Active Directory Security Baseline: Explained

Active Directory Security Baseline: Explained

Every business organization is different from one another. They serve their customers differently, their end users behave differently, and ultimately, the way that the organization handles cyber threat is vastly different from one another. Healthcare organizations focus on data protection and uptime, while financial organizations focus on data integrity. No two organizations can follow the same cybersecurity plan. However, Microsoft and other regulatory and non-regulatory bodies recommend implementing industry-standard configuration security baselines to help navigate the complex field of securing the network environment. 

How can Security Baselines be Utilized? 

Administrators can use security baselines to: 
  1. Ensure that both user and computer configuration settings are in-line with the most recent baseline suggested.
  2. Use Microsoft-recommended Group Policy Object baselines to improve the overall security posture of their environment and decrease their attack surface. 
The most recent security baseline from Microsoft recommends administrators to relax minimum password length limits and the minimum password length audit security settings. This effectively means admins are required to enforce users to use passwords between 14 and 128 characters, provided a solid SSO and 2FA system is in place.
 
Administrators can use these baselines to access the state of security in the organization and work towards monitoring the environment while constantly closing  any security gaps and reducing the threat surface.