Somebody built your Active Directory years ago, and nobody has looked at it properly since.
It still authenticates every single thing you run. It has collected a decade of accounts, groups and delegations along the way. And an attacker who reaches it has reached everything at once. We audit what your directory actually contains rather than what the documentation claims, and we lead with the findings that would matter if something happened tomorrow.

- Still the targetCompromise AD, own the estate
- Windows LAPSFree, built in, usually not deployed
- Legacy LAPSDeprecated since Windows 11 23H2
- Hybrid includedEntra Connect is in scope too
Eight areas, ordered the way an attacker would work through them.
Privileged groups, and everyone who is quietly in them
Domain Admins, Enterprise Admins, Schema Admins, Account Operators, Backup Operators and the built-in Administrators group, together with every group nested inside any of them. Nesting is what conceals the true figure. A group added for a project years ago can still be carrying a dozen accounts nobody would think to mention if you asked them who has admin. We resolve membership all the way down rather than reading off the top level.
Delegation and the permissions granted along the way
Rights delegated across organizational units so the helpdesk could reset passwords. Permissions handed to a service account during some installation. Access control entries nobody has opened since. Taken one at a time every one of those was a reasonable decision. Taken together they frequently build a route from an ordinary account to complete control of the domain, and finding that route is the entire point of the audit.
Service accounts, which are the standing weakness
Accounts whose passwords have not moved in years, sitting inside privileged groups because that was the quickest route at install time, with their credentials written into a script or a scheduled task somewhere on the network. Attackers go looking for these first, and for good reason. They are powerful, almost nobody monitors them, and nobody in the organization will touch them in case something stops working.
Local administrator passwords, and whether LAPS is deployed
Where one shared local administrator password covers the whole estate, compromising a single machine hands an attacker all of them. Windows LAPS closes that, it ships inside Windows, and it is documented as free across every supported platform, with protection against pass-the-hash and lateral traversal named as the benefit. Most estates we assess are running either nothing at all or the deprecated legacy product.
Stale accounts, stale computers, and old protocols
Accounts belonging to people who left. Computer objects for machines decommissioned several years ago. Passwords set never to expire. Legacy authentication protocols still switched on because one old application needed them once, long ago. Each of those on its own is a minor thing. Added together they are what separates an estate an attacker struggles to move through from one they do not.
Certificate services, if you run them
An internal certificate authority is genuinely powerful infrastructure, and it is very often configured once and never examined again. Template permissions and enrollment settings between them can open privilege escalation paths that are not remotely obvious from the certificate authority console. Where you run AD Certificate Services we assess it specifically, because it is a well-documented route that hardly anybody checks.
The hybrid join to Microsoft Entra
Nearly every American business running on-premises Active Directory also synchronizes it to Microsoft Entra, which makes the two halves a single connected identity system rather than two independent ones. The synchronization server is itself highly privileged, the sync account is powerful in its own right, and compromising the on-premises side frequently means compromising the cloud alongside it. We assess the join between them rather than treating each side as a separate problem.
Whether you would see any of it happening
We look at the domain controller audit policy, at what is genuinely being logged rather than what was intended, at whether those logs ever leave the domain controllers, and at how long anybody keeps them. An attacker who has reached Active Directory can alter or clear local logs at will, which means logs existing only on the domain controller are logs you may not have on the day you need them. That distinction is what separates investigating an incident from guessing about one.
Where one local admin password unlocks every machine, that is the thing to fix before anything else.
On most of these assessments this single item returns more than anything else. It costs nothing, it is already inside Windows, and it is almost always either missing entirely or running on a product that has been deprecated.
- Lateral movement is the problem being solved here. When the same local administrator password works everywhere, an attacker who takes one laptop is holding working credentials for every other machine you own. Protection against pass-the-hash and lateral traversal attacks is named in the documentation as precisely what Windows LAPS exists to provide.
- It arrived built into Windows through updates released on April 11, 2023. Availability covers Windows 11 23H2 and later, Windows 10 and 11 carrying that April 2023 update, Windows Server 2025 and later, and Server 2019 and 2022 with the same update applied. The feature is documented as free across every supported Windows platform.
- That legacy Microsoft LAPS product, the separate download dating from 2016, is deprecated from Windows 11 23H2 onward. Its installer package is blocked on newer operating system versions, and code changes for it are no longer being considered at all. If that is what your estate is running, you are relying on a product with no future while a supported replacement sits already installed on the same machines.
- There is one planning detail that catches people out. Passwords back up either to Active Directory or to Microsoft Entra ID, and never to both at once. A device joined only to Entra backs up to Entra. A device joined only to Active Directory backs up there. A hybrid joined device can go either way, and somebody has to choose. Make that decision before deploying rather than discovering it afterwards.
Four things that make the findings something you can act on rather than something that just alarms people.
We rank by exploitability, not by tool severity
A scanner tells you what deviates from a template. We tell you what genuinely shortens the path from an ordinary user account to domain control inside your particular directory. Those two lists overlap far less than anybody expects, and the second is considerably shorter, which is exactly what makes it something your team can actually work through.
We work with what you can realistically change
Every directory that has been running a long time contains a service account nobody will touch and an old application demanding a protocol that should have been retired years back. Telling you to remove them is not advice. It is a restatement of the problem you already have. What we propose instead are sequences that bring the risk down while the underlying constraint gets worked on separately, because a recommendation nobody is able to act on achieves precisely nothing.
On-premises and Entra get assessed as a single identity system
The two are joined, the synchronization server carries high privilege, and an attacker holding Active Directory very often holds the cloud tenant as well. Audit one side while ignoring the other and the picture you produce is simply false. So we assess the join itself, the sync account behind it, and what a compromise on either side would be able to reach.
We fix things, not only list them
Every finding arrives with what to change, a realistic sense of the effort, and an honest note on what might break. Your team can carry out the work or we can, and we have no preference. Where something is genuinely urgent, an exposed path to domain control being the obvious case, you hear about it during the audit rather than three weeks later in a document.
Six situations that bring US businesses to a directory audit.
Following a ransomware incident at a competitor or a supplier
This is the most common trigger, and it is a rational one. Ransomware inside a Windows estate nearly always travels through Active Directory, because that is the mechanism taking an attacker from one machine to every machine. Somebody senior reads about a comparable business losing a week of trading and asks whether the same thing could happen here. Answering that honestly means going and looking.
A regulated firm facing examination or assessment
GLBA and the FTC Safeguards Rule both expect access controls over customer information. NYDFS Part 500 asks about privileged access directly. A CMMC assessment against NIST 800-171 goes through account management in detail. For any firm still running on-premises infrastructure, Active Directory is where most of that access genuinely lives, and it is routinely the least documented area precisely because it predates every piece of compliance work you have done.
Manufacturing, logistics, and site-based operations
Estates that have been running a long time, older equipment, machines that cannot be patched on any normal cadence, and shared accounts on the shop floor existing for entirely genuine operational reasons. An audit here has to stay pragmatic about what is actually changeable, and the value lies in containing the risk from the parts that cannot change rather than pretending somebody will fix them next quarter.
A business that has changed IT provider
Any incoming provider inherits a directory somebody else built, full of administrative accounts, delegations and service accounts whose original purpose nobody can recall. An independent audit at the point of handover establishes a baseline, and it reliably turns up accounts belonging to the previous relationship that should have been removed on the day it ended.
A group that has grown by acquisition
Several domains, trusts set up during integrations and never looked at since, and standards that differ from one entity to the next. Trusts deserve particular attention, because they extend the blast radius across boundaries. A weakness in your least well managed entity becomes a problem for your best managed one. Acquirers running technical due diligence ask precisely these questions.
A cyber insurance application that asked specifics
Insurance applications in the United States now ask directly how many privileged accounts you hold, how local administrator passwords are managed, and whether administrative accounts are separated from ordinary ones. These are not questions to answer optimistically, since a claim can turn on whether the answer was accurate, and most businesses cannot answer them from their records at all.
What we find when we audit Active Directory.
| Feature | Audited and tiered | Built once, then accumulated | Never reviewed |
|---|---|---|---|
Domain Admin count known and small | Grown quietly | Unknown | |
Administrative accounts separate from daily accounts | Partially | ||
Service accounts scoped rather than privileged | Mixed | ||
Local admin passwords unique per machine | Sometimes | ||
Delegations documented and justified | |||
Stale accounts and computers removed | Occasionally | ||
Legacy protocols disabled | Partially | ||
Domain controller logs centralized | Sometimes | ||
Privileged group changes alerted | |||
How common among US mid-market estates | Uncommon | The default | Common in smaller firms |
Windows LAPS against legacy LAPS against nothing.
Built into Windows
- Windows LAPS
- Yes
- Legacy Microsoft LAPS
- No, separate installer
- No LAPS
- Not applicable
Currently supported
- Windows LAPS
- Yes
- Legacy Microsoft LAPS
- Deprecated on Windows 11 23H2 and later
- No LAPS
- Not applicable
Installer blocked on newer Windows
- Windows LAPS
- Not applicable
- Legacy Microsoft LAPS
- Yes
- No LAPS
- Not applicable
Receives code changes from Microsoft
- Windows LAPS
- Yes
- Legacy Microsoft LAPS
- No
- No LAPS
- Not applicable
Backs up to Active Directory
- Windows LAPS
- Yes
- Legacy Microsoft LAPS
- Yes
- No LAPS
- No
Backs up to Microsoft Entra ID
- Windows LAPS
- Yes
- Legacy Microsoft LAPS
- No
- No LAPS
- No
Password encryption in Active Directory
- Windows LAPS
- Yes
- Legacy Microsoft LAPS
- No
- No LAPS
- No
Password history
- Windows LAPS
- Yes
- Legacy Microsoft LAPS
- No
- No LAPS
- No
Manages DSRM password on domain controllers
- Windows LAPS
- Yes
- Legacy Microsoft LAPS
- No
- No LAPS
- No
Cost of the feature itself
- Windows LAPS
- Free on supported Windows
- Legacy Microsoft LAPS
- Free
- No LAPS
- Nil, and expensive later
One compromised machine reaches the rest
- Windows LAPS
- No
- Legacy Microsoft LAPS
- No
- No LAPS
- Yes
Five stages, typically one to two weeks.
- 1
Scope and read-only collection
We establish what falls in scope: how many domains exist, whether certificate services are running, and whether the estate is hybrid joined to Microsoft Entra. The collection itself is read-only and runs against your domain controllers without altering a thing. We agree in advance what access is needed and how it will be granted, and you revoke it when we are done.
- 2
Privilege and path analysis
Privileged group membership gets resolved in full, nesting included, alongside delegation across organizational units, the rights held by service accounts, and every path by which a standard account could arrive at domain control. This is the phase that produces the highest-severity findings, and it takes the largest share of the analysis time.
- 3
Hygiene and configuration review
Stale accounts and computer objects, how the password policy behaves in practice rather than how it reads on paper, legacy protocols still enabled, how local administrator passwords are managed and whether LAPS is deployed and in which of its two forms, plus the certificate services configuration wherever that exists.
- 4
Visibility and recovery review
The domain controller audit policy, whether those logs ever leave the domain controllers, how long anything is retained, whether a change to a privileged group would generate an alert anybody sees, and whether a single person has ever tested restoring a domain controller. Recovering a directory is materially unlike recovering files, and it is reliably the least rehearsed part of any continuity plan.
- 5
Report, prioritize, and remediate
Findings are ranked by how much each one shortens an attack path inside your directory specifically, each with what to change, the effort involved and what might break. Then the work happens, carried out by your team or by ours. Where you want it, we re-audit afterwards so the improvement is evidenced rather than assumed, which matters a great deal if an insurer or a customer asked the question that started all this.
What organizations ask about an Active Directory audit.
Fifteen questions about your own Active Directory.
Privilege
- How many accounts are in Domain Admins, counting nested groups?Resolve nesting fully. The real number surprises people.
- Do any of those same accounts also read email and browse the internet?Administrative work has no business sharing a session with ordinary daily work.
- How many service accounts sit in privileged groups?Almost always put there during an installation to get something running.
- When did service account passwords last change?If the answer is never, that is the finding.
- Who can reset passwords for privileged accounts?Delegation granted for helpdesk convenience reaches further than intended.
Accumulated debt
- How many enabled accounts have not signed in for 90 days?Every one is a live credential nobody is watching.
- How many computer objects no longer exist as machines?Stale objects clutter the picture and can be reused.
- Which accounts have passwords set never to expire?Almost always service accounts, almost always privileged.
- Are legacy authentication protocols still enabled?Usually for one old application nobody wants to touch.
- Can anybody explain, in writing, why each delegation on each OU exists?If nobody can explain it, it should probably go.
Would you see it
- Do domain controller logs leave the domain controllers?Whoever compromised the machine can clear the logs sitting on it.
- How long are those logs retained?Investigations routinely need to reach further back than anybody planned for.
- Would a new Domain Admin membership generate an alert?This is one of the very few events worth alerting on every single time.
- Is Windows LAPS deployed, and to what?Free, built in, and usually absent.
- Has anybody tested restoring a domain controller?Recovering a directory bears no resemblance to recovering a file server.
The pages around this one.
Microsoft 365 security audit
The cloud half of this same identity system, covering gaps in Conditional Access and how far back your audit evidence genuinely goes.
Microsoft Entra
Where your directory synchronizes to, and the controls that close a good many of the findings this audit produces.
Cybersecurity audit and compliance
The broader audit practice, and how to work out which sort of engagement your situation genuinely needs.
Two questions you can answer this afternoon.
Two questions. How many accounts sit in Domain Admins once every nested group has been resolved, and is any form of local administrator password management actually deployed. If that first number surprises you, or the second answer turns out to be no, an audit is worth a week of your time, and we will tell you exactly what we would look at first.
Related Services
Explore more solutions that work great with this service
Microsoft 365 Security Audit
Independent Microsoft 365 tenant security audit for US organizations
Learn moreAzure Security Audit
Independent audit of your Azure subscriptions and resources
Learn moreMicrosoft Entra
Identity and access management solutions
Learn moreRansomware Protection
Layered ransomware protection for US businesses covering prevention
Learn morePenetration Testing
Penetration testing for US businesses across external, internal, web
Learn more