Event banner
Securing Active Directory
Event details
Wondering if you should deploy Windows Server 2025 Domain Controllers? Join Active Directory Program Manager Cliff Fisher on a deep dive into new security features, policies, and defaults for Windows Server 2025, including new Windows Local Administrator Password Solution (LAPS) features, Delegated Managed Service Accounts, changes to Account Lockout and LDAP settings, and some pointers on next steps on our NTLM deprecation journey.
Speakers: Cliff Fisher
This session is part of Windows Server Summit 2025. Have a question? Q&A is open throughout the week. Post your questions and feedback in the Comments below.
32 Comments
- James_CollardCopper Contributor
Are there best practices documented (with a good example) of using Authentication Policies and Silos to aid credential tiering? I've seen examples online (mostly in lab environments) around restricting T0 accounts logging onto anything other than T0 (either defined by silo or within policy) but I feel there is more than can be done there.
- AusSupport180Brass Contributor
Hi, what will happen to the current policies when Windows 2025 DC is added to the domain?
- Cliff_Fisher
Microsoft
Current policies do not change when you deploy a Server 2025 DC.
- RahulC2310Copper Contributor
hy guys
i am stuck last 5 months from 1 issue. can u help me. let me explain my issue
my agent is read files like antivirus. but sometimes when i run my agent on window drive on that machine m not able to access any file from smb share. and its continues until i restart my window server. attached error screenshot as well. m very gratefull to get any lead from here - SalmanAhmedIron Contributor
Windows Local Admin account lock policy is a great move that will prevent potential brute force attacks by adding an extra layer of protection.
- AButtigiegCopper Contributor
Still no info regarding AGPM replacement. Anything in the pipeline?
- Cliff_Fisher
Microsoft
Unfortunately, my team does not own the Group Policy engine, so I have very little say in an AGPM replacement. I do hear the feedback consistently & will continue to pass it along to the owning team. Thank you!
- Heather_Poulsen
Community Manager
Thanks for tuning in! We hope you enjoyed this session. Q&A will remain open through Friday.
The Windows Server Summit 2025 continues.
Up next: From on-premises to cloud with Azure File Sync Thank you Cliff for the Great Session 👍
- Cliff_Fisher
Microsoft
Thanks for joining us for Windows Server Summit! If you have any feedback about AD or about this session, please email ADFeedback@microsoft.com. Thank you!
- mohit-0606Copper Contributor
Do anyone can tell me where i can watch these event later in future?
- Cliff_Fisher
Microsoft
Here, or on YouTube: Securing Active Directory
- Cliff_Fisher
Microsoft
Circle Back to Loopback is the article I was thinking of for Loopback, but pictures appear busted right now. I'll see what I can do to get those back: Circle Back to Loopback | Microsoft Community Hub
- exchange12rocksIron Contributor
Thankfully, it's all here: https://web.archive.org/web/20130214012051/http://blogs.technet.com/b/askds/archive/2013/02/08/circle-back-to-loopback.aspx