Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Hardening and Configuration Review5 services in this practice area

Close the Paths to Domain Admin

Active Directory and Domain Controller Audit

We audit your Active Directory forest and domain controllers for the misconfigurations attackers use to escalate. You get the attack paths mapped, the risky settings ranked, and a clear order to fix them.

See the engagement path, 6 phasesSee the full Hardening and Configuration Review service index

Overview

Active Directory is the backbone of most enterprise networks, which makes it the prize attackers aim for. Years of delegation, stale accounts and legacy protocols leave paths that lead straight to domain admin. This audit maps those paths, reviews domain controller hardening, and checks the settings that matter most: privileged group membership, Kerberos configuration, delegation, and password policy. We show you the shortest routes an attacker would take and how to cut them.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the Active Directory and Domain Controller Audit engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Baseline Selection. We agree the forests and domains in scope and select the CIS Microsoft Windows Server and Active Directory hardening baselines to measure against. Activities: Map the forest, domains and trusts in scope; Count domain controllers and their OS versions; Select the CIS Windows Server and AD hardening baselines; Provision a read-only domain account for collection. Hands over AD Scope and Baseline Agreement. Phase 2, Evidence and Config Collection. Using read-only domain access we collect AD objects, group policy, trust and delegation data with ADRecon and PingCastle exports. Activities: Run ADRecon to export users, groups, computers and OUs; Run PingCastle for a scored health and risk snapshot; Export every group policy object and its linked scope; Collect trust, delegation and password policy settings. Hands over Directory Evidence Export. Phase 3, Attack-Path Analysis. We map privilege escalation routes with BloodHound and PowerView, identifying the shortest paths from ordinary users to domain admin. Activities: Map privileged group membership with BloodHound; Trace shortest paths from standard users to domain admin; Query ACL abuse routes such as GenericAll and WriteDACL; Identify Kerberoastable and AS-REP roastable accounts; Check certificate services templates for escalation paths. Hands over Attack-Path Map to Domain Admin. Phase 4, Manual Review of Risky Settings. We review domain controller hardening, Kerberos delegation, privileged group sprawl, stale accounts and legacy protocols that automated scoring can understate. Activities: Review unconstrained and constrained delegation on accounts; Check SMB signing, LDAP signing and NTLM usage on controllers; List stale accounts, dormant admins and never-expiring passwords; Assess tiering, LAPS coverage and admin workstation practice. Hands over AD Hardening Scorecard. Phase 5, Prioritised Findings. Findings are ranked by how directly they lead to compromise, with the affected objects listed so remediation is targeted. Activities: Rank findings by how directly they reach domain admin; List the affected accounts, groups and objects per finding; Separate quick wins from structural tiering work; Brief the identity team on the top escalation paths. Hands over Active Directory Findings Report. Phase 6, Remediation and Re-Check. We provide a fix order that closes the highest-value paths first, then re-run PingCastle and BloodHound to confirm the paths are gone. Activities: Set a fix order that breaks the shortest paths first; Give step-by-step guidance for each delegation and ACL change; Advise on rollout risk for protocol hardening changes; Re-run PingCastle and BloodHound to confirm paths are closed. Hands over Prioritised Remediation Runbook and Re-Check Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Baseline Selection

We agree the forests and domains in scope and select the CIS Microsoft Windows Server and Active Directory hardening baselines to measure against.

What Happens In This Phase

  • Map the forest, domains and trusts in scope
  • Count domain controllers and their OS versions
  • Select the CIS Windows Server and AD hardening baselines
  • Provision a read-only domain account for collection

The Handover

AD Scope and Baseline Agreement

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Baseline Selection

    We agree the forests and domains in scope and select the CIS Microsoft Windows Server and Active Directory hardening baselines to measure against.

    OutputAD Scope and Baseline Agreement

    Activities

    • Map the forest, domains and trusts in scope
    • Count domain controllers and their OS versions
    • Select the CIS Windows Server and AD hardening baselines
    • Provision a read-only domain account for collection
  2. 02

    Evidence and Config Collection

    Using read-only domain access we collect AD objects, group policy, trust and delegation data with ADRecon and PingCastle exports.

    OutputDirectory Evidence Export

    Activities

    • Run ADRecon to export users, groups, computers and OUs
    • Run PingCastle for a scored health and risk snapshot
    • Export every group policy object and its linked scope
    • Collect trust, delegation and password policy settings
  3. 03

    Attack-Path Analysis

    We map privilege escalation routes with BloodHound and PowerView, identifying the shortest paths from ordinary users to domain admin.

    OutputAttack-Path Map to Domain Admin

    Activities

    • Map privileged group membership with BloodHound
    • Trace shortest paths from standard users to domain admin
    • Query ACL abuse routes such as GenericAll and WriteDACL
    • Identify Kerberoastable and AS-REP roastable accounts
    • Check certificate services templates for escalation paths
  4. 04

    Manual Review of Risky Settings

    We review domain controller hardening, Kerberos delegation, privileged group sprawl, stale accounts and legacy protocols that automated scoring can understate.

    OutputAD Hardening Scorecard

    Activities

    • Review unconstrained and constrained delegation on accounts
    • Check SMB signing, LDAP signing and NTLM usage on controllers
    • List stale accounts, dormant admins and never-expiring passwords
    • Assess tiering, LAPS coverage and admin workstation practice
  5. 05

    Prioritised Findings

    Findings are ranked by how directly they lead to compromise, with the affected objects listed so remediation is targeted.

    OutputActive Directory Findings Report

    Activities

    • Rank findings by how directly they reach domain admin
    • List the affected accounts, groups and objects per finding
    • Separate quick wins from structural tiering work
    • Brief the identity team on the top escalation paths
  6. 06

    Remediation and Re-Check

    We provide a fix order that closes the highest-value paths first, then re-run PingCastle and BloodHound to confirm the paths are gone.

    OutputPrioritised Remediation Runbook and Re-Check Report

    Activities

    • Set a fix order that breaks the shortest paths first
    • Give step-by-step guidance for each delegation and ACL change
    • Advise on rollout risk for protocol hardening changes
    • Re-run PingCastle and BloodHound to confirm paths are closed

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Active Directory and Domain Controller Audit scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: BloodHound, PingCastle, PowerView, PurpleKnight, ADRecon, Microsoft Security Compliance Toolkit, Group Policy analysis, CIS-CAT Pro. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: CIS Microsoft Windows Server Benchmarks, CIS Microsoft Active Directory hardening references, DISA Active Directory and Windows Server STIGs, Microsoft security baselines, NIST SP 800-53, MITRE ATT&CK (Credential Access, Privilege Escalation).

What We Run

8 tools

  • BloodHound
  • PingCastle
  • PowerView
  • PurpleKnight
  • ADRecon
  • Microsoft Security Compliance Toolkit
  • Group Policy analysis
  • CIS-CAT Pro

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

6 standards

  • CISMicrosoft Windows Server
  • CISMicrosoft Active DirectoryHardening
  • DISASTIGsActive Directory
  • MSMicrosoftSecurity Baselines
  • NIST SP 800-53
  • MITRE ATT&CK (Credential Access, Privilege Escalation)
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Active Directory findings report
  • Attack-path map to domain admin
  • AD hardening scorecard
  • Prioritised remediation runbook
  • Re-check report after remediation

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Is running these tools safe in production?

Yes. We use read-only collection and schedule any heavier queries with you. Nothing changes your directory; we only read and analyse.

What is an attack path?

It is the chain of memberships, permissions and delegations that lets an ordinary account reach domain admin. We map the shortest ones so you can break them.

Do you cover Entra ID as well?

This audit focuses on on-premises Active Directory and domain controllers. We can extend to Entra ID and hybrid identity as a separate scope.