Verify that the time within the domain is synchronized to a stratum 1 or stratum 2 time service
Verify that Active Directory servers are dedicated to that purpose, implementing the principles of separation of duties and economy of mechanism
Verify that all services configured for startup are necessary for the purpose of the servers examined
Verify that all appropriate patches have been applied in a reasonable amount of time from release
Verify that, where appropriate, DACLs and SACLs have been configured on critical or otherwise sensitive directory objects
Verify that the Schema Administrators group has no members
Inquire as to the process followed when a schema change is required
Is the process reasonable?
Does the process protect the Active Directory Schema Master from unauthorized change?
Does the process protect the Active Directory Schema Master from corruption?
Verify any cross domain trust relationships are appropriate, documented and authorized
Verify that the Active Directory is functioning at the highest functional level permitted by deployed systems
Verify that all service accounts have sufficiently long and complex passwords that they need not be changed
Verify that Administrators are using differentiated accounts with administrative rights rather than a single “Administrator” account
Verify that there are no undocumented, unused or inactive accounts in the Active Directory
Verify that all accounts in the Active Directory are for Service Accounts or current active users in the environment