First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Active Directory Security Assessment and Hardening
AssessmentSecurity and Protection

Active Directory Security Assessment and Hardening

A fixed-fee, 2-week security assessment of your on-premises Active Directory against the attack paths that actually get domains compromised: privileged group sprawl, dangerous delegation, legacy authentication protocols, Kerberos hygiene including the age of your krbtgt password, Group Policy exposure, certificate services misconfigurations, and trust posture. You receive a scored findings report with severity and exploitability per finding, a prioritized hardening roadmap, an admin-tiering plan, and a set of agreed low-risk quick wins implemented during the engagement. This is an engineering assessment, not a certified penetration test — we say that plainly because the difference matters. $3,950 per project, fixed.

Timeline 2 weeksService owner Dan ApplebyActive DirectoryWindows ServerMicrosoft Entra ID

What this engagement is

Most ransomware incidents in hybrid organizations still run through on-premises Active Directory, because that is where twenty years of accumulated configuration debt lives: a Domain Admins group that grew one 'temporary' member at a time, service accounts with servicePrincipalNames and passwords set in 2013, unconstrained delegation nobody remembers enabling, NTLMv1 still answered because one appliance might need it, and a krbtgt password older than some of your employees. Attackers do not need zero-days for any of this — the paths are documented, the tooling is public, and the same handful of misconfigurations shows up in breach reports year after year. This assessment finds those paths in your domain before someone else does. The review covers the ground that real attacks cross: privileged group membership and the shadow-admin problem (accounts with rights equivalent to Domain Admin through nesting, ACLs, or AdminSDHolder drift); delegation in all three flavors — unconstrained, constrained, and resource-based; Kerberos exposure including kerberoastable service accounts, AS-REP roasting candidates, and krbtgt password age; legacy protocol posture — NTLM versions, SMBv1, LDAP signing and channel binding, and where each is actually still used versus merely still allowed; Group Policy hygiene including permissions, legacy credential artifacts in SYSVOL, and settings that undermine the rest; Active Directory Certificate Services misconfigurations of the kind that quietly grant domain escalation; trust relationships and SID filtering; password and lockout policy reality; and stale-object accumulation across users, computers, and admin accounts. Every finding is scored for severity and exploitability, in your context — a risk that requires Domain Admin to exploit is not the same as one reachable from any workstation, and the report says which is which. You get more than a list of problems. The hardening roadmap sequences fixes by risk reduced per unit of disruption, the admin-tiering roadmap gives you a realistic, staged path toward separating Tier 0 from everything else instead of an all-or-nothing model nobody implements, and a short list of agreed low-risk quick wins gets implemented during the engagement itself — you end the two weeks measurably harder, not just better informed. Deeper remediation is deliberately out of scope and separately quoted, most naturally through our on-premises hardening service; ongoing attack detection belongs to Microsoft Defender for Identity; and if your strategic direction is fewer domain controllers rather than harder ones, the honest endgame is a planned transition from on-premises AD to Microsoft Entra ID.

Success criteria

01Every assessed area — privileged access, delegation, Kerberos hygiene, legacy protocols, GPO, AD CS, trusts, stale objects — has documented findings or a documented clean bill, with evidence.
02Each finding carries a severity and exploitability rating with the reasoning stated, not just a color.
03The hardening roadmap sequences remediation by risk reduced versus operational disruption, with owner and effort noted per item.
04The admin-tiering roadmap gives a staged, achievable path appropriate to your team's size — not a copy-paste enterprise model.
05The agreed quick wins are implemented, verified, and documented before the engagement closes.
06Leadership has heard the readout and understands the top risks in plain language, including what a realistic attacker would do first.
07Your team knows exactly which items they can fix themselves, which need scoping, and in what order.

What you receive

Scored findings report — every finding with evidence, severity, exploitability, and the attack path it enables, written so both an engineer and an executive can use it.
Privileged access review — effective membership of privileged groups including nesting, shadow-admin paths through ACLs and AdminSDHolder, stale and shared admin accounts, and DCSync-capable principals.
Delegation review — unconstrained, constrained, and resource-based constrained delegation, each instance dispositioned as required, removable, or restrictable.
Kerberos hygiene review — kerberoastable service accounts and password ages, AS-REP roasting exposure, krbtgt password age with a safe double-reset procedure documented.
Legacy protocol assessment — NTLM version posture, SMBv1, LDAP signing and channel binding, with an evidence-based view of what still genuinely uses each protocol.
Group Policy hygiene review — GPO permissions, legacy credential artifacts in SYSVOL, conflicting or obsolete policies, and settings that weaken the security baseline.
Active Directory Certificate Services review (where AD CS is present) — template and permission misconfigurations of the classes known to enable escalation.
Trust and forest posture review — external and forest trusts, SID filtering state, and the machine-account quota default that most domains never changed.
Admin-tiering roadmap — a staged plan toward tiered administration sized to your organization, with the first stage concrete enough to start the following week.
Implemented quick wins — a short, agreed set of low-risk fixes executed with your change process during the engagement, each documented with before/after state.
Executive readout — one session for leadership, one working session for the technical team.

How the work unfolds

1. Scoping and access

Agree the domains and forests in scope, the quick-win ground rules, and the change-control process. Access is time-bound and least-privilege: assessment collection runs read-oriented, and anything requiring elevation is agreed explicitly.

2. Collection and analysis

Configuration, ACL, and object data is collected from the in-scope domains and analyzed against known attack paths — privilege escalation routes, delegation abuse, roastable accounts, protocol downgrade exposure, GPO and AD CS weaknesses. Findings are verified rather than raw-tool-dumped: every reported item has been looked at by an engineer.

3. Findings, roadmap, and tiering plan

Findings are scored and written up, the hardening roadmap is sequenced with your operational constraints in mind, and the admin-tiering roadmap is drafted at a stage-by-stage level your team can actually execute.

4. Quick wins and readout

The agreed low-risk fixes are implemented through your change process and verified. The engagement closes with the executive readout and a technical working session that turns the roadmap into an ordered to-do list with owners.

Prerequisites

An on-premises or hybrid Active Directory environment — one forest and domain in the base scope; additional domains or forests are agreed at scoping.
Approved access for assessment collection — read-oriented, time-bound accounts that you create and disable afterward; we never ask for standing Domain Admin.
A change-control path and a named approver for the quick-win fixes.
Availability of whoever knows the history: an engineer who can answer 'is this delegation still needed?' makes the dispositions faster and better.
Network access to a domain-joined collection point (VM is fine) or a supervised remote session, per your security policy.
Any recent pen-test or insurer findings you want the assessment to address — we map our findings to theirs where they overlap.

Who does what

IT Partner

  • Collect and analyze the in-scope AD configuration against known attack paths, with an engineer verifying every reported finding.
  • Produce the scored findings report, hardening roadmap, and admin-tiering roadmap.
  • Implement the agreed quick wins through your change process and document before/after state.
  • Deliver the executive readout and the technical working session.
  • Recommend remediation paths honestly, including items your team can fix without us.

Your team

  • Provide scoped, time-bound access and disable it after the engagement.
  • Make the environment historian and change approver available during the two weeks.
  • Approve the quick-win list before anything is changed — nothing is modified without sign-off.
  • Own remediation decisions and scheduling beyond the included quick wins.
  • Own the risk-acceptance decision for any finding you choose not to fix — documented is not the same as fixed, and the report will say so.

What's not included

Penetration testing — no exploitation, no payloads, no red-team activity, and no certified pen-test report. If a compliance framework, customer contract, or insurer requires a penetration test by an accredited testing firm, this assessment does not satisfy that requirement, and we will say so before you book rather than after.
Remediation beyond the agreed quick wins — the roadmap prices out into follow-on work, whether by your team or through our separately quoted on-premises hardening service; large items such as a full tiering implementation or a domain controller migration are their own projects.
Ongoing monitoring and attack detection — that is a product-plus-operations question; Microsoft Defender for Identity is the natural next step and is scoped separately.
Microsoft Entra ID, Microsoft 365, and cloud security posture — this engagement is deliberately about the on-premises directory; tenant-side assessment is covered by our Microsoft 365 security services.
Non-AD infrastructure — network devices, hypervisors, backup platforms, and application servers appear only where they intersect an AD attack path (a domain-joined backup server with Domain Admin credentials cached is in; your firewall ruleset is not).
Incident response — if we find evidence of active compromise, we stop, tell you immediately, and help you engage the right response process; turning an assessment into a quiet IR engagement serves nobody.
Compliance certification or attestation of any kind.

Limitations & technical notes

!This is an engineering assessment against known Active Directory attack paths, not a certified penetration test — no exploitation is performed, and findings state what an attacker could do, verified by configuration analysis rather than by doing it. Organizations needing an accredited pen test for compliance should commission one; this assessment pairs well with pen tests (before one, to fix the obvious; after one, to turn findings into an ordered plan) but replaces neither.
!Quick wins are deliberately conservative: low-risk, reversible, change-controlled fixes agreed with you — typical candidates include disabling long-dead accounts, removing clearly obsolete privileged group members, and correcting unambiguous misconfigurations. Anything with meaningful breakage potential — protocol disablement, delegation removal under uncertainty, tiering enforcement — goes on the roadmap, not into week two.
!Findings reflect the environment during the assessment window. Directories drift; an annual re-assessment, or one after major changes (mergers, migrations, new admin staff), is the honest cadence.
!The assessment sees what the collected data shows. Deliberately hidden persistence from a prior compromise is an incident-response problem, and while several findings classes do surface common persistence techniques, absence of findings is not a forensic clean bill.
!Fixing legacy protocol findings is often gated on discovering what still uses them — the report gives you the evidence-based usage view, but a device that authenticates once a quarter can hide from a two-week window. The roadmap accounts for that with audit-before-disable sequencing.
!The base scope is one forest and domain of typical SMB/mid-market size; multi-forest estates or unusually large domains are agreed (and where needed, re-quoted in writing) at scoping — before work begins, per our fixed-price terms.

Frequently asked questions

Is this a penetration test?

No, and we put that in writing because the distinction has teeth. A penetration test exploits weaknesses to demonstrate impact and often carries accreditation requirements (for compliance frameworks or insurers). This assessment analyzes your directory's configuration against the same attack paths a competent attacker would use — without exploitation — and tells you what to fix in what order. If your obligation says 'penetration test by a certified firm', commission exactly that; many clients run this assessment first so the pen test they pay for finds interesting things instead of a stale krbtgt password.

What does the $3,950 include, exactly?

The full assessment of one forest and domain across all the listed areas, the scored findings report, the prioritized hardening roadmap, the admin-tiering roadmap, the agreed quick-win fixes implemented during the engagement, and both readout sessions — executive and technical. Fixed price, quoted in writing before we start; you pay after you approve delivery. Multi-domain or multi-forest scopes are agreed and priced at scoping, not discovered in week two.

Why does the age of the krbtgt password matter?

The krbtgt account's password signs every Kerberos ticket in the domain. If it has not been rotated in years — common, because rotation is scary without a procedure — then anyone who ever extracted its hash can mint golden tickets that impersonate any user, indefinitely, surviving every other password reset you do. The assessment reports its age and hands you Microsoft's supported double-reset procedure with the timing caveats, so rotation becomes routine hygiene instead of folklore.

What is admin tiering and why do you deliver a roadmap instead of implementing it?

Tiering separates control of the directory itself (Tier 0: domain controllers, privileged accounts, and everything that can reach them) from server and workstation administration, so a phished helpdesk account can no longer become Domain Admin by lunchtime. Full enforcement touches accounts, workstations, policies, and habits — it is weeks of change management, not an afternoon, and pretending it fits inside an assessment would shortchange both. You get a staged roadmap sized to your team, with stage one concrete enough to start immediately; implementation is separately scoped if you want our hands on it.

Will the assessment break anything?

The assessment itself is read-oriented collection and analysis — it changes nothing. The only changes made during the engagement are the quick wins, and those are: agreed with you item by item beforehand, low-risk and reversible by design, and executed through your change process with before/after state documented. Anything with real breakage potential is explicitly routed to the roadmap instead.

What access do you need?

Time-bound, least-privilege access that you create and you disable afterward — the same discipline we publish for our Microsoft 365 engagements. Collection runs with read-oriented rights; certain checks that need elevation are agreed explicitly and individually. We never ask for standing Domain Admin, and if a provider assessing your directory does, that is itself a finding.

We just failed items on a pen test or an insurer questionnaire. Is this the right response?

Often, yes — third-party findings tell you that a problem exists; this assessment tells you why, what else sits in the same category, and in what order to fix it all without breaking authentication for a plant floor at 2 a.m. Bring the report: we map our findings to theirs, close the overlap, and give your insurer or auditor a documented remediation plan, which is frequently what they actually wanted.

Our AD is 'legacy' — we plan to go cloud-only eventually. Why harden it now?

Because 'eventually' is the attacker's favorite word. As long as domain controllers authenticate your users, AD is your security foundation, and a compromised domain also compromises everything it syncs to — including your Microsoft 365 tenant via the identities it masters. Harden what you run today; and if cloud-only is the genuine direction, we will say so in the readout and point you at a planned Entra ID transition rather than selling you hardening forever.

What are 'known attack paths' — what do you actually check?

The documented, repeatedly-breached routes: privilege escalation through group nesting and ACLs, DCSync rights outside domain controllers, kerberoastable service accounts, AS-REP roasting, unconstrained and resource-based delegation abuse, NTLM relay exposure via missing signing and channel binding, credential artifacts in SYSVOL, exploitable AD CS template configurations, stale privileged accounts, machine-account quota abuse, and trust misconfigurations, among others. The methodology is attack-path-first: we report what an adversary could chain together in your domain, not an alphabetical list of settings that differ from a benchmark.

Do you use automated tools or is this manual?

Both, in the only order that works: tooling collects and correlates at a scale no human can, then an engineer verifies, contextualizes, and scores every finding that makes the report. What you will not get is a raw tool export with a cover page — a finding only appears if a person confirmed it is real in your environment and understood what it enables.

What happens if you find evidence of an active compromise?

We stop assessing, tell you immediately through the agreed contact, and help you engage a proper incident-response process — preserving evidence rather than trampling it. An assessment quietly upgraded into incident response serves neither purpose well, and you deserve to know the moment the engagement changes character.

How is this different from your on-premises security hardening service?

Sequence and product. This is the fixed-fee assessment: two weeks, a scored report, a roadmap, a tiering plan, and the agreed quick wins — you know exactly what it costs and what you get. The hardening service is the remediation arm: hourly engineering that executes roadmap items across your broader on-premises environment. Assessment first is the honest order; buying remediation hours before anyone has scored the risks is how budgets get spent on the wrong fixes.

How often should this be repeated?

Annually as a baseline, and after anything that reshapes the directory: a merger or acquisition, a domain migration, major delegation changes, or turnover in privileged staff. Directories drift toward entropy — group memberships grow, exceptions outlive their reasons — and the second assessment is typically faster and cheaper to act on because the roadmap infrastructure already exists.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$3,950 per project
2 weeks
Book the AD assessment