Active Directory has been around for decades and is still the identity backbone of most schools. Attackers know this, compromise the AD, and then often own the entire environment. Today, many districts also run Microsoft Entra ID (formerly Azure AD) alongside their on-prem AD. This hybrid model expands your attack surface but also gives you more free/built-in defenses if you use them wisely. Here are four practical ways to harden your environment using only built-in Microsoft tools. 1. Deploy Microsoft LAPS (Local Administrator Password Solution) Why it matters: Attackers love reusing local admin credentials across multiple machines. If every computer in your district has the same local admin password, one compromise means they own them all. What LAPS does: Randomizes each computer’s local administrator password. Stores the unique password securely in AD, accessible only by authorized admins. Rotates automatically on a schedule. How to implement: Download LAPS (free from Microsoft)....
The Greenbush K12 Tech Blog is dedicated to exploring the unique challenges and opportunities at the intersection of education, technology, and cybersecurity. Greenbush's mission is to help schools, educators, and IT leaders understand the evolving digital risks facing K-12 environments and how to build safer, more resilient learning communities.