Microsoft’s Active Directory
What is Microsoft's Active Directory?
Active Directory provides the means to manage the identities and relationships that make up your organization’s network. Active Directory gives you out-of-the-box functionality needed to centrally configure and administer system, user, and application settings. Active Directory Domain Services (AD DS) stores directory data and manages communication between users and domains, including user logon processes, authentication, and directory searches.
It is responsible for authenticating and authorizing all users and computers within a network of Windows domain type, assigning and enforcing security policies for all computers in a network and installing or updating software on network computers. Secure Domain Controller Policy Setting
Security Feature
Establishing Group Policy settings for your domains in Active Directory, you can also establish Group Policy settings and Windows 2000 configuration settings to secure your domain controllers. Domain controller policies are set on the Domain Controllers organizational unit (OU) in each domain.- Secure Domain Controller Policy Setting
Domain controller policies are divided into multiple categories of settings. To enhance comprehensive security for your domain controllers, perform the following tasks: Establish domain controller user rights assignment policy settings.
- Establish domain controller audit policy settings.
- Enable auditing on Active Directory database objects.
- Establish domain controller security options policy settings.
- Establish domain controller event log policy settings.
http://technet.microsoft.com/en-us/library/bb727065.aspx
http://www.promedianj.com/data-center-and-virtualization/microsoft-solutions