Assessment

Privileged Access Review

How easily can an attacker go from one compromised account to controlling your entire network? The Privileged Access Review is the focused variant of the AD assessment — sharply focused on privileged access and the shortest paths to Domain Admin.

What the review covers

  • Domain/Enterprise Admins, Tier-0 accounts and protected users
  • Privileged group memberships — incl. nested and stale accounts
  • Unconstrained/constrained delegation, RBCD, AdminSDHolder and dangerous ACLs
  • Service accounts with SPNs (Kerberoasting) and accounts without Kerberos pre-auth (AS-REP roasting)
  • Password, lockout and Kerberos policies
  • Overall assessment of the shortest paths to Domain Admin

What you get

  • Written report with prioritised findings
  • Recommendations targeting reduced privilege-escalation risk

Out of scope

  • The offline password penetration test is part of the full AD assessment — not this variant, unless separately agreed

How it works

01

Free pre-analysis

We assess the scope and give you a fixed price. No obligation, no surprises.

02

Read-only data collection

Automated extracts via PowerShell and Graph — zero operational disruption.

03

Analysis & assessment

Manual specialist review with risk prioritisation and business context.

04

Report & plan

An executive summary for leadership, technical depth for your team — ready to act on.

First step

Ready to have your security verified?

A free, no-obligation pre-analysis. A fixed price. A concrete plan you can act on right away.

Book a free pre-analysis