Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Part of Hardening and Configuration Review5 services in this practice area

Close the Paths to Domain Admin

Active Directory and Domain Controller Audit

We audit your Active Directory forest and domain controllers for the misconfigurations attackers use to escalate. You get the attack paths mapped, the risky settings ranked, and a clear order to fix them.

See the engagement path, 6 phasesSee the full Hardening and Configuration Review service index

Overview

Active Directory is the backbone of most enterprise networks, which makes it the prize attackers aim for. Years of delegation, stale accounts and legacy protocols leave paths that lead straight to domain admin. This audit maps those paths, reviews domain controller hardening, and checks the settings that matter most: privileged group membership, Kerberos configuration, delegation, and password policy. We show you the shortest routes an attacker would take and how to cut them.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the Active Directory and Domain Controller Audit engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Baseline Selection. We agree the forests and domains in scope and select the CIS Microsoft Windows Server and Active Directory hardening baselines to measure against. Activities: Map the forest, domains and trusts in scope; Count domain controllers and their OS versions; Select the CIS Windows Server and AD hardening baselines; Provision a read-only domain account for collection. Hands over AD Scope and Baseline Agreement. Phase 2, Evidence and Config Collection. Using read-only domain access we collect AD objects, group policy, trust and delegation data with ADRecon and PingCastle exports. Activities: Run ADRecon to export users, groups, computers and OUs; Run PingCastle for a scored health and risk snapshot; Export every group policy object and its linked scope; Collect trust, delegation and password policy settings. Hands over Directory Evidence Export. Phase 3, Attack-Path Analysis. We map privilege escalation routes with BloodHound and PowerView, identifying the shortest paths from ordinary users to domain admin. Activities: Map privileged group membership with BloodHound; Trace shortest paths from standard users to domain admin; Query ACL abuse routes such as GenericAll and WriteDACL; Identify Kerberoastable and AS-REP roastable accounts; Check certificate services templates for escalation paths. Hands over Attack-Path Map to Domain Admin. Phase 4, Manual Review of Risky Settings. We review domain controller hardening, Kerberos delegation, privileged group sprawl, stale accounts and legacy protocols that automated scoring can understate. Activities: Review unconstrained and constrained delegation on accounts; Check SMB signing, LDAP signing and NTLM usage on controllers; List stale accounts, dormant admins and never-expiring passwords; Assess tiering, LAPS coverage and admin workstation practice. Hands over AD Hardening Scorecard. Phase 5, Prioritised Findings. Findings are ranked by how directly they lead to compromise, with the affected objects listed so remediation is targeted. Activities: Rank findings by how directly they reach domain admin; List the affected accounts, groups and objects per finding; Separate quick wins from structural tiering work; Brief the identity team on the top escalation paths. Hands over Active Directory Findings Report. Phase 6, Remediation and Re-Check. We provide a fix order that closes the highest-value paths first, then re-run PingCastle and BloodHound to confirm the paths are gone. Activities: Set a fix order that breaks the shortest paths first; Give step-by-step guidance for each delegation and ACL change; Advise on rollout risk for protocol hardening changes; Re-run PingCastle and BloodHound to confirm paths are closed. Hands over Prioritised Remediation Runbook and Re-Check Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Baseline Selection

We agree the forests and domains in scope and select the CIS Microsoft Windows Server and Active Directory hardening baselines to measure against.

What Happens In This Phase

  • Map the forest, domains and trusts in scope
  • Count domain controllers and their OS versions
  • Select the CIS Windows Server and AD hardening baselines
  • Provision a read-only domain account for collection

The Handover

AD Scope and Baseline Agreement

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Baseline Selection

    We agree the forests and domains in scope and select the CIS Microsoft Windows Server and Active Directory hardening baselines to measure against.

    OutputAD Scope and Baseline Agreement

    Activities

    • Map the forest, domains and trusts in scope
    • Count domain controllers and their OS versions
    • Select the CIS Windows Server and AD hardening baselines
    • Provision a read-only domain account for collection
  2. 02

    Evidence and Config Collection

    Using read-only domain access we collect AD objects, group policy, trust and delegation data with ADRecon and PingCastle exports.

    OutputDirectory Evidence Export

    Activities

    • Run ADRecon to export users, groups, computers and OUs
    • Run PingCastle for a scored health and risk snapshot
    • Export every group policy object and its linked scope
    • Collect trust, delegation and password policy settings
  3. 03

    Attack-Path Analysis

    We map privilege escalation routes with BloodHound and PowerView, identifying the shortest paths from ordinary users to domain admin.

    OutputAttack-Path Map to Domain Admin

    Activities

    • Map privileged group membership with BloodHound
    • Trace shortest paths from standard users to domain admin
    • Query ACL abuse routes such as GenericAll and WriteDACL
    • Identify Kerberoastable and AS-REP roastable accounts
    • Check certificate services templates for escalation paths
  4. 04

    Manual Review of Risky Settings

    We review domain controller hardening, Kerberos delegation, privileged group sprawl, stale accounts and legacy protocols that automated scoring can understate.

    OutputAD Hardening Scorecard

    Activities

    • Review unconstrained and constrained delegation on accounts
    • Check SMB signing, LDAP signing and NTLM usage on controllers
    • List stale accounts, dormant admins and never-expiring passwords
    • Assess tiering, LAPS coverage and admin workstation practice
  5. 05

    Prioritised Findings

    Findings are ranked by how directly they lead to compromise, with the affected objects listed so remediation is targeted.

    OutputActive Directory Findings Report

    Activities

    • Rank findings by how directly they reach domain admin
    • List the affected accounts, groups and objects per finding
    • Separate quick wins from structural tiering work
    • Brief the identity team on the top escalation paths
  6. 06

    Remediation and Re-Check

    We provide a fix order that closes the highest-value paths first, then re-run PingCastle and BloodHound to confirm the paths are gone.

    OutputPrioritised Remediation Runbook and Re-Check Report

    Activities

    • Set a fix order that breaks the shortest paths first
    • Give step-by-step guidance for each delegation and ACL change
    • Advise on rollout risk for protocol hardening changes
    • Re-run PingCastle and BloodHound to confirm paths are closed

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Active Directory and Domain Controller Audit scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: BloodHound, PingCastle, PowerView, PurpleKnight, ADRecon, Microsoft Security Compliance Toolkit, Group Policy analysis, CIS-CAT Pro. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: CIS Microsoft Windows Server Benchmarks, CIS Microsoft Active Directory hardening references, DISA Active Directory and Windows Server STIGs, Microsoft security baselines, NIST SP 800-53, MITRE ATT&CK (Credential Access, Privilege Escalation).

What We Run

8 tools

  • BloodHound
  • PingCastle
  • PowerView
  • PurpleKnight
  • ADRecon
  • Microsoft Security Compliance Toolkit
  • Group Policy analysis
  • CIS-CAT Pro

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

6 standards

  • CISMicrosoft Windows Server
  • CISMicrosoft Active DirectoryHardening
  • DISASTIGsActive Directory
  • MSMicrosoftSecurity Baselines
  • NIST SP 800-53
  • MITRE ATT&CK (Credential Access, Privilege Escalation)
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Active Directory findings report
  • Attack-path map to domain admin
  • AD hardening scorecard
  • Prioritised remediation runbook
  • Re-check report after remediation

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Which attack paths do you actually examine, and how do you decide which ones to report first?

We examine the routes that lead from an ordinary domain account to domain admin, and we rank them by how short and how reliable they are. In practice that means four recurring families. Privileged group sprawl, where membership of built-in administrative groups has grown through years of exceptions and was never trimmed back. Delegation, both unconstrained and constrained, left configured on accounts and computers that no longer need it. Kerberos weaknesses, including service accounts whose tickets can be requested and cracked offline, and accounts that do not require pre-authentication. Stale objects: dormant admins, never-expiring passwords and computer accounts for machines that were decommissioned. We also review certificate template permissions, because those can turn a standard user into a domain administrator in a single step. Findings are then ranked by how directly they reach domain admin, with the affected accounts, groups and objects listed, so your remediation is targeted rather than general.

Is the collection genuinely read-only, and what risk does running it carry on a production domain?

Yes. We read directory objects, group policy, trust and delegation data, and we write nothing back; nothing in this audit changes your directory. The account you provision for us needs no administrative rights, only the ability to read the objects we enumerate, and we ask you to create it for the engagement so you can disable it the day we finish. The honest risk is load, not change. Enumerating a large forest generates a lot of queries against domain controllers, and session-collection passes touch many machines in a short window, so we agree the timing of the heavier queries with you and run them when your operations team says it suits. If your monitoring alerts on directory enumeration, tell us during scoping. A defensive team noticing our collection and escalating it is a good outcome, and it is better discovered deliberately than during a real intrusion.

What does remediation actually require from us, and why is tiering the part that takes longest?

Findings split into two piles, and only one of them is quick. The quick pile is object-level: removing accounts from privileged groups, clearing delegation flags nobody needs any more, retiring dormant admin accounts, tightening a certificate template, correcting password policy settings. Your identity team can work through that from the remediation runbook, which gives step-by-step guidance for each delegation and ACL change and an order that breaks the shortest paths first. The slow pile is structural. Administrative tiering separates the accounts that administer domain controllers from those that administer servers and workstations, so it changes how your administrators log in every day and reaches into joiner-mover-leaver process, privileged access workstations and local administrator password management. That is a project, not a change ticket. We separate the two piles explicitly, so you can close the shortest paths in weeks while planning the tiering work properly, then we re-check once your fixes land.

Does this cover Entra ID and hybrid identity, or only on-premises Active Directory?

This audit is scoped to on-premises Active Directory and the domain controllers behind it. Entra ID and hybrid identity can be added, but as a separate scope agreed during scoping, not as an assumed extra. We say so plainly because the two estates fail differently. On premises, the question is who can reach domain admin through group membership, delegation and access control lists. In Entra ID it is directory role assignment, application consent, service principal credentials and conditional access gaps, and none of those appear in an on-premises collection. The bridge between them is the synchronisation infrastructure, which is where a hybrid estate gets interesting, because the synchronisation service account holds standing privilege on both sides. So raise hybrid identity on the scoping call. We will tell you whether the on-premises audit alone answers the question you are asking, or whether the cloud side belongs in the same engagement.

How is this different from an internal network penetration test, and which should we run first?

This audit reads your directory configuration exhaustively; an internal network penetration test attacks it selectively. The difference is coverage against proof. Here we enumerate privileged groups, delegation settings, trusts and stale objects across the forests in scope, measure domain controller hardening against the published Windows Server and Active Directory baselines named on this page, and hand you the map of escalation routes, including ones no attacker would bother with because a shorter path exists. Our Network Infrastructure penetration test does the opposite: it starts from a foothold and demonstrates the path an attacker takes, with proof of concept for every finding, which is more persuasive and less complete as an inventory. If your goal is to fix Active Directory, start with this audit, because it tells you what to change. If your goal is to prove the risk to people who have not funded the fix, the penetration test makes that case.