This is such an awesome writeup, but it's missing one thing - remediation steps
— Nathan McNulty (@NathanMcNulty) July 12, 2020
Some AD admins may know how to fix these issues, but it's fair to assume some do not.
I'd also highly recommend using PingCastle by @mysmartlogon as it audits most of this and more.
Thread time! https://t.co/99LVR6tcp0