SaaS EDL Feeds Threat Intel Security Tools Config Audit Consulting About
✅ Cisco IOS/ASA/Firepower✅ Palo Alto PAN-OS✅ FortiGate FortiOS ✅ pfSense / OPNsense✅ Check Point✅ Juniper SRX 🔒 Config never stored or transmitted⚡ Results in under 60 seconds 🏆 NSA · CIS · NIST compliance checks🌍 Used by MSPs worldwide ✅ Cisco IOS/ASA/Firepower✅ Palo Alto PAN-OS✅ FortiGate FortiOS ✅ pfSense / OPNsense✅ Check Point✅ Juniper SRX 🔒 Config never stored or transmitted⚡ Results in under 60 seconds 🏆 NSA · CIS · NIST compliance checks🌍 Used by MSPs worldwide

Automated Windows Active Directory
Security Audit

Run our free PowerShell export script on any Domain Controller, upload the results, and get a scored AD security report in under 60 seconds. Every finding mapped to the CIS AD Benchmark and Microsoft's AD Tiering Model — with exact PowerShell remediation commands.

🚀 Audit My Active Directory ⬇ Download Export Script 📄 View Sample Report ⬇️ Download Sample AD Export

What the AD Audit Checks

Run the export script as a Domain Admin — it reads AD configuration and account metadata only, never passwords, hashes, or file contents.

👑

Privileged Groups

Domain Admins and Enterprise Admins membership size — flags standing over-privileged access that expands your attack surface.

🎫

Kerberos Security

krbtgt password age (Golden Ticket risk), Kerberoastable service accounts, and unconstrained delegation exposure.

🔑

Password Policy

Minimum length, complexity, lockout threshold, reversible encryption, and accounts with never-expiring or blank passwords.

🕸️

Stale Accounts

Inactive user and computer accounts (90+ days) left enabled — unmonitored attack surface from former employees and forgotten systems.

🛡️

Hardening & Recovery

LAPS deployment, AD Recycle Bin, SMBv1 exposure, anonymous LDAP/SAM access, and end-of-life Domain Controllers.

🤝

Trusts & GPOs

External/forest trust SID filtering and unlinked/orphaned Group Policy Objects that suggest weak change management.

Common AD Findings We Catch

Criticalkrbtgt Password Not Rotated in 180+ DaysMITRE ATT&CK T1558.001
An old, unrotated krbtgt password hash enables Golden Ticket forgery if it's ever compromised — an attacker can mint valid Kerberos tickets for any account, indefinitely.

Fix:
✅ Rotate the krbtgt password twice, 24 hours apart, using Microsoft's documented reset script.
HighExcessive Domain Admins MembershipCIS AD Benchmark — Privileged Groups
More than 5 standing members in Domain Admins means more full-domain-compromise paths if any one of those accounts or workstations is breached.

Fix:
✅ Move to just-in-time (JIT) elevation or a PAM solution; limit standing membership to break-glass accounts only.

Audit Your Active Directory Now

Download the script, run it on a DC, upload the results — get a scored report in 60 seconds.

🔒 Start Free Audit
Explore More on AuditXA
Microsoft 365 AuditPalo Alto AuditFortiGate AuditCisco Firewall AuditMSP Firewall AuditsCheck Point AuditSophos AuditSonicWall AuditWatchGuard AuditFree Security ToolsPricing