AD audit & hardening
Active Directory remains the backbone — and the number one target — of most IT estates. This service combines a full tool-based audit of your directory with a prioritized hardening plan, aligned with the reference security frameworks.
AdGUARD — the tool-based audit
The audit relies on AdGUARD, our application dedicated to Active Directory security analysis: local execution, read-only, no data leaves your environment.
173 checks AD / LDAP
Privileged accounts and groups, delegations, sensitive ACLs, Kerberos, legacy protocols, password policies, replication.
Attack paths
Kerberoasting, DCSync, abusive ACLs, dangerous delegations, AD CS certificate abuse: the chains an adversary follows to Domain Admin.
Built-in frameworks
Results mapped to ANSSI, NIS2, DORA and the Microsoft Cloud Security Benchmark — every gap is linked to the matching requirement.
Baselines & history
Per-scope customizable baselines, reference audits and score tracking over time.
Reporting exploitable
CSV, Excel, JSON, HTML and PDF exports: a report for leadership, an actionable backlog for the teams.
Hardening — prioritized
An audit only has value if it turns into remediation. The hardening plan is built with your teams, in order of impact on the attack surface:
- Privileged accounts — fewer Domain Admins members, service accounts (gMSA), Protected Users, LAPS.
- Tiering model — Tier 0 / 1 / 2 segregation, PAWs, logon restrictions.
- Protocols and encryption — retiring NTLMv1 and SMBv1, LDAP/SMB signing, Kerberos AES, secure channels.
- GPOs and delegations — cleanup of legacy GPOs, review of directory ACLs and dangerous delegations.
- Contre-audit — new AdGUARD pass to measure the gain and freeze the reference audit.