These accounts are used by more than one (1) individual.
What are Shared IDs?
Each forest for a typical client should have just one of these.
What is a domain?
This tool correlates all logs through forwarding.
What is a SIEM?
All users require this to logon, the first step being a username and password.
What is MFA?
This MFA solution is built-in to MS tooling.
What is Authenticator?
We treat these as the "system administrators" of AD.
What is a "Domain Administrator?"
This feature on an OU overrides prcedence and inheritance.
What is enforcement?
Logs should be stored with this restriction.
What is read-only mode?
Terminated and inactive / unnecessary users are a result of this deficient process.
What is access right administration / review?
In this most popular cloud model, a provider provisions AD infrastructure.
What is Infrastructure-as-a-Service (IaaS)?
These grant full access rights to the object / machine.
What are local administrator rights?
We check GPO layouts with this tool.
What is the group policy management console (GPMC)?
This function analyzes and responds to collected logs.
What is a Security and Operations Center (SOC)?
This is most commonly unnecessarily held by service desk or security personnel.
What is full administrative access to their own machine?
This replaces GPOs for Azure environments.
This tool protects service accounts.
What is a password vault?
This policy does not follow traditional precedence and inheritance rules.
What is the default domain policy?
These types of logs cover system health, performance, and other errors.
What are event logs?
This ensures management appropriately designs all required controls for AD.
What is the risk assessment?
Thi scontrol, though it can enforce MFA, is not in itself a form of MFA.
What is condititional access?
This recommended privilege model replaces traditional security group membership.
What is a "tiered-privilege" model?
This set-up overrides GPO authentication settings.
These types of logs record who did what when.
What are audit logs?
When a full configuration program exists, this is the next best reason for persistent misconfigurations?
What is MFA?
These accounts should not be synced between cloud and on premises environments.
What are privleged accounts?