Montréal · Remote delivery · FR / EN

Active Directory security assessment
Privileges and attack paths.

Identify configurations and access that could facilitate domain compromise. A technical review designed to prioritize hardening while accounting for your applications and legacy dependencies.

01 — Why assess?

Which gaps could expose your domain to compromise?

For businesses and IT teams that need an actionable picture, not another report sitting in a document pile.

02 — Technical scope

What gets reviewed.

Checks are tailored to the components present and agreed scope. Exclusions and visibility limitations are documented.

01

Privileges and delegation

Review sensitive groups, nested memberships, delegated permissions and separation of administrative accounts. Potential access paths are evaluated in the context of the resources and identities involved.

02

Accounts and passwords

Analyze stale accounts, service accounts, password policies and opportunities for gMSA use. Review Windows LAPS and associated read permissions where deployed.

03

Kerberos and legacy protocols

Examine RC4, NTLM, LDAP and SMB dependencies using available configurations and logs. Recommendations include compatibility auditing before any change that could interrupt a service.

04

GPOs and domain controllers

Perform a targeted review of security settings, domain controller administration, exposure and operational hygiene. The scope does not replace an exhaustive assessment of every server or application.

05

AD CS and certificates

Where AD CS is present, examine agreed templates, permissions and enrolment endpoints. Identify configurations that may contribute to attack paths, without active exploitation by default.

06

Detection and recovery readiness

Review Defender for Identity coverage where available, logging and domain recovery procedures. An actual restore or compromise exercise requires a separately defined scope.

Defender for Identity and third-party tools are not universal prerequisites. Collection methods, licensing and usage terms are confirmed during scoping. The report identifies checks not performed because of missing data, access or capabilities.

03 — Method

Validated findings.
Practical priorities.

A tool export is not enough. PingCastle, Purple Knight or PowerShell collection results may inform the review, depending on scope and usage terms. False positives, application dependencies and remediation effort are examined to produce a plan your team can act on.

  1. 01

    Scoping

    Confirm objectives, included components, exclusions, access, constraints and scheduling before collecting any data.

  2. 02

    Controlled collection

    Collect agreed configurations and evidence with temporary, read-only access where possible. Validate tooling and collection windows with your team.

  3. 03

    Analysis and prioritization

    Cross-check results, document limitations and rank findings by impact, exposure, dependencies and remediation effort.

  4. 04

    Readout and next steps

    Present results to IT owners and decision-makers. Define actions, proposed owners and validation criteria.

04 — Deliverables

What you receive.

A report you can act on and a conversation to make it useful. The roadmap proposes sequencing; it does not promise complete remediation within 90 days.

01

Executive summary

A clear summary of priority risks, assessment limitations and decisions to make.

02

Technical report

Findings with relevant evidence, impact, recommendations and validation criteria. Checks not performed are identified.

03

Remediation roadmap

A sequence aligned with your capacity: immediate actions, pilots and work to organize over 30, 60 and 90 days.

04

Findings workshop

A discussion to understand results, review dependencies and agree on next steps.

05 — Sample deliverable

A finding, from evidence to action.

Entirely fictional, illustrative example. It describes no client, real incident or guaranteed outcome.

A service account in Domain Admins without a demonstrated need

Evidence to validate
In this fictional example, an application account belongs to Domain Admins even though its documented requirement is limited to an application resource. Ownership and dependencies still need confirmation.
Potential impact
Compromising this account could grant domain privileges far beyond the relevant service. Immediately removing its membership could nevertheless interrupt the application if dependencies are poorly understood.
Recommendation
Identify the owner, inventory tasks and services using the account and define minimum delegation. Pilot reduced permissions; consider a gMSA only if the application supports it.
Post-remediation validation
Confirm service functionality, effective memberships and access events after the change. Document residual permissions, ownership and the planned rollback.

06 — Access and confidentiality

Collect what matters.
Respect your operations.

Prepare forest, domain and domain controller counts, key applications, AD CS presence and security tooling. Collection can run from an authorized workstation, either by your team or using agreed temporary access.

Access is individually attributable where possible, limited to the engagement and revoked at closure. Privilege exceptions are justified before use.

Transfer, storage, retention and deletion of exports are agreed before collection. A confidentiality agreement can govern exchanges.

Collection does not include production changes or active exploitation by default. Intrusive actions or remediation require separate authorization.

07 — FAQ

Before we begin.

Do we need to provide a Domain Admin account?

Not as a universal prerequisite. Privileges depend on the agreed collection method. Checks requiring elevation are explained and can be executed by your team without permanently sharing a privileged account.

Is this simply a PingCastle report?

No. A tool can surface signals, but the engagement includes validation, dependency analysis, prioritization and a readout. An isolated score demonstrates neither an absence of risk nor exploitability of every finding.

Will legacy systems be disabled?

Collection does not include disabling systems or changing GPOs by default. Identified dependencies inform a proposed pilot, compensating controls and remediation sequence for your team to validate.

Can you assess AD CS and hybrid identity?

Yes, when explicitly scoped. AD CS is reviewed according to the components present; detailed tenant and cloud policy analysis belongs to the Microsoft 365 assessment. Both scopes can be coordinated.

Can the engagement be remote, and how long does it take?

Work can be performed remotely when access and your organization's policies allow it. Timing is agreed after scoping, based on size, complexity and availability of data and stakeholders; no universal turnaround is promised.

Are fixes included?

The assessment provides findings and a roadmap. Implementation, pilots and post-remediation validation can be scoped as separate support. No production changes are made without explicit authorization.

Is this a penetration test or certification?

No. This is a point-in-time posture and configuration assessment, not a guarantee that no compromise exists. Active exploitation, incident response and compliance attestation are not included by default.

08 — Explore further

The topics, in practice.

These technical guides illustrate my approach. They do not replace a review of your environment.

Guides for this serviceSecure Active Directory Certificate Services: detect ESC1, ESC4, ESC6 and ESC8Stale MDE devices: cleanup with PowerShell and the APIMigrate Microsoft Defender for Identity to v3.x sensors: a practical guideSMB hardening with Windows 11 24H2 and Windows Server 2025: a deployment guideKerberos and RC4 in 2026: audit Active Directory and migrate to AES without outagesActive Directory security assessment: 10 checks to prioritize

Next step

Let's define a useful scope.

Briefly describe your environment and what prompted the assessment. Do not send passwords, sensitive exports or confidential data through the form.

Request a conversation