AzureHow-To & HardeningRetrospectives

How to Patch and Monitor Domain Controllers in Hybrid Azure Environments

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2020, written in 2026 with the benefit of hindsight.

Domain controllers hold the keys to your on-premises identity — and, in hybrid environments, a path to the cloud. Here is how to patch and monitor them whether they run on-premises or as Azure VMs.

Step 1: Treat domain controllers as Tier 0

Domain controllers, Entra Connect servers, AD FS servers and PKI are Tier 0. Only Tier 0 admins manage them, from privileged access workstations.

Step 2: Patch fast

  • Apply security updates to domain controllers within days for critical vulnerabilities, using a staged approach (one DC first, then the rest).
  • In Azure, use Azure Update Manager for DC VMs with maintenance windows that keep at least one DC available per site.
  • Track build numbers for all DCs in one report.

Step 3: Harden configuration

  • Remove unnecessary roles and software from DCs.
  • Enable LDAP signing and channel binding.
  • Disable SMBv1 and NTLMv1.
  • Restrict who can log on to DCs.

Step 4: Restrict network access

Use network security groups or firewalls so only domain-joined systems and required management hosts can reach DC ports. Never expose DCs to the internet.

Step 5: Monitor

  • Deploy Microsoft Defender for Identity sensors on every DC, AD FS and AD CS server. It detects Zerologon exploitation, DCSync, Kerberos attacks and suspicious replication.
  • Forward security event logs to Microsoft Sentinel.

Step 6: Back up and test recovery

Keep system state backups of DCs offline or immutable, and test forest recovery procedures. Ransomware attacks often target AD.

Step 7: Protect the cloud link

Harden Entra Connect servers like DCs, and consider cloud sync or moving away from AD FS to reduce on-prem dependencies.

domain controller hardeningZerologon2020

More on this story