  • AES Kerberos Encryption
  • Authentication Auditing

Hands-on Lab 13: Analyze Kerberos Authentication

  • Authenticate Domain User
  • Examine Kerberos Tickets with klist
  • Analyze Event ID 4768 and 4769
  • Identify Authentication Flow

DAY 3: Active Directory Cybersecurity, Monitoring & Recovery

Module 14: Understanding Active Directory Attack Surface

14.1 Why Attackers Target Active Directory

  • Credential Theft
  • Privilege Escalation
  • Lateral Movement
  • Domain Compromise

14.2 Common Identity Attack Concepts

  • Password Spraying
  • Kerberoasting
  • AS-REP Roasting
  • Pass-the-Hash
  • Pass-the-Ticket
  • NTLM Relay
  • Credential Dumping

14.3 Privilege Escalation Risks

  • Excessive Permissions
  • Weak Service Accounts
  • Dangerous Group Membership
  • Misconfigured Delegation

Module 15: LDAP & Domain Controller Security

15.1 LDAP Security

  • LDAP and LDAPS
  • LDAP Signing
  • LDAP Channel Binding
  • Insecure Bind Risks

15.2 Domain Controller Hardening

  • Restrict Interactive Logon
  • Windows Firewall
  • Patch Management
  • Administrative Separation
  • Security Baseline

Hands-on Lab 15: Active Directory Security Hardening

  • Assess Weak Password Policy
  • Find Unnecessary Privileged Accounts
  • Find Password Never Expires Accounts
  • Review Legacy Authentication
  • Review LDAP and Domain Controller Security
  • Create AD Security Hardening Checklist

Module 16: Credential & Service Account Protection

16.1 Service Account Risks

  • Static Passwords
  • Password Never Expires
  • Excessive Privileges

16.2 Managed Service Accounts

  • MSA
  • gMSA

16.3 Windows Server 2025 dMSA Concept

  • Delegated Managed Service Accounts
  • Automated Credential Management
  • Migration from Traditional Service Accounts

16.4 Credential Guard

  • Virtualization-Based Security
  • NTLM Hash Protection
  • Kerberos Credential Protection

Hands-on Lab 16: Service Account & Credential Security

  • Identify Traditional Service Accounts
  • Review Service Account Permissions
  • Create gMSA
  • Configure Secure Service Authentication
  • Verify Credential Guard and Privileged Accounts

Module 17: Active Directory Auditing

17.1 Advanced Audit Policy

  • Account Logon
  • Account Management
  • Directory Service Access
  • Policy Change
  • Privilege Use

17.2 Important Security Event IDs

  • 4624 Successful Logon
  • 4625 Failed Logon
  • 4648 Explicit Credentials
  • 4672 Special Privileges
  • 4720 User Created
  • 4728/4732 Privileged Group Membership Changes
  • 4740 Account Locked
  • 4768 Kerberos TGT
  • 4769 Kerberos Service Ticket
  • 4771 Kerberos Authentication Failure

17.3 Event Sources

  • Security Logs
  • Directory Service Logs
  • DNS Logs
  • System Logs

Hands-on Lab 17: Detect Suspicious AD Activities

  • Generate Multiple Login Failures
  • Analyze Account Lockout
  • Detect Privilege Change
  • Review Administrative Logon
  • Investigate with Event Viewer and PowerShell

Module 18: Centralized Active Directory Monitoring

18.1 Windows Event Forwarding

  • Windows Event Forwarding
  • Windows Event Collector

18.2 Centralized Security Monitoring

  • Authentication Events
  • Account Changes
  • Privileged Group Changes
  • Domain Controller Events

18.3 Microsoft Defender for Identity Overview

  • Identity Monitoring
  • Suspicious Authentication
  • Lateral Movement Detection
  • Identity Security Posture

Hands-on Lab 16: Build Basic AD Security Monitoring

  • Configure Advanced Audit Policy
  • Generate Authentication Events
  • Filter Important Events
  • Query Logs with PowerShell
  • Create Security Monitoring View

Module 19: Active Directory Health Check & Troubleshooting

19.1 AD Health Assessment

  • Domain Controller
  • DNS
  • SYSVOL
  • Replication
  • FSMO
  • Time Synchronization
  • Event Logs

19.2 Essential Tools

  • dcdiag
  • repadmin
  • nltest
  • netdom
  • nslookup
  • Resolve-DnsName
  • PowerShell

19.3 Common AD Problems

  • Cannot Join Domain
  • Authentication Failure
  • DNS Failure
  • Replication Failure
  • GPO Not Applied
  • Trust Problem
  • Time Synchronization Problem

Hands-on Lab 19: Enterprise Active Directory Health Check

  • Check Domain and DC Status
  • Check DNS and Replication
  • Check FSMO and SYSVOL
  • Review Security Findings
  • Create Active Directory Health Assessment Report

Module 20: Active Directory Backup & Disaster Recovery

20.1 Backup Strategy

  • System State Backup
  • Domain Controller Backup
  • Backup Verification

20.2 Object Recovery

  • Active Directory Recycle Bin
  • Deleted Object Recovery

20.3 Disaster Recovery

  • Domain Controller Failure
  • FSMO Disaster Recovery
  • Forest Recovery Concepts

Hands-on Lab 20: Active Directory Object Recovery

  • Enable AD Recycle Bin
  • Delete User and OU
  • Recover Deleted Objects
  • Verify Group Membership and Authentication

Hands-on Lab 21: Domain Controller Disaster Recovery

  • Diagnose DC Failure
  • Check Remaining Domain Controller
  • Verify DNS and FSMO
  • Perform Required Recovery
  • Verify Replication and Authentication