Assessment
Privileged Access Review
How easily can an attacker go from one compromised account to controlling your entire network? The Privileged Access Review is the focused variant of the AD assessment — sharply focused on privileged access and the shortest paths to Domain Admin.
What the review covers
- Domain/Enterprise Admins, Tier-0 accounts and protected users
- Privileged group memberships — incl. nested and stale accounts
- Unconstrained/constrained delegation, RBCD, AdminSDHolder and dangerous ACLs
- Service accounts with SPNs (Kerberoasting) and accounts without Kerberos pre-auth (AS-REP roasting)
- Password, lockout and Kerberos policies
- Overall assessment of the shortest paths to Domain Admin
What you get
- Written report with prioritised findings
- Recommendations targeting reduced privilege-escalation risk
Out of scope
- The offline password penetration test is part of the full AD assessment — not this variant, unless separately agreed
How it works
01
Free pre-analysis
We assess the scope and give you a fixed price. No obligation, no surprises.
02
Read-only data collection
Automated extracts via PowerShell and Graph — zero operational disruption.
03
Analysis & assessment
Manual specialist review with risk prioritisation and business context.
04
Report & plan
An executive summary for leadership, technical depth for your team — ready to act on.
First step
Ready to have your security verified?
A free, no-obligation pre-analysis. A fixed price. A concrete plan you can act on right away.
Book a free pre-analysis