6.6 KiB
Chapter 4 - Active Directory
In this chapter, you'll build the Active Directory environment that powers the corporate network. This includes deploying a Domain Controller, configuring DNS, creating users and groups, joining workstations to the domain, and intentionally introducing realistic misconfigurations for security testing.
Objectives
By the end of this chapter, you will have:
- Windows Server 2022 installed
- Active Directory Domain Services (AD DS) configured
- DNS configured
- A new domain created
- Organizational Units (OUs)
- Domain users and groups
- Service accounts
- Domain-joined Windows clients
- Group Policy configured
- A realistic enterprise directory for penetration testing
Active Directory Overview
Active Directory (AD) is Microsoft's centralized identity and authentication platform.
It provides:
- Authentication
- Authorization
- DNS
- Kerberos
- LDAP
- Group Policy
- Computer management
- User management
Almost every medium or large Windows environment relies on Active Directory.
Lab Topology
Corporate LAN
10.10.20.0/24
+----------------------------------+
| |
DC01 WIN10-01
| |
| WIN10-02
|
FILE01
|
SQL01
|
LINUX01
Domain Controller VM
Recommended specifications:
| Setting | Value |
|---|---|
| CPU | 2–4 vCPU |
| RAM | 4096–8192 MB |
| Disk | 100 GB |
| Bridge | vmbr2 |
Static configuration:
Hostname : DC01
IP : 10.10.20.10
Mask : 255.255.255.0
Gateway : 10.10.20.1
DNS : 10.10.20.10
Notice that after installing AD, the server points DNS to itself.
Installing Active Directory
Open:
Server Manager
Select:
Add Roles and Features
Install:
- Active Directory Domain Services
- DNS Server
After installation:
Select:
Promote this server to a Domain Controller
Create a New Forest
Domain name:
lab.local
Although .local is acceptable for a lab, a production environment would typically use a registered internal namespace such as corp.example.com.
Set a Directory Services Restore Mode (DSRM) password and document it securely.
Organizational Units
Avoid placing users directly in the default Users container.
Create the following OUs:
LAB.LOCAL
├── Servers
├── Workstations
├── Users
├── Service Accounts
├── IT
├── HR
├── Finance
└── Security
Keeping objects organized makes administration easier and allows targeted Group Policies.
User Accounts
Create realistic users:
| Username | Department |
|---|---|
| john.smith | IT |
| sarah.jones | HR |
| michael.brown | Finance |
| emily.davis | Security |
| helpdesk | IT |
Create passwords that are memorable but not identical.
Example:
Winter2026!
Avoid using the same password everywhere unless intentionally creating a vulnerable scenario.
Administrative Accounts
Create dedicated administrative accounts.
Examples:
administrator
itadmin
domainadmin
Avoid logging into workstations with highly privileged accounts during normal operation.
Service Accounts
Many enterprise attacks target service accounts.
Create:
svc_backup
svc_sql
svc_web
Later chapters will intentionally configure weak permissions or Service Principal Names (SPNs) to practice attacks such as Kerberoasting.
Security Groups
Create groups such as:
IT
HR
Finance
Developers
Helpdesk
Server Admins
SQL Admins
Assign users based on job function rather than individual permissions.
Domain Computers
Join the following systems to the domain:
WIN10-01
WIN10-02
FILE01
SQL01
Linux systems will remain standalone for now.
Joining a Workstation
Configure:
IP Address : 10.10.20.20
Gateway : 10.10.20.1
DNS : 10.10.20.10
Open:
System Properties
Change the computer from a workgroup to the LAB.LOCAL domain.
Restart the machine when prompted.
Verify the computer appears under the Computers container, then move it into the Workstations OU.
DNS Verification
From a workstation:
nslookup dc01.lab.local
You should receive:
10.10.20.10
Test name resolution before moving on.
Group Policy
Create a baseline GPO for the Workstations OU.
Example settings:
- Disable guest account
- Configure Windows Update
- Set desktop wallpaper
- Enable Remote Desktop (optional)
- Configure password policy
- Enable auditing
Later, you can create intentionally weak GPOs to practice abuse.
File Shares
On FILE01 create:
Finance
HR
IT
Public
Software
Use different NTFS and share permissions to simulate real departments.
Some shares can intentionally have excessive permissions for later exercises.
SQL Server
Deploy SQL Server Express on SQL01.
Create:
- Sample databases
- SQL logins
- Windows authentication
This provides targets for SQL enumeration and privilege escalation.
Common AD Attacks to Practice
After the environment is complete, you'll be able to explore:
- SMB Enumeration
- LDAP Enumeration
- Kerberos Enumeration
- Password Spraying
- AS-REP Roasting
- Kerberoasting
- BloodHound Collection
- Lateral Movement
- Pass-the-Hash
- Pass-the-Ticket
- Group Policy Abuse
- Unconstrained Delegation
- Resource-Based Constrained Delegation (RBCD)
Recommended Snapshots
Take snapshots after each milestone:
SERVER_INSTALLED
AD_INSTALLED
USERS_CREATED
WORKSTATIONS_JOINED
READY_FOR_ATTACK
This lets you reset the environment after exercises.
Validation Checklist
Before continuing:
- Windows Server installed
- AD DS installed
- DNS installed
LAB.LOCALdomain created- Organizational Units created
- User accounts created
- Service accounts created
- Security groups created
- Workstations joined to the domain
- DNS resolution verified
- Baseline Group Policy applied
- Snapshot created
Next Chapter
The next chapter covers the Kali Linux attack workstation.
Topics include:
- Installing offensive security tools
- Building a consistent pentesting toolkit
- Configuring SSH keys
- Setting up wordlists
- Installing Impacket, BloodHound, Ligolo-ng, and other utilities
- Creating reusable aliases and scripts
- Organizing notes and reports for engagements