Active Directory Security
Assess identity architecture, privileged access and configuration controls across authorized Active Directory environments.
Active Directory usually predates everything else in an enterprise environment, and it has usually been changed by more people than anything else. Groups are created for a project and never removed, service accounts accumulate rights nobody audits, and permissions are granted through nested membership that no single person has ever traced end to end.
The result is an identity system where the effective permissions are genuinely difficult to know. Assessment is about establishing what those permissions actually are — which accounts can reach what, and through which relationships.
Identity risk is a graph problem
Access in Active Directory is rarely granted directly. It arrives through nested group membership, delegated rights, service account configuration and trust relationships — each individually reasonable, and collectively hard to reason about.
That is why a permission review that reads accounts one at a time tends to miss the point. The interesting question is not what an account was granted, but what it can reach once every indirect relationship is followed through.
The layers this assessment covers.
RIGHTS ARRIVE THROUGH RELATIONSHIPS — CONCEPTUAL, NOT A REAL DIRECTORY
Rights are inherited through relationships, which is what makes effective permissions hard to see.
- USERUserAn account, and the groups it belongs to
- DOMAINDomainThe directory structure and its policies
- GROUPSGroupsNested membership that accumulates rights
- PRIVILEGESPrivilegesDelegated rights and administrative roles
- RESOURCESResourcesSystems and data those privileges reach
Conceptual model of identity relationships. Assessment is performed against the environment and scope you authorize.
What we assess
This is an assessment service. Findings are documented privately to your team — this page describes what we review, not how to attack a directory.
How an AD assessment runs
- 01SCOPEAgree the domains, forests and systems in scope, in writing.
- 02COLLECTGather directory configuration and permission data.
- 03MAPResolve effective permissions through nested and delegated relationships.
- 04ANALYSEIdentify where access is broader than intended.
- 05PRIORITISERank findings by what they would actually allow.
- 06REPORTFindings with remediation guidance and hardening recommendations.
When Should Enterprise Identity Be Reviewed?
Findings your team can act on.
Which of these apply depends on engagement scope.
Weaknesses identified across the environment in scope, with the reasoning behind each.
Settings that widen exposure or weaken a boundary, described precisely enough to locate.
What a finding means in your environment rather than against a generic scoring table.
Supporting detail so findings can be verified rather than taken on trust.
Practical direction on addressing each finding, including where the change belongs.
An order of work, so limited engineering time goes to what matters most.
Verification that addressed findings no longer reproduce, within the agreed retest scope.
Adjacent parts of the infrastructure.
Questions we get asked before an engagement.
Typically a standard domain account and read access to directory configuration. Elevated access is not usually required to map permissions — and starting from an ordinary account is often more representative of what matters.
The work is primarily read and analysis of configuration, and is scoped to avoid disruption. Anything with operational risk is identified during scoping and either scheduled deliberately or excluded.
Where it is in scope, yes. Most enterprise environments now synchronise on-premise identity with a cloud provider, and that relationship is often where the interesting findings sit.
A written account of the identity weaknesses found, what each would permit, and prioritised remediation guidance — ordered by impact, since directory changes need planning.
Request an AD Security Assessment
Tell us how your directory is structured and how long it has been running. Age and change history are usually the best predictors of where to look.
