FLAGSHIP COURSE
Building a Secure Active Directory
EARLY ACCESS

Learn How to Build and Harden AD — Step-by-Step
Active Directory is at the heart of your Windows infrastructure — and attackers know it.
This hands-on course teaches you how to build, secure, and harden Active Directory using Microsoft best practices — from a clean demo setup to a fully secured domain environment.
🚀 You’ll create your own AD lab from scratch, configure it using modern security principles, and apply critical defenses like Kerberos armoring, tiered administration, LAPS, and more.
Whether you're managing AD in production or just getting started, this course gives you the real-world knowledge to secure your infrastructure — properly.
No online labs — you’ll build your own Hyper-V environment (use what you prefer), so you truly learn by doing.
What You'll Learn
✔ Build a secure Active Directory environment from scratch
✔ Harden domain controllers using Microsoft's best practices
✔ Implement a secure tiering model for privileged access
✔ Deploy defenses like LAPS, auditing, Kerberos armoring & more
✔ Simulate a real-world domain: DCs, WSUS, File Server, Workstations
✔ Learn critical AD concepts that directly apply to production
Who This Course Is For
🎯 System administrators, IT pros, and security teams who want to:
― Build deep AD security knowledge
― Understand what real AD hardening looks like
― Reduce privilege escalation & lateral movement risks
― Create a secure reference lab for testing or validation
🛑 Not for beginners — some basic AD/Windows knowledge required.
System Requirements
This course is fully hands-on, requiring you to build a lab environment on your own hardware. I chose to guide students through building their own lab using Hyper-V or VMware because it’s free, reusable, and more realistic. You’ll have full control of your environment — and you can keep it even after finishing the course for testing and experimenting further.
💻 Recommended setup:
● 32 GB RAM
● External SSD for VMs
● Ability to run 3–4 VMs at once
―Each with 2 vCPUs and 4 GB RAM (dynamic)
● vCPU example:
―Intel Xeon Silver 4110 CPU @ 2.10 GHz
―Total Cores: 8
―Total Threads: 16
―Equals 128 vCPUs
● 230 GB total disk space for all virtual machines
✅ Works best on Hyper-V, but you can adapt it to VMware or other platforms.
If you're unsure whether your hardware can handle it — contact us and we'll help you evaluate.
You can also run a smaller version (2 VMs) for limited testing.
Course Format & Features
🎥 Step-by-step video training
📄 Downloadable PDF guide
🛠️ Fully practical — you build everything
📧 Support available if you get stuck
🎓 Certificate of completion
📆 365-day access
🕒 Total length: 13h 50m
▶️ Demo: 11h 49m
📚 Theory: 2h 00m
⚠️ This course is not about theory — it’s about execution.
You'll follow every step from demo build to full AD hardening. By the end, you’ll have a secured AD environment you built yourself — and the knowledge to do it again in production.
🎬 Until then, enjoy a sneak peek:
● [Protected Users Group] — Block token theft & protect admin accounts
https://youtu.be/KbAFxMiB25s
● [Advanced Auditing] — Learn how to audit AD without flooding your SIEM
https://youtu.be/gwfCIQeJnWc
Course Curriculum
Available in
days
days
after you enroll
Available in
days
days
after you enroll
Available in
days
days
after you enroll
Available in
days
days
after you enroll
- Theory (40:51)
- Secure Administrator Account + Implement Tiering Model (Part 1 - Tier 0) (43:04)
- Implement Tiering Model (Part 2) (38:26)
- Use Protected Users Group (22:47)
- Create multiple Password Policies (11:57)
- Kerberos Armoring and Security Baselines (31:24)
- Security Baselines – Migration Process (31:42)
- Install LAPS and Policy Definitions (23:04)
- Advanced Audit Policy and Sysmon (44:15)
- Sysmon GPO, Domain Join, Recycle Bin, Pre-Windows 2000 Group (43:23)
- Knowledge Check
Available in
days
days
after you enroll
- Theory (19:26)
- WSUS – Part 1 (Domain Join & Domain Integration) (41:19)
- WSUS – Part 2 (Configuration & GPO) (43:31)
- WSUS – Part 3 (Optimization & Performance Tuning) (21:07)
- File Server – Part 1 (Offline Join & Domain Integration) (29:33)
- File Server – Part 2 (Remote Management & Workstation Integration) (59:52)
- Workstation - Part 1 (Pre-Windows 2000 Group & gMSA) (27:19)
- Workstation - Part 2 (Windows Updates & WSUS) (22:01)
- Knowledge Check
Available in
days
days
after you enroll
Available in
days
days
after you enroll
Available in
days
days
after you enroll