High-privilege accounts should be added to the "Protected Users" group. This group enforces strict security policies (e.g., preventing NTLM authentication, preventing caching of credentials). When testing this configuration, ADUC on Windows 10 will enforce these stricter login protocols.
Running ADUC on a Windows 10 client introduces specific security considerations. ad users and computers windows 10
Windows 10’s Credential Guard (available in Enterprise editions) protects ADUC’s domain admin credentials from pass-the-hash attacks by virtualizing the Local Security Authority (LSA). High-privilege accounts should be added to the "Protected
| Feature | Description | |---------|-------------| | | Create, disable, reset passwords, unlock accounts, modify group memberships | | Computer management | Join/domain computer accounts, reset computer accounts, manage delegation | | Group management | Create security/distribution groups, manage nesting and membership | | OU management | Create/link Group Policy Objects, delegate control | | Advanced features | View system protection, object attributes, tombstone objects | Running ADUC on a Windows 10 client introduces
: Your workstation should be joined to the domain to manage it effectively.
Microsoft provides to allow Windows 10 to manage Windows Server roles. As of Windows 10 October 2018 Update (version 1809), RSAT is installed as a set of Features on Demand rather than a separate downloadable package.