Close the Paths to Domain Admin
Active Directory and Domain Controller Audit
We audit your Active Directory forest and domain controllers for the misconfigurations attackers use to escalate. You get the attack paths mapped, the risky settings ranked, and a clear order to fix them.
See the engagement path, 6 phasesSee the full Hardening and Configuration Review service index
Overview
Active Directory is the backbone of most enterprise networks, which makes it the prize attackers aim for. Years of delegation, stale accounts and legacy protocols leave paths that lead straight to domain admin. This audit maps those paths, reviews domain controller hardening, and checks the settings that matter most: privileged group membership, Kerberos configuration, delegation, and password policy. We show you the shortest routes an attacker would take and how to cut them.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Active Directory and Domain Controller Audit engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Baseline Selection. We agree the forests and domains in scope and select the CIS Microsoft Windows Server and Active Directory hardening baselines to measure against. Activities: Map the forest, domains and trusts in scope; Count domain controllers and their OS versions; Select the CIS Windows Server and AD hardening baselines; Provision a read-only domain account for collection. Hands over AD Scope and Baseline Agreement. Phase 2, Evidence and Config Collection. Using read-only domain access we collect AD objects, group policy, trust and delegation data with ADRecon and PingCastle exports. Activities: Run ADRecon to export users, groups, computers and OUs; Run PingCastle for a scored health and risk snapshot; Export every group policy object and its linked scope; Collect trust, delegation and password policy settings. Hands over Directory Evidence Export. Phase 3, Attack-Path Analysis. We map privilege escalation routes with BloodHound and PowerView, identifying the shortest paths from ordinary users to domain admin. Activities: Map privileged group membership with BloodHound; Trace shortest paths from standard users to domain admin; Query ACL abuse routes such as GenericAll and WriteDACL; Identify Kerberoastable and AS-REP roastable accounts; Check certificate services templates for escalation paths. Hands over Attack-Path Map to Domain Admin. Phase 4, Manual Review of Risky Settings. We review domain controller hardening, Kerberos delegation, privileged group sprawl, stale accounts and legacy protocols that automated scoring can understate. Activities: Review unconstrained and constrained delegation on accounts; Check SMB signing, LDAP signing and NTLM usage on controllers; List stale accounts, dormant admins and never-expiring passwords; Assess tiering, LAPS coverage and admin workstation practice. Hands over AD Hardening Scorecard. Phase 5, Prioritised Findings. Findings are ranked by how directly they lead to compromise, with the affected objects listed so remediation is targeted. Activities: Rank findings by how directly they reach domain admin; List the affected accounts, groups and objects per finding; Separate quick wins from structural tiering work; Brief the identity team on the top escalation paths. Hands over Active Directory Findings Report. Phase 6, Remediation and Re-Check. We provide a fix order that closes the highest-value paths first, then re-run PingCastle and BloodHound to confirm the paths are gone. Activities: Set a fix order that breaks the shortest paths first; Give step-by-step guidance for each delegation and ACL change; Advise on rollout risk for protocol hardening changes; Re-run PingCastle and BloodHound to confirm paths are closed. Hands over Prioritised Remediation Runbook and Re-Check Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Baseline Selection
We agree the forests and domains in scope and select the CIS Microsoft Windows Server and Active Directory hardening baselines to measure against.
What Happens In This Phase
- Map the forest, domains and trusts in scope
- Count domain controllers and their OS versions
- Select the CIS Windows Server and AD hardening baselines
- Provision a read-only domain account for collection
The Handover
AD Scope and Baseline Agreement
The next phase starts from this.
Phase 01 Scoping and Baseline Selection
We agree the forests and domains in scope and select the CIS Microsoft Windows Server and Active Directory hardening baselines to measure against.
What Happens In This Phase
- Map the forest, domains and trusts in scope
- Count domain controllers and their OS versions
- Select the CIS Windows Server and AD hardening baselines
- Provision a read-only domain account for collection
The Handover
AD Scope and Baseline Agreement
The next phase starts from this.
- 01
Scoping and Baseline Selection
We agree the forests and domains in scope and select the CIS Microsoft Windows Server and Active Directory hardening baselines to measure against.
OutputAD Scope and Baseline AgreementActivities
- Map the forest, domains and trusts in scope
- Count domain controllers and their OS versions
- Select the CIS Windows Server and AD hardening baselines
- Provision a read-only domain account for collection
- 02
Evidence and Config Collection
Using read-only domain access we collect AD objects, group policy, trust and delegation data with ADRecon and PingCastle exports.
OutputDirectory Evidence ExportActivities
- Run ADRecon to export users, groups, computers and OUs
- Run PingCastle for a scored health and risk snapshot
- Export every group policy object and its linked scope
- Collect trust, delegation and password policy settings
- 03
Attack-Path Analysis
We map privilege escalation routes with BloodHound and PowerView, identifying the shortest paths from ordinary users to domain admin.
OutputAttack-Path Map to Domain AdminActivities
- Map privileged group membership with BloodHound
- Trace shortest paths from standard users to domain admin
- Query ACL abuse routes such as GenericAll and WriteDACL
- Identify Kerberoastable and AS-REP roastable accounts
- Check certificate services templates for escalation paths
- 04
Manual Review of Risky Settings
We review domain controller hardening, Kerberos delegation, privileged group sprawl, stale accounts and legacy protocols that automated scoring can understate.
OutputAD Hardening ScorecardActivities
- Review unconstrained and constrained delegation on accounts
- Check SMB signing, LDAP signing and NTLM usage on controllers
- List stale accounts, dormant admins and never-expiring passwords
- Assess tiering, LAPS coverage and admin workstation practice
- 05
Prioritised Findings
Findings are ranked by how directly they lead to compromise, with the affected objects listed so remediation is targeted.
OutputActive Directory Findings ReportActivities
- Rank findings by how directly they reach domain admin
- List the affected accounts, groups and objects per finding
- Separate quick wins from structural tiering work
- Brief the identity team on the top escalation paths
- 06
Remediation and Re-Check
We provide a fix order that closes the highest-value paths first, then re-run PingCastle and BloodHound to confirm the paths are gone.
OutputPrioritised Remediation Runbook and Re-Check ReportActivities
- Set a fix order that breaks the shortest paths first
- Give step-by-step guidance for each delegation and ACL change
- Advise on rollout risk for protocol hardening changes
- Re-run PingCastle and BloodHound to confirm paths are closed
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Active Directory and Domain Controller Audit scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: BloodHound, PingCastle, PowerView, PurpleKnight, ADRecon, Microsoft Security Compliance Toolkit, Group Policy analysis, CIS-CAT Pro. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: CIS Microsoft Windows Server Benchmarks, CIS Microsoft Active Directory hardening references, DISA Active Directory and Windows Server STIGs, Microsoft security baselines, NIST SP 800-53, MITRE ATT&CK (Credential Access, Privilege Escalation).
What We Run
8 tools
- PowerView
- PurpleKnight
- ADRecon
- Microsoft Security Compliance Toolkit
- Group Policy analysis
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
6 standards
- CIS
- CISHardening
- DISAActive Directory
- MSMicrosoft
Deliverables
What You Receive
- Active Directory findings report
- Attack-path map to domain admin
- AD hardening scorecard
- Prioritised remediation runbook
- Re-check report after remediation
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Is running these tools safe in production?
Yes. We use read-only collection and schedule any heavier queries with you. Nothing changes your directory; we only read and analyse.
What is an attack path?
It is the chain of memberships, permissions and delegations that lets an ordinary account reach domain admin. We map the shortest ones so you can break them.
Do you cover Entra ID as well?
This audit focuses on on-premises Active Directory and domain controllers. We can extend to Entra ID and hybrid identity as a separate scope.
Keep Moving Through Hardening and Configuration Review
Service 4 of 5 in this practice area
Practice Area
More in Hardening and Configuration Review
- Cloud Security Configuration AssessmentBenchmark review of your AWS, Azure and GCP accounts against secure baselines
- Operating System Hardening ReviewBenchmark comparison of your Windows and Linux builds against CIS and STIG baselines
- Firewall and Perimeter ReviewRule-base and configuration review of your firewalls, VPNs and edge devices
- Database and Web Server ConfigurationHardening review of your databases and web servers against CIS Benchmarks