Active Directory Security Assessment
Active Directory is often the crown jewel — and a compromise here usually means a compromise of the entire environment. We analyse your AD in depth and test every user password offline against known wordlists, without any impact on operations.
What the review covers
- Domain controllers, Windows security, updates and replication
- GPOs, security groups, OU structure, Sites & Services
- Domains & Trusts, FSMO roles, DNS and delegations
- Admin and service accounts, account administration and inactive accounts
- LDAP security and password policies
- Offline password penetration test of the AD database
What you get
- Thorough report with findings prioritised by risk
- Excel data extract with account overview
- Concrete, actionable recommendations
- Typically 2–3 weeks from start to report
Out of scope
- Not remediation or continuous monitoring
- No active exploitation beyond the agreed offline password analysis
How it works
Free pre-analysis
We assess the scope and give you a fixed price. No obligation, no surprises.
Read-only data collection
Automated extracts via PowerShell and Graph — zero operational disruption.
Analysis & assessment
Manual specialist review with risk prioritisation and business context.
Report & plan
An executive summary for leadership, technical depth for your team — ready to act on.
Frequently asked questions
Is the offline password test safe?
Yes. The test runs offline on a copy of password hashes following an agreed procedure — it never touches your production environment and does not expose plaintext passwords beyond what is agreed.
Why test passwords at all?
Weak and reused passwords remain one of the most exploited attack paths. The test shows exactly how widespread the problem is in your organisation — documented and measurable.
Ready to have your security verified?
A free, no-obligation pre-analysis. A fixed price. A concrete plan you can act on right away.
Book a free pre-analysis