How to Patch and Monitor Domain Controllers in Hybrid Azure Environments
Retrospective: this article looks back at events from September 2020, written in 2026 with the benefit of hindsight.
Domain controllers hold the keys to your on-premises identity — and, in hybrid environments, a path to the cloud. Here is how to patch and monitor them whether they run on-premises or as Azure VMs.
Step 1: Treat domain controllers as Tier 0
Domain controllers, Entra Connect servers, AD FS servers and PKI are Tier 0. Only Tier 0 admins manage them, from privileged access workstations.
Step 2: Patch fast
- Apply security updates to domain controllers within days for critical vulnerabilities, using a staged approach (one DC first, then the rest).
- In Azure, use Azure Update Manager for DC VMs with maintenance windows that keep at least one DC available per site.
- Track build numbers for all DCs in one report.
Step 3: Harden configuration
- Remove unnecessary roles and software from DCs.
- Enable LDAP signing and channel binding.
- Disable SMBv1 and NTLMv1.
- Restrict who can log on to DCs.
Step 4: Restrict network access
Use network security groups or firewalls so only domain-joined systems and required management hosts can reach DC ports. Never expose DCs to the internet.
Step 5: Monitor
- Deploy Microsoft Defender for Identity sensors on every DC, AD FS and AD CS server. It detects Zerologon exploitation, DCSync, Kerberos attacks and suspicious replication.
- Forward security event logs to Microsoft Sentinel.
Step 6: Back up and test recovery
Keep system state backups of DCs offline or immutable, and test forest recovery procedures. Ransomware attacks often target AD.
Step 7: Protect the cloud link
Harden Entra Connect servers like DCs, and consider cloud sync or moving away from AD FS to reduce on-prem dependencies.
- Zerologon (Aug–Sept 2020): Taking Over a Domain Controller in Seconds Incident Teardowns
- Detecting Netlogon Exploitation: Defender for Cloud and Sentinel KQL Detection & Response
- CIO Brief: Hybrid Identity Means On-Prem Flaws Become Cloud Flaws CIO Briefings