Security Assessments · Michigan

Active Directory Security Assessment

A focused assessment of your on-premises and hybrid Active Directory covering hardening and security best practices.

What is an Active Directory security assessment?

An Active Directory security assessment takes a deep look at the directory at the center of most organizations' networks. We identify domain and trust relationships, insecure configurations, Kerberos and delegation weaknesses, Group Policy and permission misconfigurations, and gaps in how you separate administrative access. We also check the actual configuration of your domain and domain controllers, along with the security controls in place. Ransomware crews use these same weaknesses to go from one infected laptop to every server in the building.

Why focus on Active Directory?

Once an attacker lands on any domain-joined computer, Active Directory becomes their path. By default, every user can read most of the directory, which means every user can see the paths to Domain Admin, and so can an attacker who compromises any one of them.

Directories also collect history. Years of leftover permissions, old service accounts with weak passwords that never expire, and delegation settings someone configured for a project a decade ago all stay in place until someone goes looking.

What do you look for?

  • Security configurations and controls on your domain and domain controllers, checked against hardening best practices
  • Excessive privileges in nested groups, privileged group membership and object permissions
  • Kerberos weaknesses, including service accounts with crackable passwords
  • Delegation settings that let one compromised system impersonate users across the domain
  • Certificate services templates that hand out certificates an attacker can use to become anyone
  • Group Policy permissions and stored secrets
  • Trusts between domains and forests, and what each one exposes
  • Administrative tiering, like admin accounts signing into everyday workstations
  • Hybrid sync accounts and settings that connect on-premises AD to Entra ID

How does this differ from an internal network pentest?

An internal network penetration test exploits Active Directory weaknesses to evaluate the risk of each vulnerability or misconfiguration. An Active Directory security assessment does not include active exploitation and attack chains. It is a comprehensive, audit-style assessment instead.

The two pair well. The assessment gives you a repair list. The pentest proves the risk is real.

Will it disrupt anything?

No. The assessment reads the directory. It doesn't change it. Most of the data collection uses the same queries any domain user can already run, and we coordinate any active checks with you before we run them.

What do you need from us?

A standard domain user account and network access to a domain controller. We'll work out how to connect during scoping. If you run a hybrid environment, we'll also look at how your directory syncs to Entra ID, so let us know which tenant it connects to.

What do we get at the end?

You get a report that lays out every issue and misconfiguration we found, ranked by how objectively risky each one is, with the specific change that closes each one. Some fixes take minutes, like removing a stale permission or rotating a service account password. Others, like separating admin access into tiers, take real planning. We separate the two so your team can knock out the quick wins this week and build a plan for the rest. Then we walk you through it, and the person who did the work answers your questions.

Related services and reading

Want a full review of your directory?

Let's scope an assessment.

Let's Talk Through Your Scope