Active Directory Security Assessment
Active Directory is often the most critical system you run — if it is compromised, the entire environment usually is. We analyse your AD in depth and test every user password offline against known wordlists — with zero operational impact, as an independent third party with no vendor interests.
The Active Directory Security Assessment is an independent, in-depth analysis of your on-premises AD — including an offline test of every user password against known wordlists. It is for organisations where AD remains the backbone. You get a thorough report with prioritised findings and actionable recommendations. Typically 2–3 weeks, read-only with zero operational impact, fixed price after a free pre-analysis. Unlike the Privileged Access Review, it covers the entire environment.
What the assessment covers
- Domain controllers, Windows security, updates and replication
- GPOs, security groups, OU structure, Sites & Services
- Domains & Trusts, FSMO roles, DNS and delegations
- Admin and service accounts, account administration and inactive accounts
- LDAP security and password policies
- Offline password penetration test of the AD database
What you get
- Thorough report with findings prioritised by risk
- Excel data extract with account overview
- Concrete, actionable recommendations
- Typically 2–3 weeks from start to report
Out of scope
- Not remediation or continuous monitoring
- No active exploitation beyond the agreed offline password analysis
- Unilite
- Cadpeople
- Kunde & Co
- Bitcoin Suisse
- Mercantec
- Dagrofa
- Laursens Realskole
- Zug Kommune
- Altid Vikar
- Adeo Datacenter
- A&O Kreston
- Numarics
- Geelmuyden Kiese
The assessment we received deserves a 10 out of 10 without hesitation.
80+ certifications — CISSP, CISM, CISA, ISO 27001 · More about Martin →
How it works
Free pre-analysis
We assess the scope and give you a fixed price. No obligation, no surprises.
Read-only data collection
Automated extracts via PowerShell and Graph — zero operational disruption.
Analysis & assessment
Manual specialist review with risk prioritisation and business context.
Report & plan
An executive summary for leadership, technical depth for your team — ready to act on.
Practicalities
Free and without obligation — we are given read access and assess the scope so that we can give you a fixed price.
Typically a kick-off meeting of about an hour plus setting up read access. We do the rest.
Read-only data collection — no changes to your systems and no operational disruption.
A written report with prioritised recommendations, data extracts in Excel where relevant — and a walkthrough of the results at both management and engineering level.
Frequently asked questions
Is the offline password test safe?
Yes. The test runs offline on a copy of password hashes following an agreed procedure — it never touches your production environment and does not expose plaintext passwords beyond what is agreed.
Why test passwords at all?
Weak and reused passwords remain one of the most exploited attack paths. The test shows exactly how widespread the problem is in your organisation — documented and measurable.
What does an Active Directory security assessment cost — and why isn't the price listed here?
Because no two companies — or system landscapes — are alike, and a fixed price list would be either too high for some or too vague for all. Instead, we always start with a free, no-obligation pre-analysis. After that you usually get a fixed price with no surprises — and where a fixed price isn’t possible, an estimate we stand behind and keep.
Ready to have your security verified by an independent third party?
A free, no-obligation pre-analysis. A fixed price. A concrete plan you can act on right away.
Get a free pre-analysis