附錄Appendices

適用於:Windows Server 2016、Windows Server 2012 R2、Windows Server 2012Applies To: Windows Server 2016, Windows Server 2012 R2, Windows Server 2012

本文件擴大本文件中所包含的資訊,均附錄。Appendices are included in this document to augment the information contained in the body of the document. 附錄和每的簡短描述的清單中包含表。The list of appendices and a brief description of each in included the following table.

附錄Appendix 描述Description
B 附錄特殊權限的帳號及 Active Directory 中的群組Appendix B: Privileged Accounts and Groups in Active Directory 提供協助找出使用者和群組,您應該會對焦於因為它們可以利用攻擊者甚至破壞 Active Directory 安裝侵入您,並保護您的背景資訊。Provides background information that helps you to identify the users and groups you should focus on securing because they can be leveraged by attackers to compromise and even destroy your Active Directory installation.
C:附錄受保護的帳號及 Active Directory 中的群組Appendix C: Protected Accounts and Groups in Active Directory 包含受保護的群組 Active Directory 中相關資訊。Contains information about protected groups in Active Directory. 它也包含群組視為受保護的群組 AdminSDHolder 和 SDProp 會受到限制自訂 (移除) 的資訊。It also contains information for limited customization (removal) of groups that are considered protected groups and are affected by AdminSDHolder and SDProp.
在 Active Directory 中附錄 d 保護建系統管理員帳號Appendix D: Securing Built-In Administrator Accounts in Active Directory 包含可協助保護森林中的每個網域中管理員指導方針。Contains guidelines to help secure the Administrator account in each domain in the forest.
在 Active Directory 中附錄 e 保護企業管理員群組Appendix E: Securing Enterprise Admins Groups in Active Directory 包含指導方針操作,以協助保護森林中的企業系統管理員 」 群組。Contains guidelines to help secure the Enterprise Admins group in the forest.
在 Active Directory 中附錄 f︰ 保護網域管理員群組Appendix F: Securing Domain Admins Groups in Active Directory 包含指導方針操作,以協助保護森林中的每個網域中的網域系統管理員 」 群組。Contains guidelines to help secure the Domain Admins group in each domain in the forest.
在 Active Directory 中附錄 g:保護系統管理員群組Appendix G: Securing Administrators Groups in Active Directory 包含可協助保護建系統管理員群組森林中的每個網域中的指導方針。Contains guidelines to help secure the Built-in Administrators group in each domain in the forest.
附錄 H:WINDOWS 保護本機系統管理員帳號,並群組Appendix H: Securing Local Administrator Accounts and Groups 包含指導方針操作,以協助安全本機系統管理員帳號,並加入網域的伺服器上工作站系統管理員 」 群組。Contains guidelines to help secure local Administrator accounts and Administrators groups on domain-joined servers and workstations.
附錄 i:建立管理帳號受保護的帳號和 Active Directory 中的群組Appendix I: Creating Management Accounts for Protected Accounts and Groups in Active Directory 提供資訊,以建立帳號,有限的權限但可以嚴格控制,可以用來需要暫時提高權限時填入 Active Directory 中有特殊權限的群組。Provides information to create accounts that have limited privileges and can be stringently controlled, but can be used to populate privileged groups in Active Directory when temporary elevation is required.
事件監視器附錄 l:Appendix L: Events to Monitor 列出的活動,您應該會監視您的環境中。Lists events for which you should monitor in your environment.
附錄 m:文件的連結,並建議朗讀Appendix M: Document Links and Recommended Reading 包含建議朗讀的清單。Contains a list of recommended reading. 也包含清單連結到外部文件,以及他們的 Url,讀卡機的硬碟份文件可以存取此資訊。Also contains a list of links to external documents and their URLs so that readers of hard copies of this document can access this information.