Improving AD security and enabling new features

Seema Kanwal Gurmani 341 Reputation points
2025-08-28T09:29:09.7333333+00:00

Dear Community,

We are in the process of enabling new security  features in our AD environment. We want to enable following:

 

  1. Disabling Kerberos Weak Encryption i.e. (DES )
  2. How to hide sensitive identifiers in Active Directory Object Descriptions
  3. Enforce LDAP signing by configuring Group Policy settings to require signing and validating it using PowerShell or the GPMC.
  4. Enabling LAPS - LAPS Local Administrator Password Management
  5. what are the best practices to do above and what be the side effects when we enable above settings?
Microsoft Security | Active Directory Federation Services
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.