I compiled years of Active Directory admin notes into a 28-page quick reference (PowerShell, GPO, Event IDs, attacks)

Posted by Available_Ad9294@reddit | sysadmin | View on Reddit | 16 comments

I put together an Active Directory quick reference guide that I've been building out from notes accumulated over years of managing AD environments. I put it up on Gumroad — if anyone’s interested, just let me know and I can share it. It's 28 pages — covers the stuff that actually comes up: PowerShell commands for the full user lifecycle, the AGDLP/AGUDLP nesting model with worked examples, GPO processing and troubleshooting, a full Event ID reference with logon type codes and 4625 sub-status codes so you know exactly why a login failed without guessing, and an adversary awareness section covering Pass-the-Hash, Kerberoasting, Golden Ticket, DCSync, password spray, AdminSDHolder abuse, and GPO hijacking — each with detection Event IDs and specific mitigations. There's also a daily/weekly/monthly/quarterly admin checklist with the actual commands baked in, and a 45-term glossary. The goal was to have one document open on a second monitor instead of 12 browser tabs. If your environment runs on AD and you want something you can actually reference at speed, it might be worth it. Happy to answer questions about what's covered.