QuestionQ25

Secure Windows Server infrastructure

A network contains an Active Directory Domain Services (AD DS) domain with a Windows Server 2012 R2 domain functional level. The domain includes an account named Admin1, used solely for domain administration.

You need to protect Admin1 from credential theft. The solution must prevent the domain account from using NTLM authentication, credential delegation, and cached offline sign-in.

What should you do?

Explanation

Membership in the Protected Users group applies the required protections for a Windows Server 2012 R2 domain: the account cannot authenticate with NTLM or use credential delegation, and a cached verifier is not created at sign-in or unlock, preventing offline sign-in.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!