Active Directory Security Assessment and Hardening
A fixed-fee, 2-week security assessment of your on-premises Active Directory against the attack paths that actually get domains compromised: privileged group sprawl, dangerous delegation, legacy authentication protocols, Kerberos hygiene including the age of your krbtgt password, Group Policy exposure, certificate services misconfigurations, and trust posture. You receive a scored findings report with severity and exploitability per finding, a prioritized hardening roadmap, an admin-tiering plan, and a set of agreed low-risk quick wins implemented during the engagement. This is an engineering assessment, not a certified penetration test — we say that plainly because the difference matters. $3,950 per project, fixed.
What this engagement is
Most ransomware incidents in hybrid organizations still run through on-premises Active Directory, because that is where twenty years of accumulated configuration debt lives: a Domain Admins group that grew one 'temporary' member at a time, service accounts with servicePrincipalNames and passwords set in 2013, unconstrained delegation nobody remembers enabling, NTLMv1 still answered because one appliance might need it, and a krbtgt password older than some of your employees. Attackers do not need zero-days for any of this — the paths are documented, the tooling is public, and the same handful of misconfigurations shows up in breach reports year after year. This assessment finds those paths in your domain before someone else does. The review covers the ground that real attacks cross: privileged group membership and the shadow-admin problem (accounts with rights equivalent to Domain Admin through nesting, ACLs, or AdminSDHolder drift); delegation in all three flavors — unconstrained, constrained, and resource-based; Kerberos exposure including kerberoastable service accounts, AS-REP roasting candidates, and krbtgt password age; legacy protocol posture — NTLM versions, SMBv1, LDAP signing and channel binding, and where each is actually still used versus merely still allowed; Group Policy hygiene including permissions, legacy credential artifacts in SYSVOL, and settings that undermine the rest; Active Directory Certificate Services misconfigurations of the kind that quietly grant domain escalation; trust relationships and SID filtering; password and lockout policy reality; and stale-object accumulation across users, computers, and admin accounts. Every finding is scored for severity and exploitability, in your context — a risk that requires Domain Admin to exploit is not the same as one reachable from any workstation, and the report says which is which. You get more than a list of problems. The hardening roadmap sequences fixes by risk reduced per unit of disruption, the admin-tiering roadmap gives you a realistic, staged path toward separating Tier 0 from everything else instead of an all-or-nothing model nobody implements, and a short list of agreed low-risk quick wins gets implemented during the engagement itself — you end the two weeks measurably harder, not just better informed. Deeper remediation is deliberately out of scope and separately quoted, most naturally through our on-premises hardening service; ongoing attack detection belongs to Microsoft Defender for Identity; and if your strategic direction is fewer domain controllers rather than harder ones, the honest endgame is a planned transition from on-premises AD to Microsoft Entra ID.
Success criteria
What you receive
How the work unfolds
Agree the domains and forests in scope, the quick-win ground rules, and the change-control process. Access is time-bound and least-privilege: assessment collection runs read-oriented, and anything requiring elevation is agreed explicitly.
Configuration, ACL, and object data is collected from the in-scope domains and analyzed against known attack paths — privilege escalation routes, delegation abuse, roastable accounts, protocol downgrade exposure, GPO and AD CS weaknesses. Findings are verified rather than raw-tool-dumped: every reported item has been looked at by an engineer.
Findings are scored and written up, the hardening roadmap is sequenced with your operational constraints in mind, and the admin-tiering roadmap is drafted at a stage-by-stage level your team can actually execute.
The agreed low-risk fixes are implemented through your change process and verified. The engagement closes with the executive readout and a technical working session that turns the roadmap into an ordered to-do list with owners.
Prerequisites
Who does what
IT Partner
- Collect and analyze the in-scope AD configuration against known attack paths, with an engineer verifying every reported finding.
- Produce the scored findings report, hardening roadmap, and admin-tiering roadmap.
- Implement the agreed quick wins through your change process and document before/after state.
- Deliver the executive readout and the technical working session.
- Recommend remediation paths honestly, including items your team can fix without us.
Your team
- Provide scoped, time-bound access and disable it after the engagement.
- Make the environment historian and change approver available during the two weeks.
- Approve the quick-win list before anything is changed — nothing is modified without sign-off.
- Own remediation decisions and scheduling beyond the included quick wins.
- Own the risk-acceptance decision for any finding you choose not to fix — documented is not the same as fixed, and the report will say so.
What's not included
Limitations & technical notes
Frequently asked questions
Is this a penetration test?
No, and we put that in writing because the distinction has teeth. A penetration test exploits weaknesses to demonstrate impact and often carries accreditation requirements (for compliance frameworks or insurers). This assessment analyzes your directory's configuration against the same attack paths a competent attacker would use — without exploitation — and tells you what to fix in what order. If your obligation says 'penetration test by a certified firm', commission exactly that; many clients run this assessment first so the pen test they pay for finds interesting things instead of a stale krbtgt password.
What does the $3,950 include, exactly?
The full assessment of one forest and domain across all the listed areas, the scored findings report, the prioritized hardening roadmap, the admin-tiering roadmap, the agreed quick-win fixes implemented during the engagement, and both readout sessions — executive and technical. Fixed price, quoted in writing before we start; you pay after you approve delivery. Multi-domain or multi-forest scopes are agreed and priced at scoping, not discovered in week two.
Why does the age of the krbtgt password matter?
The krbtgt account's password signs every Kerberos ticket in the domain. If it has not been rotated in years — common, because rotation is scary without a procedure — then anyone who ever extracted its hash can mint golden tickets that impersonate any user, indefinitely, surviving every other password reset you do. The assessment reports its age and hands you Microsoft's supported double-reset procedure with the timing caveats, so rotation becomes routine hygiene instead of folklore.
What is admin tiering and why do you deliver a roadmap instead of implementing it?
Tiering separates control of the directory itself (Tier 0: domain controllers, privileged accounts, and everything that can reach them) from server and workstation administration, so a phished helpdesk account can no longer become Domain Admin by lunchtime. Full enforcement touches accounts, workstations, policies, and habits — it is weeks of change management, not an afternoon, and pretending it fits inside an assessment would shortchange both. You get a staged roadmap sized to your team, with stage one concrete enough to start immediately; implementation is separately scoped if you want our hands on it.
Will the assessment break anything?
The assessment itself is read-oriented collection and analysis — it changes nothing. The only changes made during the engagement are the quick wins, and those are: agreed with you item by item beforehand, low-risk and reversible by design, and executed through your change process with before/after state documented. Anything with real breakage potential is explicitly routed to the roadmap instead.
What access do you need?
Time-bound, least-privilege access that you create and you disable afterward — the same discipline we publish for our Microsoft 365 engagements. Collection runs with read-oriented rights; certain checks that need elevation are agreed explicitly and individually. We never ask for standing Domain Admin, and if a provider assessing your directory does, that is itself a finding.
We just failed items on a pen test or an insurer questionnaire. Is this the right response?
Often, yes — third-party findings tell you that a problem exists; this assessment tells you why, what else sits in the same category, and in what order to fix it all without breaking authentication for a plant floor at 2 a.m. Bring the report: we map our findings to theirs, close the overlap, and give your insurer or auditor a documented remediation plan, which is frequently what they actually wanted.
Our AD is 'legacy' — we plan to go cloud-only eventually. Why harden it now?
Because 'eventually' is the attacker's favorite word. As long as domain controllers authenticate your users, AD is your security foundation, and a compromised domain also compromises everything it syncs to — including your Microsoft 365 tenant via the identities it masters. Harden what you run today; and if cloud-only is the genuine direction, we will say so in the readout and point you at a planned Entra ID transition rather than selling you hardening forever.
What are 'known attack paths' — what do you actually check?
The documented, repeatedly-breached routes: privilege escalation through group nesting and ACLs, DCSync rights outside domain controllers, kerberoastable service accounts, AS-REP roasting, unconstrained and resource-based delegation abuse, NTLM relay exposure via missing signing and channel binding, credential artifacts in SYSVOL, exploitable AD CS template configurations, stale privileged accounts, machine-account quota abuse, and trust misconfigurations, among others. The methodology is attack-path-first: we report what an adversary could chain together in your domain, not an alphabetical list of settings that differ from a benchmark.
Do you use automated tools or is this manual?
Both, in the only order that works: tooling collects and correlates at a scale no human can, then an engineer verifies, contextualizes, and scores every finding that makes the report. What you will not get is a raw tool export with a cover page — a finding only appears if a person confirmed it is real in your environment and understood what it enables.
What happens if you find evidence of an active compromise?
We stop assessing, tell you immediately through the agreed contact, and help you engage a proper incident-response process — preserving evidence rather than trampling it. An assessment quietly upgraded into incident response serves neither purpose well, and you deserve to know the moment the engagement changes character.
How is this different from your on-premises security hardening service?
Sequence and product. This is the fixed-fee assessment: two weeks, a scored report, a roadmap, a tiering plan, and the agreed quick wins — you know exactly what it costs and what you get. The hardening service is the remediation arm: hourly engineering that executes roadmap items across your broader on-premises environment. Assessment first is the honest order; buying remediation hours before anyone has scored the risks is how budgets get spent on the wrong fixes.
How often should this be repeated?
Annually as a baseline, and after anything that reshapes the directory: a merger or acquisition, a domain migration, major delegation changes, or turnover in privileged staff. Directories drift toward entropy — group memberships grow, exceptions outlive their reasons — and the second assessment is typically faster and cheaper to act on because the roadmap infrastructure already exists.