Active Directory Security Audit
Active Directory is the key to almost everything else you own, and in most organisations it has been quietly accumulating accounts, permissions and exceptions for a decade or more. This is a full audit of how yours is actually configured — who really holds administrative power, which accounts an attacker could crack offline, and which forgotten settings would hand over the domain.
Who this is for
- Your Active Directory has grown organically through years of mergers, migrations and quick fixes, and nobody can say what state it is in
- You have had an incident, or a near miss, and the board wants assurance the domain is not still exposed
- You are planning a migration, a hardening programme or a move to hybrid Entra ID, and need a documented baseline to work from
- An insurer, client or framework wants evidence that your directory has been independently reviewed, not just patched
What we test
Coverage runs in depth, not breadth alone — each stage goes past where the one above it stops.
- Tier 0
Privileged access and tiering
Every account with Tier 0 control of the domain, and whether the tiering model that is supposed to protect them exists in practice or only in the design document.
- Kerberos
The ticket-request attack surface
Accounts with Service Principal Names any authenticated user can request a ticket for, and accounts with pre-authentication disabled — offline cracking material available to anyone with a login.
- Delegation
Impersonation paths
Unconstrained delegation on users and computers, separating domain controllers where it is expected from the member servers where it is a standing compromise of every account that touches them.
- Certificates
AD CS misconfiguration
Enrollment services and certificate templates checked for the ESC1, ESC2 and ESC3 misconfigurations that turn a standard user into a domain administrator in a single request.
- Hygiene
Directory hygiene and password policy
Dormant accounts, passwords never set or older than a year, accounts flagged as not requiring a password — assessed against both NIST SP 800-63B and CIS Benchmark positions.
- Boundaries
Trusts and domain configuration
Trust direction, transitivity and SID filtering, LDAP signing enforcement, and machine account quota — the settings that decide whether a neighbouring domain is a boundary or a doorway.
- Scenarios
Built from your data, not a template
Each attack scenario names the accounts actually affected in your directory and carries MITRE ATT&CK technique IDs — so it can be checked against your own telemetry.
What the testing looks like
Our own tooling, built in-house — here is what it shows us.
The tooling




Screenshots show synthetic demo data.
What you get
The package in three parts — what you read, what you act on, and what happens after.
What you read
The numbers leadership asks for, with a plain-English position.
- Executive summary with total users, Tier 0 and Tier 1 counts, computers and groups
- Prioritised attack scenarios modelled from your own directory, each with the chain, impact and ATT&CK mapping
- Sectioned analysis across user security, hygiene, delegation, Kerberos, groups and password policy
What you act on
The account-level data your team needs to actually fix it.
- Complete appendix tables — stale accounts, non-expiring passwords, Kerberoastable and AS-REP roastable accounts, privileged users
- Guidance separating the changes to make this week from the ones that need a project
What happens after
Re-run and evidenced.
- Remediation retest confirming the findings we raised are resolved*
* Free remediation retesting applies to penetration testing engagements. It is subject to the size of the assessment and available for three months from delivery of your report. A web application test is typically covered; a large engagement — an internal test across hundreds of systems, for example — is scoped and quoted, and a full re-assessment is always chargeable.
How it runs

The same six phases, every engagement
Threat Model Development
We agree what the exercise is replicating: the credible threats to your organisation, the starting position, the objectives, and which controls are in scope. It is also where disruption is bounded, so the test does not cost you a working day.
Information Gathering
Enumerating the systems and services actually in play from that starting point, so the attack surface is mapped as it is rather than as the asset register describes it — and choosing tools and techniques that suit it.
Vulnerability Identification
Examining that surface for weakness, using automated tooling for breadth and manual technique for everything a scanner cannot reason about. Neither finds what the other does, which is why the blend is deliberate.
Attack Vector Development
Weighing each weakness against your actual environment — how exploitable it really is, what skill it demands, what it would cost you. The output is the routes that are practical here, not the ones theoretically possible somewhere.
Exploitation
Where it is appropriate, we exploit, which usually opens a fresh attack surface and sends us back round the cycle. Where exploiting would cause harm we verify the finding is genuine rather than a stale banner, and assume the worst case.
Reporting
One document for two audiences: an executive summary your board can act on, and the technical chain your engineers can reproduce step by step, each finding carrying its severity and its remediation.
Prerequisites
- Network access to a domain controller, from a device you provide or one we ship to you
- A standard domain user account — no administrative rights required
- A signed Laneden authorisation form
Frequently asked questions
How is this different from internal infrastructure testing?
Internal infrastructure testing attacks: we take an assumed-breach foothold and try to reach Domain Admin, and the path we take is the finding. This audit enumerates instead, and enumerates everything — every account, every delegation setting, every certificate template, every trust — then assesses it. A penetration test tells you one route in was open. This tells you the full state of the directory, including the exposures nobody happened to walk through that week. They pair well, and many clients run both: see our Internal Infrastructure Testing service at /services/internal-infrastructure/.
What access do you need?
A standard domain user account and network access to a domain controller. That is genuinely all — Active Directory is designed so any authenticated user can read the directory, which is precisely why so much of this is exposed to an attacker who phishes one set of credentials. We do not need Domain Admin, and we would rather you did not offer it.
Will this disrupt our domain controllers?
No. The assessment is read-only: standard LDAP queries of the kind your own management tools make all day. We change nothing, add nothing and delete nothing in the directory, and we agree the window with you before we start.
We have run BloodHound ourselves. Do we still need this?
BloodHound is an excellent graph, and we reference the same edges so you can verify our findings in a tool you already know. What it does not give you is the rest of it — password policy against current standards, certificate template misconfigurations, trust and SID filtering, LDAP signing, directory hygiene — or a prioritised, written assessment your board and your auditor can read. This is the assessment around the graph.
Can you assess a hybrid environment?
Yes. We identify the on-premises side of a hybrid deployment as part of the audit — Entra Connect sync accounts, Seamless SSO, password protection agents and password writeback indicators — because those components are frequently the highest-value targets in the domain and are often overlooked when responsibility is split between teams.
Can you tell us how weak our passwords actually are?
Not from the directory alone — Active Directory will tell us your policy, not whether people work around it. That requires cracking the password hashes offline, which is a separate exercise with a much higher access requirement and much stricter handling. It is our Active Directory Password Audit service, and the two are commonly run together: see /services/password-audit/.
Related services
Active Directory Password Audit
Your password policy says fourteen characters with complexity.
Learn more →
Internal Infrastructure Testing
When an attacker gets past the perimeter — through phishing, a compromised laptop or a rogue device — how far can they go?
Learn more →
Vulnerability Assessment
Not everything needs a full penetration test, and not every budget stretches to one each quarter.
Learn more →
Ready to test your defences?
Tell us about your active directory security audit requirement — we'll come back with a scoped proposal within two working days.
Free remediation retesting* to confirm your fixes (subject to assessment size).
