We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Active Directory security audit
Active Directory security audit for US businesses

Somebody built your Active Directory years ago, and nobody has looked at it properly since.

It still authenticates every single thing you run. It has collected a decade of accounts, groups and delegations along the way. And an attacker who reaches it has reached everything at once. We audit what your directory actually contains rather than what the documentation claims, and we lead with the findings that would matter if something happened tomorrow.

Book an Active Directory auditSee what we examine
Active Directory security audit for US organizations
  • Still the targetCompromise AD, own the estate
  • Windows LAPSFree, built in, usually not deployed
  • Legacy LAPSDeprecated since Windows 11 23H2
  • Hybrid includedEntra Connect is in scope too
What we examine

Eight areas, ordered the way an attacker would work through them.

This is not a health check on replication and DNS, useful though those undoubtedly are. It is an assessment of the routes by which an ordinary user account could end up a domain administrator, and of the accumulated decisions that have made those routes shorter than anybody in the building realizes.

Privileged groups, and everyone who is quietly in them

Domain Admins, Enterprise Admins, Schema Admins, Account Operators, Backup Operators and the built-in Administrators group, together with every group nested inside any of them. Nesting is what conceals the true figure. A group added for a project years ago can still be carrying a dozen accounts nobody would think to mention if you asked them who has admin. We resolve membership all the way down rather than reading off the top level.

Delegation and the permissions granted along the way

Rights delegated across organizational units so the helpdesk could reset passwords. Permissions handed to a service account during some installation. Access control entries nobody has opened since. Taken one at a time every one of those was a reasonable decision. Taken together they frequently build a route from an ordinary account to complete control of the domain, and finding that route is the entire point of the audit.

Service accounts, which are the standing weakness

Accounts whose passwords have not moved in years, sitting inside privileged groups because that was the quickest route at install time, with their credentials written into a script or a scheduled task somewhere on the network. Attackers go looking for these first, and for good reason. They are powerful, almost nobody monitors them, and nobody in the organization will touch them in case something stops working.

Local administrator passwords, and whether LAPS is deployed

Where one shared local administrator password covers the whole estate, compromising a single machine hands an attacker all of them. Windows LAPS closes that, it ships inside Windows, and it is documented as free across every supported platform, with protection against pass-the-hash and lateral traversal named as the benefit. Most estates we assess are running either nothing at all or the deprecated legacy product.

Stale accounts, stale computers, and old protocols

Accounts belonging to people who left. Computer objects for machines decommissioned several years ago. Passwords set never to expire. Legacy authentication protocols still switched on because one old application needed them once, long ago. Each of those on its own is a minor thing. Added together they are what separates an estate an attacker struggles to move through from one they do not.

Certificate services, if you run them

An internal certificate authority is genuinely powerful infrastructure, and it is very often configured once and never examined again. Template permissions and enrollment settings between them can open privilege escalation paths that are not remotely obvious from the certificate authority console. Where you run AD Certificate Services we assess it specifically, because it is a well-documented route that hardly anybody checks.

The hybrid join to Microsoft Entra

Nearly every American business running on-premises Active Directory also synchronizes it to Microsoft Entra, which makes the two halves a single connected identity system rather than two independent ones. The synchronization server is itself highly privileged, the sync account is powerful in its own right, and compromising the on-premises side frequently means compromising the cloud alongside it. We assess the join between them rather than treating each side as a separate problem.

Whether you would see any of it happening

We look at the domain controller audit policy, at what is genuinely being logged rather than what was intended, at whether those logs ever leave the domain controllers, and at how long anybody keeps them. An attacker who has reached Active Directory can alter or clear local logs at will, which means logs existing only on the domain controller are logs you may not have on the day you need them. That distinction is what separates investigating an incident from guessing about one.

One free fix worth doing regardless

Where one local admin password unlocks every machine, that is the thing to fix before anything else.

On most of these assessments this single item returns more than anything else. It costs nothing, it is already inside Windows, and it is almost always either missing entirely or running on a product that has been deprecated.

  • Lateral movement is the problem being solved here. When the same local administrator password works everywhere, an attacker who takes one laptop is holding working credentials for every other machine you own. Protection against pass-the-hash and lateral traversal attacks is named in the documentation as precisely what Windows LAPS exists to provide.
  • It arrived built into Windows through updates released on April 11, 2023. Availability covers Windows 11 23H2 and later, Windows 10 and 11 carrying that April 2023 update, Windows Server 2025 and later, and Server 2019 and 2022 with the same update applied. The feature is documented as free across every supported Windows platform.
  • That legacy Microsoft LAPS product, the separate download dating from 2016, is deprecated from Windows 11 23H2 onward. Its installer package is blocked on newer operating system versions, and code changes for it are no longer being considered at all. If that is what your estate is running, you are relying on a product with no future while a supported replacement sits already installed on the same machines.
  • There is one planning detail that catches people out. Passwords back up either to Active Directory or to Microsoft Entra ID, and never to both at once. A device joined only to Entra backs up to Entra. A device joined only to Active Directory backs up there. A hybrid joined device can go either way, and somebody has to choose. Make that decision before deploying rather than discovering it afterwards.
Ask us to check your LAPS position
How we audit

Four things that make the findings something you can act on rather than something that just alarms people.

Running a tool against Active Directory and producing four hundred findings is trivially easy. That report gets read once and filed away forever, because nobody has ever acted on four hundred of anything.

We rank by exploitability, not by tool severity

A scanner tells you what deviates from a template. We tell you what genuinely shortens the path from an ordinary user account to domain control inside your particular directory. Those two lists overlap far less than anybody expects, and the second is considerably shorter, which is exactly what makes it something your team can actually work through.

We work with what you can realistically change

Every directory that has been running a long time contains a service account nobody will touch and an old application demanding a protocol that should have been retired years back. Telling you to remove them is not advice. It is a restatement of the problem you already have. What we propose instead are sequences that bring the risk down while the underlying constraint gets worked on separately, because a recommendation nobody is able to act on achieves precisely nothing.

On-premises and Entra get assessed as a single identity system

The two are joined, the synchronization server carries high privilege, and an attacker holding Active Directory very often holds the cloud tenant as well. Audit one side while ignoring the other and the picture you produce is simply false. So we assess the join itself, the sync account behind it, and what a compromise on either side would be able to reach.

We fix things, not only list them

Every finding arrives with what to change, a realistic sense of the effort, and an honest note on what might break. Your team can carry out the work or we can, and we have no preference. Where something is genuinely urgent, an exposed path to domain control being the obvious case, you hear about it during the audit rather than three weeks later in a document.

When organizations ask for this

Six situations that bring US businesses to a directory audit.

Hardly anybody audits Active Directory before they have to, which is a shame, because in most estates it is exactly where the highest-severity findings have been sitting all along.

Following a ransomware incident at a competitor or a supplier

This is the most common trigger, and it is a rational one. Ransomware inside a Windows estate nearly always travels through Active Directory, because that is the mechanism taking an attacker from one machine to every machine. Somebody senior reads about a comparable business losing a week of trading and asks whether the same thing could happen here. Answering that honestly means going and looking.

A regulated firm facing examination or assessment

GLBA and the FTC Safeguards Rule both expect access controls over customer information. NYDFS Part 500 asks about privileged access directly. A CMMC assessment against NIST 800-171 goes through account management in detail. For any firm still running on-premises infrastructure, Active Directory is where most of that access genuinely lives, and it is routinely the least documented area precisely because it predates every piece of compliance work you have done.

Manufacturing, logistics, and site-based operations

Estates that have been running a long time, older equipment, machines that cannot be patched on any normal cadence, and shared accounts on the shop floor existing for entirely genuine operational reasons. An audit here has to stay pragmatic about what is actually changeable, and the value lies in containing the risk from the parts that cannot change rather than pretending somebody will fix them next quarter.

A business that has changed IT provider

Any incoming provider inherits a directory somebody else built, full of administrative accounts, delegations and service accounts whose original purpose nobody can recall. An independent audit at the point of handover establishes a baseline, and it reliably turns up accounts belonging to the previous relationship that should have been removed on the day it ended.

A group that has grown by acquisition

Several domains, trusts set up during integrations and never looked at since, and standards that differ from one entity to the next. Trusts deserve particular attention, because they extend the blast radius across boundaries. A weakness in your least well managed entity becomes a problem for your best managed one. Acquirers running technical due diligence ask precisely these questions.

A cyber insurance application that asked specifics

Insurance applications in the United States now ask directly how many privileged accounts you hold, how local administrator passwords are managed, and whether administrative accounts are separated from ordinary ones. These are not questions to answer optimistically, since a claim can turn on whether the answer was accurate, and most businesses cannot answer them from their records at all.

Three directory positions

What we find when we audit Active Directory.

The middle column covers the overwhelming majority. Somebody competent built the directory properly. Then a decade of projects, staff changes and consultants happened to it, and nobody ever stood back and looked at the whole thing again.
Domain Admin count known and small
Audited and tiered
Built once, then accumulatedGrown quietly
Never reviewedUnknown
Administrative accounts separate from daily accounts
Audited and tiered
Built once, then accumulatedPartially
Never reviewed
Service accounts scoped rather than privileged
Audited and tiered
Built once, then accumulatedMixed
Never reviewed
Local admin passwords unique per machine
Audited and tiered
Built once, then accumulatedSometimes
Never reviewed
Delegations documented and justified
Audited and tiered
Built once, then accumulated
Never reviewed
Stale accounts and computers removed
Audited and tiered
Built once, then accumulatedOccasionally
Never reviewed
Legacy protocols disabled
Audited and tiered
Built once, then accumulatedPartially
Never reviewed
Domain controller logs centralized
Audited and tiered
Built once, then accumulatedSometimes
Never reviewed
Privileged group changes alerted
Audited and tiered
Built once, then accumulated
Never reviewed
How common among US mid-market estates
Audited and tieredUncommon
Built once, then accumulatedThe default
Never reviewedCommon in smaller firms
Feature
Audited and tiered
Built once, then accumulated
Never reviewed
Domain Admin count known and small
Grown quietlyUnknown
Administrative accounts separate from daily accounts
Partially
Service accounts scoped rather than privileged
Mixed
Local admin passwords unique per machine
Sometimes
Delegations documented and justified
Stale accounts and computers removed
Occasionally
Legacy protocols disabled
Partially
Domain controller logs centralized
Sometimes
Privileged group changes alerted
How common among US mid-market estates
UncommonThe defaultCommon in smaller firms
Local administrator password management

Windows LAPS against legacy LAPS against nothing.

Everything in the first two columns is drawn from the vendor documentation. The third column describes the position most estates are genuinely in, and it is that position which turns one compromised laptop into a compromised estate.

Built into Windows

Windows LAPS
Yes
Legacy Microsoft LAPS
No, separate installer
No LAPS
Not applicable

Currently supported

Windows LAPS
Yes
Legacy Microsoft LAPS
Deprecated on Windows 11 23H2 and later
No LAPS
Not applicable

Installer blocked on newer Windows

Windows LAPS
Not applicable
Legacy Microsoft LAPS
Yes
No LAPS
Not applicable

Receives code changes from Microsoft

Windows LAPS
Yes
Legacy Microsoft LAPS
No
No LAPS
Not applicable

Backs up to Active Directory

Windows LAPS
Yes
Legacy Microsoft LAPS
Yes
No LAPS
No

Backs up to Microsoft Entra ID

Windows LAPS
Yes
Legacy Microsoft LAPS
No
No LAPS
No

Password encryption in Active Directory

Windows LAPS
Yes
Legacy Microsoft LAPS
No
No LAPS
No

Password history

Windows LAPS
Yes
Legacy Microsoft LAPS
No
No LAPS
No

Manages DSRM password on domain controllers

Windows LAPS
Yes
Legacy Microsoft LAPS
No
No LAPS
No

Cost of the feature itself

Windows LAPS
Free on supported Windows
Legacy Microsoft LAPS
Free
No LAPS
Nil, and expensive later

One compromised machine reaches the rest

Windows LAPS
No
Legacy Microsoft LAPS
No
No LAPS
Yes
Windows LAPSLegacy Microsoft LAPSNo LAPS
Built into WindowsYesNo, separate installerNot applicable
Currently supportedYesDeprecated on Windows 11 23H2 and laterNot applicable
Installer blocked on newer WindowsNot applicableYesNot applicable
Receives code changes from MicrosoftYesNoNot applicable
Backs up to Active DirectoryYesYesNo
Backs up to Microsoft Entra IDYesNoNo
Password encryption in Active DirectoryYesNoNo
Password historyYesNoNo
Manages DSRM password on domain controllersYesNoNo
Cost of the feature itselfFree on supported WindowsFreeNil, and expensive later
One compromised machine reaches the restNoNoYes
How the audit runs

Five stages, typically one to two weeks.

Collection is read-only, runs remotely and disrupts nothing at all. Interpretation is what consumes the time, because a permission that is genuinely dangerous in one directory is entirely reasonable in another, and the only thing separating the two is context.
  1. 1

    Scope and read-only collection

    We establish what falls in scope: how many domains exist, whether certificate services are running, and whether the estate is hybrid joined to Microsoft Entra. The collection itself is read-only and runs against your domain controllers without altering a thing. We agree in advance what access is needed and how it will be granted, and you revoke it when we are done.

  2. 2

    Privilege and path analysis

    Privileged group membership gets resolved in full, nesting included, alongside delegation across organizational units, the rights held by service accounts, and every path by which a standard account could arrive at domain control. This is the phase that produces the highest-severity findings, and it takes the largest share of the analysis time.

  3. 3

    Hygiene and configuration review

    Stale accounts and computer objects, how the password policy behaves in practice rather than how it reads on paper, legacy protocols still enabled, how local administrator passwords are managed and whether LAPS is deployed and in which of its two forms, plus the certificate services configuration wherever that exists.

  4. 4

    Visibility and recovery review

    The domain controller audit policy, whether those logs ever leave the domain controllers, how long anything is retained, whether a change to a privileged group would generate an alert anybody sees, and whether a single person has ever tested restoring a domain controller. Recovering a directory is materially unlike recovering files, and it is reliably the least rehearsed part of any continuity plan.

  5. 5

    Report, prioritize, and remediate

    Findings are ranked by how much each one shortens an attack path inside your directory specifically, each with what to change, the effort involved and what might break. Then the work happens, carried out by your team or by ours. Where you want it, we re-audit afterwards so the improvement is evidenced rather than assumed, which matters a great deal if an insurer or a customer asked the question that started all this.

Straight answers

What organizations ask about an Active Directory audit.

There is, and arguably more during a migration than before one starts. Most American businesses moving to Microsoft 365 keep Active Directory synchronized to Entra for years afterwards, which makes the two a single connected identity system rather than an old one and a new one. An attacker compromising the on-premises side very often reaches the cloud tenant through that connection. Auditing the directory you are in the process of leaving is not wasted effort while it still authenticates your people and still feeds your cloud identity.

It does not. Collection is read-only, runs against your domain controllers without altering any configuration, and no user notices a thing. Remediation is where disruption becomes possible, particularly anything touching service accounts or authentication protocols, and that is exactly why the two are kept separate and every change is planned with you. Anything genuinely urgent found during collection reaches you immediately rather than waiting for the report to be written.

Three, in order. Privileged group membership that turns out far larger than anyone believed once every nested group has been resolved. Service accounts sitting inside Domain Admins carrying passwords that have not moved in years, put there during an installation because it made something start working. And one shared local administrator password covering the entire estate, which converts a single compromised laptop into a compromised organization and costs nothing to fix with Windows LAPS.

It manages and backs up the local administrator password on every machine automatically, so no two devices share one. The capability is built into Windows, arrived in updates released on April 11, 2023, and is documented as free across every supported Windows platform. Its stated purpose is protection against pass-the-hash and lateral traversal attacks, which is exactly the movement that turns one infection into an estate-wide incident. If you currently manage local administrator passwords not at all, no free change available to you returns more than this one.

That depends entirely on which one you have. The legacy Microsoft LAPS product, downloaded separately since 2016, is deprecated from Windows 11 23H2 onward, its installer is blocked on newer operating system versions, and code changes for it are no longer being considered. Windows LAPS is the built-in successor, adding backup into Microsoft Entra ID, password encryption within Active Directory, and password history. Anyone still on the legacy product is running something with no future while its supported replacement sits already installed on the same machines.

You cannot, and this trips up more deployments at the planning stage than anything else. Backing up to both destinations is explicitly not supported. A device joined only to Microsoft Entra ID backs up to Entra alone. A device joined only to Active Directory backs up there alone. A hybrid joined device can use one or the other, never both. Settle that destination before you deploy, based on where your devices are genuinely joined and where your administrators will actually go to retrieve a password.

Very few, with a stated reason attached to each. No universal number exists, though the pattern behind the growth is always the same. A project needed it. A vendor asked for it. Somebody was granted it temporarily and nobody ever took it away. Beyond the raw count, two questions matter more: are administrative accounts held separately from the everyday accounts those same people use for email and browsing, and is any service account sitting in that group simply because it was the quickest route during an installation.

Tiering divides administration according to how sensitive the thing being administered is, so credentials capable of controlling domain controllers never touch an ordinary workstation where somebody could capture them. It works, and implementing it properly is a substantial piece of work. For a smaller business, separating administrative accounts from daily accounts and getting LAPS deployed delivers most of the practical benefit at a fraction of that effort, and that is normally what we would recommend doing first.

Very directly, because the two are joined. Where identities synchronize, the synchronization server is among the most privileged machines you own and the sync account behind it is powerful in its own right. A compromise on the Active Directory side regularly becomes a compromise of the cloud tenant along that path. The join gets assessed as part of this audit. If you want the cloud side examined to the same depth, that is our Microsoft 365 security audit, and the two are frequently run together.

A typical single-domain estate takes one to two weeks. What we need is read access sufficient to enumerate the directory, granted in a form you control and can withdraw, plus time with whoever remembers the history. Which service account belongs to which system. Why a particular delegation was created. Which application is still holding the old protocol open. That history is precisely what turns a pile of raw findings into a report somebody can act on.

They can, subject to the same caveat we apply to ourselves in the same position. They built the directory or they have been running it, which makes their audit an assessment of their own work. That is structural rather than an accusation about anybody. Where we manage a client estate we say plainly that our audit of it is not independent, and we have no objection to a third party reviewing it. For an insurer, an examiner or an acquirer, independence is frequently the entire point of asking.

A directory accumulates without pause, so annually is a sensible cadence, with an extra audit following anything significant such as an acquisition, a domain restructure or a change of IT provider. Frequency matters, and so does comparability: the second audit has to be measured the same way as the first, otherwise it cannot show whether anything genuinely improved. Engagements are scoped per business, driven by domain count, whether certificate services and hybrid identity fall in scope, and whether remediation is included. In the first conversation we will show you free of charge how to check two things for yourself: your fully resolved Domain Admins membership, and whether any form of local administrator password management exists at all.
Directory health check

Fifteen questions about your own Active Directory.

Group one is privilege, being what an attacker is working toward. Group two is the accumulated debt every long-lived directory carries around with it. Group three answers a single question: would you see an attack happening, or would you learn about it afterwards.

Privilege

  • How many accounts are in Domain Admins, counting nested groups?
    Resolve nesting fully. The real number surprises people.
  • Do any of those same accounts also read email and browse the internet?
    Administrative work has no business sharing a session with ordinary daily work.
  • How many service accounts sit in privileged groups?
    Almost always put there during an installation to get something running.
  • When did service account passwords last change?
    If the answer is never, that is the finding.
  • Who can reset passwords for privileged accounts?
    Delegation granted for helpdesk convenience reaches further than intended.

Accumulated debt

  • How many enabled accounts have not signed in for 90 days?
    Every one is a live credential nobody is watching.
  • How many computer objects no longer exist as machines?
    Stale objects clutter the picture and can be reused.
  • Which accounts have passwords set never to expire?
    Almost always service accounts, almost always privileged.
  • Are legacy authentication protocols still enabled?
    Usually for one old application nobody wants to touch.
  • Can anybody explain, in writing, why each delegation on each OU exists?
    If nobody can explain it, it should probably go.

Would you see it

  • Do domain controller logs leave the domain controllers?
    Whoever compromised the machine can clear the logs sitting on it.
  • How long are those logs retained?
    Investigations routinely need to reach further back than anybody planned for.
  • Would a new Domain Admin membership generate an alert?
    This is one of the very few events worth alerting on every single time.
  • Is Windows LAPS deployed, and to what?
    Free, built in, and usually absent.
  • Has anybody tested restoring a domain controller?
    Recovering a directory bears no resemblance to recovering a file server.
Related reading

The pages around this one.

Microsoft 365 security audit

The cloud half of this same identity system, covering gaps in Conditional Access and how far back your audit evidence genuinely goes.

Learn more

Microsoft Entra

Where your directory synchronizes to, and the controls that close a good many of the findings this audit produces.

Learn more

Cybersecurity audit and compliance

The broader audit practice, and how to work out which sort of engagement your situation genuinely needs.

Learn more
Next step

Two questions you can answer this afternoon.

Two questions. How many accounts sit in Domain Admins once every nested group has been resolved, and is any form of local administrator password management actually deployed. If that first number surprises you, or the second answer turns out to be no, an audit is worth a week of your time, and we will tell you exactly what we would look at first.

Book an Active Directory auditSee the audit practice

Related Services

Explore more solutions that work great with this service

Microsoft 365 Security Audit

Independent Microsoft 365 tenant security audit for US organizations

Learn more

Azure Security Audit

Independent audit of your Azure subscriptions and resources

Learn more

Microsoft Entra

Identity and access management solutions

Learn more

Ransomware Protection

Layered ransomware protection for US businesses covering prevention

Learn more

Penetration Testing

Penetration testing for US businesses across external, internal, web

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA