หลักสูตรการบริหารจัดการและรักษาความปลอดภัย Active Directory สำหรับองค์กร
Deploy / Manage / Secure / Monitor / Troubleshoot / Recover
Active Directory Domain Services (AD DS) ยังคงเป็นโครงสร้างพื้นฐานด้าน Identity, Authentication และ Authorization ที่สำคัญขององค์กรที่ใช้ระบบ Microsoft Windows โดยทำหน้าที่เป็นศูนย์กลางในการบริหาร User, Computer, Group, Group Policy และทรัพยากรภายในองค์กร
หลักสูตรนี้ออกแบบสำหรับผู้ที่รับผิดชอบ Active Directory โดยตรง ครอบคลุมทั้งการติดตั้ง การบริหารจัดการ การแก้ไขปัญหา การรักษาความปลอดภัย การตรวจสอบเหตุการณ์ และการกู้คืนระบบบน Windows Server 2025 พร้อม Lab ที่จำลองงานจริงขององค์กร
จุดเด่นของหลักสูตร
หลักสูตรนี้ไม่ได้สอนเพียง “วิธีสร้าง Domain และ User” แต่สอนให้ผู้เรียนสามารถบริหาร Active Directory ขององค์กรให้ทำงานได้อย่างถูกต้อง ปลอดภัย ตรวจสอบได้ และสามารถกู้คืนระบบเมื่อเกิดเหตุการณ์ผิดปกติ จึงเหมาะกับผู้ที่ต้องรับผิดชอบ Active Directory และ Windows Server Infrastructure ขององค์กรโดยตรง
วัตถุประสงค์ของหลักสูตร
- ติดตั้งและ Configure Active Directory Domain Services บน Windows Server 2025
- ออกแบบ Forest, Domain, OU และ Administrative Structure
- บริหาร User, Group, Computer และ Service Accounts
- จัดการ Active Directory ด้วย GUI และ PowerShell
- ติดตั้งและ Troubleshoot DNS สำหรับ Active Directory
- บริหาร Replication, Sites, Subnets และ FSMO Roles
- ออกแบบและ Implement Group Policy สำหรับองค์กร
- Delegate สิทธิ์ตามหลัก Least Privilege
- ติดตั้งและใช้งาน Windows LAPS
- เข้าใจและ Hardening Kerberos, NTLM และ LDAP
- ป้องกัน Privileged Accounts และ Credential Theft
- Configure Active Directory Auditing และวิเคราะห์ Security Events
- ตรวจสอบสุขภาพ AD ด้วย dcdiag, repadmin และ PowerShell
- Backup, Object Recovery และ Domain Controller Recovery
- รับมือเหตุการณ์ผิดปกติที่เกี่ยวข้องกับ Identity Infrastructure
ผู้ที่เหมาะสมเข้ารับการอบรม
- System Administrator
- Windows Server Administrator
- Active Directory Administrator
- IT Infrastructure Administrator
- Network & System Engineer
- IT Support ระดับ Intermediate-Advanced
- Cybersecurity Administrator / Security Engineer
- IT Operation Engineer
- IT Manager และผู้ที่ได้รับมอบหมายให้ดูแล AD ขององค์กร
พื้นฐานของผู้เข้ารับการอบรม
- พื้นฐาน Windows Operating System
- พื้นฐาน TCP/IP Networking, IP Address และ Subnet
- พื้นฐาน DNS
- พื้นฐาน Windows Server
- ไม่จำเป็นต้องมีความรู้ Cybersecurity ระดับสูงมาก่อน
DAY 1: Building & Managing Enterprise Active Directory
Module 1: Modern Active Directory Fundamentals
1.1 Active Directory in Modern Enterprise
- Active Directory Domain Services
- Identity Infrastructure
- Authentication and Authorization
- Centralized Administration
- Active Directory Security Boundary
1.2 Logical and Physical Components
- Forest, Tree, Domain, Organizational Unit
- Schema and Global Catalog
- Domain Controller
- Sites, Subnets and Site Links
- Replication
1.3 Active Directory Objects
- Users
- Computers
- Groups
- Service Accounts
- Printers, Contacts and Shared Resources
Module 2: Deploying Windows Server 2025 Active Directory
2.1 Preparing Windows Server 2025
- Server Naming
- Static IP and DNS Configuration
- Time Synchronization
- Security Considerations
2.2 Installing AD DS
- Installing AD DS Role
- Creating a New Forest and Domain
- Domain Controller Promotion
- Directory Services Restore Mode (DSRM)
2.3 Domain Controller Components
- NTDS.DIT
- SYSVOL
- NETLOGON
- Global Catalog
2.4 Functional Levels
- Domain Functional Level
- Forest Functional Level
- Windows Server 2025 Compatibility Planning
Hands-on Lab 2: Building Windows Server 2025 Active Directory
- Install AD DS Role
- Create New Forest
- Promote Domain Controller
- Verify AD DS, SYSVOL, NETLOGON and DNS
- Join Windows Client to Domain
Module 3: Designing Enterprise Active Directory
3.1 Forest and Domain Design
- Single Forest vs Multiple Forests
- Single Domain vs Multiple Domains
- Security Boundaries
3.2 Organizational Unit Design
- Department-Based Design
- Geographic-Based Design
- Functional and Hybrid OU Design
- OU vs Group
3.3 Administration Design
- Administrative Boundaries
- Delegation of Control
- Least Privilege
Hands-on Lab 3: Designing Enterprise OU Infrastructure
- Create Enterprise OU Structure
- Move AD Objects
- Protect OU from Accidental Deletion
- Design Administrative Structure
Module 4: Managing Users, Groups and Computers
4.1 User Account Administration
- Create, Modify, Disable and Remove Users
- Password Reset
- Account Expiration
- Logon Restrictions
4.2 Group Administration
- Security Groups and Distribution Groups
- Domain Local, Global and Universal
- AGDLP / AGUDLP Models
- Role-Based Access
4.3 Computer Accounts
- Domain Join
- Reset Computer Account
- Secure Channel
- Computer Account Troubleshooting
Hands-on Lab 4: Enterprise User and Group Administration
- Create Users and Security Groups
- Implement AGDLP
- Assign Resource Permissions
- Disable/Re-enable Accounts
- Reset Passwords
Module 5: Active Directory Administration with PowerShell
5.1 PowerShell AD Module
- Get-ADUser / New-ADUser / Set-ADUser
- Get-ADComputer
- Get-ADGroup / Get-ADGroupMember
5.2 Bulk Administration
- CSV Import
- Bulk User Creation
- Bulk Account Modification
- Account Reporting
5.3 Security-Oriented Queries
- Disabled Users
- Expired Accounts
- Inactive Accounts
- Password Never Expires
- Dormant Accounts
Hands-on Lab 5: Automated AD Administration with PowerShell
- Create Users from CSV
- Assign OU and Group Membership
- Modify Accounts in Bulk
- Generate Administrative Report
Module 6: DNS for Active Directory
6.1 DNS Role in AD
- Domain Name Resolution
- Domain Controller Discovery
- Kerberos Service Discovery
6.2 AD Integrated DNS
- Forward Lookup Zone
- Reverse Lookup Zone
- Secure Dynamic Updates
6.3 DNS Records
- A, PTR, CNAME and SRV Records
6.4 DNS Troubleshooting
- nslookup
- Resolve-DnsName
- ipconfig
- dcdiag DNS Tests
Hands-on Lab 6: Configure and Troubleshoot Active Directory DNS
- Create Reverse Lookup Zone
- Examine SRV Records
- Test DC Discovery
- Simulate DNS Failure
- Diagnose Domain Join Failure
DAY 2: Enterprise AD Operations, Group Policy & Security
Module 7: Active Directory Replication
7.1 Replication Architecture
- Multi-Master Replication
- Replication Partners
- Knowledge Consistency Checker (KCC)
- Intra-Site and Inter-Site Replication
7.2 Monitoring Replication
- repadmin
- dcdiag
- Event Viewer
- PowerShell
Hands-on Lab 7: Deploy Second Domain Controller & Test Replication
- Install Additional Domain Controller
- Verify Replication
- Create Objects on DC1 and Verify on DC2
- Use repadmin
- Simulate and Troubleshoot Replication Failure
Module 8: Active Directory Sites and Subnets
8.1 AD Sites Architecture
- Sites
- Subnets
- Site Links
8.2 Enterprise Placement
- Domain Controller Placement
- Branch Office Design
- Client Domain Controller Selection
Hands-on Lab 8: Configure Active Directory Sites
- Create Bangkok and Branch Sites
- Configure IP Subnets
- Configure Site Links
- Verify DC Selection
Module 9: FSMO Roles
9.1 Forest-Wide Roles
- Schema Master
- Domain Naming Master
9.2 Domain-Wide Roles
- RID Master
- PDC Emulator
- Infrastructure Master
9.3 Failure and Recovery
- FSMO Failure Scenarios
- Transfer vs Seizure
Hands-on Lab 9: FSMO Management & Recovery
- Identify FSMO Holders
- Transfer FSMO Roles
- Simulate DC Failure
- Seize FSMO Roles
- Verify Domain Health
Module 10: Enterprise Group Policy Management
10.1 Group Policy Architecture
- GPO
- Group Policy Container
- Group Policy Template
10.2 Processing and Inheritance
- LSDOU Processing
- Enforced
- Block Inheritance
- Policy Conflict
10.3 Filtering and Troubleshooting
- Security Filtering
- WMI Filtering
- gpupdate
- gpresult
- RSOP
- Group Policy Event Logs
Hands-on Lab 10: Enterprise Security Group Policy
- Configure Password and Account Lockout Policies
- Configure Windows Firewall
- Configure Administrative / USB Restrictions
- Configure Security Audit and Microsoft Defender Policies
- Verify with gpresult and RSOP
Module 11: Delegation & Privileged Administration
11.1 Least Privilege
- Delegation of Control
- Help Desk Permission Model
- Administrative Role Separation
11.2 Privileged Groups
- Domain Admins
- Enterprise Admins
- Schema Admins
- Administrators
11.3 Administrative Account Model
- Normal User Account
- Server Administrator Account
- Domain Administrator Account
Hands-on Lab 11: Implement Least-Privilege AD Administration
- Create HelpDesk Admin, Server Admin and AD Admin Roles
- Delegate Password Reset and Account Unlock
- Verify Restricted Privileges
Module 12: Windows LAPS
12.1 Local Administrator Security
- Risk of Shared Local Admin Passwords
- Password Rotation
12.2 Windows LAPS Architecture
- AD Password Backup
- Password Encryption
- Automatic Account Management
- DSRM Password Management
12.3 LAPS Permission Model
- Password Retrieval
- Password Reset
- Auditing
Hands-on Lab 12: Deploy Windows LAPS
- Prepare Active Directory and Update Schema
- Configure Permissions
- Create and Apply LAPS GPO
- Retrieve and Rotate Password
- Verify LAPS Event Logs
Module 13: Kerberos, NTLM & Authentication Security
13.1 Kerberos Authentication
- KDC
- Authentication Service
- Ticket Granting Service
- TGT and Service Ticket
13.2 NTLM Authentication
- NTLM Architecture
- Legacy Compatibility
- Security Risks
13.3 Authentication Hardening
- Prefer Kerberos
- Reduce NTLM Dependency
- AES Kerberos Encryption
- Authentication Auditing
Hands-on Lab 13: Analyze Kerberos Authentication
- Authenticate Domain User
- Examine Kerberos Tickets with klist
- Analyze Event ID 4768 and 4769
- Identify Authentication Flow
DAY 3: Active Directory Cybersecurity, Monitoring & Recovery
Module 14: Understanding Active Directory Attack Surface
14.1 Why Attackers Target Active Directory
- Credential Theft
- Privilege Escalation
- Lateral Movement
- Domain Compromise
14.2 Common Identity Attack Concepts
- Password Spraying
- Kerberoasting
- AS-REP Roasting
- Pass-the-Hash
- Pass-the-Ticket
- NTLM Relay
- Credential Dumping
14.3 Privilege Escalation Risks
- Excessive Permissions
- Weak Service Accounts
- Dangerous Group Membership
- Misconfigured Delegation
Module 15: LDAP & Domain Controller Security
15.1 LDAP Security
- LDAP and LDAPS
- LDAP Signing
- LDAP Channel Binding
- Insecure Bind Risks
15.2 Domain Controller Hardening
- Restrict Interactive Logon
- Windows Firewall
- Patch Management
- Administrative Separation
- Security Baseline
Hands-on Lab 15: Active Directory Security Hardening
- Assess Weak Password Policy
- Find Unnecessary Privileged Accounts
- Find Password Never Expires Accounts
- Review Legacy Authentication
- Review LDAP and Domain Controller Security
- Create AD Security Hardening Checklist
Module 16: Credential & Service Account Protection
16.1 Service Account Risks
- Static Passwords
- Password Never Expires
- Excessive Privileges
16.2 Managed Service Accounts
- MSA
- gMSA
16.3 Windows Server 2025 dMSA Concept
- Delegated Managed Service Accounts
- Automated Credential Management
- Migration from Traditional Service Accounts
16.4 Credential Guard
- Virtualization-Based Security
- NTLM Hash Protection
- Kerberos Credential Protection
Hands-on Lab 16: Service Account & Credential Security
- Identify Traditional Service Accounts
- Review Service Account Permissions
- Create gMSA
- Configure Secure Service Authentication
- Verify Credential Guard and Privileged Accounts
Module 17: Active Directory Auditing
17.1 Advanced Audit Policy
- Account Logon
- Account Management
- Directory Service Access
- Policy Change
- Privilege Use
17.2 Important Security Event IDs
- 4624 Successful Logon
- 4625 Failed Logon
- 4648 Explicit Credentials
- 4672 Special Privileges
- 4720 User Created
- 4728/4732 Privileged Group Membership Changes
- 4740 Account Locked
- 4768 Kerberos TGT
- 4769 Kerberos Service Ticket
- 4771 Kerberos Authentication Failure
17.3 Event Sources
- Security Logs
- Directory Service Logs
- DNS Logs
- System Logs
Hands-on Lab 17: Detect Suspicious AD Activities
- Generate Multiple Login Failures
- Analyze Account Lockout
- Detect Privilege Change
- Review Administrative Logon
- Investigate with Event Viewer and PowerShell
Module 18: Centralized Active Directory Monitoring
18.1 Windows Event Forwarding
- Windows Event Forwarding
- Windows Event Collector
18.2 Centralized Security Monitoring
- Authentication Events
- Account Changes
- Privileged Group Changes
- Domain Controller Events
18.3 Microsoft Defender for Identity Overview
- Identity Monitoring
- Suspicious Authentication
- Lateral Movement Detection
- Identity Security Posture
Hands-on Lab 16: Build Basic AD Security Monitoring
- Configure Advanced Audit Policy
- Generate Authentication Events
- Filter Important Events
- Query Logs with PowerShell
- Create Security Monitoring View
Module 19: Active Directory Health Check & Troubleshooting
19.1 AD Health Assessment
- Domain Controller
- DNS
- SYSVOL
- Replication
- FSMO
- Time Synchronization
- Event Logs
19.2 Essential Tools
- dcdiag
- repadmin
- nltest
- netdom
- nslookup
- Resolve-DnsName
- PowerShell
19.3 Common AD Problems
- Cannot Join Domain
- Authentication Failure
- DNS Failure
- Replication Failure
- GPO Not Applied
- Trust Problem
- Time Synchronization Problem
Hands-on Lab 19: Enterprise Active Directory Health Check
- Check Domain and DC Status
- Check DNS and Replication
- Check FSMO and SYSVOL
- Review Security Findings
- Create Active Directory Health Assessment Report
Module 20: Active Directory Backup & Disaster Recovery
20.1 Backup Strategy
- System State Backup
- Domain Controller Backup
- Backup Verification
20.2 Object Recovery
- Active Directory Recycle Bin
- Deleted Object Recovery
20.3 Disaster Recovery
- Domain Controller Failure
- FSMO Disaster Recovery
- Forest Recovery Concepts
Hands-on Lab 20: Active Directory Object Recovery
- Enable AD Recycle Bin
- Delete User and OU
- Recover Deleted Objects
- Verify Group Membership and Authentication
Hands-on Lab 21: Domain Controller Disaster Recovery
- Diagnose DC Failure
- Check Remaining Domain Controller
- Verify DNS and FSMO
- Perform Required Recovery
- Verify Replication and Authentication
