Secure Active Directory Baseline
Budget: $15 – $25 USD
I need a brand-new Active Directory forest deployed and hardened from day one. The sole focus is security: strong user authentication, tight access control, and comprehensive auditing and logging must be baked into the design rather than added later.
Scope
• Build a single-forest, single-domain AD on Windows Server (latest LTS release).
• Apply Microsoft Security Baseline templates and custom Group Policy Objects that enforce password/lockout policies, privileged group separation, and Kerberos hardening.
• Configure tiered administration, least-privilege RBAC, and protected admin workstations.
• Enable advanced auditing, forward critical events to a central log collector, and document the exact audit policies applied.
• Deliver PowerShell scripts or DSC files so the configuration can be re-run or modified automatically.
• Provide a concise hand-over document outlining every GPO, OU structure, and recovery procedure.
Acceptance
The build will be tested in a fresh VM, verified with Microsoft Security Compliance Toolkit (SCT) and Best Practice Analyzer, and must pass without critical or high findings.
If you are comfortable automating secure AD rollouts with PowerShell, Group Policy, and the SCT, your expertise will help get this new environment off to a solid, compliant start.
Scope
• Build a single-forest, single-domain AD on Windows Server (latest LTS release).
• Apply Microsoft Security Baseline templates and custom Group Policy Objects that enforce password/lockout policies, privileged group separation, and Kerberos hardening.
• Configure tiered administration, least-privilege RBAC, and protected admin workstations.
• Enable advanced auditing, forward critical events to a central log collector, and document the exact audit policies applied.
• Deliver PowerShell scripts or DSC files so the configuration can be re-run or modified automatically.
• Provide a concise hand-over document outlining every GPO, OU structure, and recovery procedure.
Acceptance
The build will be tested in a fresh VM, verified with Microsoft Security Compliance Toolkit (SCT) and Best Practice Analyzer, and must pass without critical or high findings.
If you are comfortable automating secure AD rollouts with PowerShell, Group Policy, and the SCT, your expertise will help get this new environment off to a solid, compliant start.