Skip to content
Active Directory security assessment

Turn an Active Directory security assessment into a continuous hardening cycle.

Retrievy assesses the security state collected from Active Directory and its domain controllers, connects risky identity relationships to configuration evidence, and carries each confirmed issue from detection through remediation and a later verifying scan. It is a posture and hardening workflow, not a generic network vulnerability scan.

The assessment gap

A finding list is not an Active Directory security program.

A quarterly export can show that an account is privileged or that a domain controller setting is weak. It rarely shows how nested membership, Kerberos exposure, delegation, Group Policy, and host configuration combine into the next practical hardening decision.

The other gap appears after the report is delivered. Ownership becomes unclear, evidence is scattered across tickets, and nobody can prove that the correction survived the next configuration change.

Retrievy keeps the assessment tied to collected evidence, remediation ownership, configuration history, and subsequent scans so the work ends with verification rather than a closed spreadsheet row.

Assessment coverage

Correlate identity risk with the controls that shape it.

Each lens answers a different part of the assessment without pretending that one score explains the whole directory.

Privilege and identity exposure

Review direct and nested privileged membership, risky account state, Kerberos-related exposure, selected delegation risks, DCSync evidence, and evidence-backed routes into Tier Zero.

Domain controller hardening

Surface collected host and directory-control gaps such as LDAP and SMB protections plus supported protocol, audit, and other Windows hardening findings.

AD CS and credential controls

Identify supported vulnerable certificate-template conditions, service-account risk, password-policy weaknesses, and whether legacy or Windows LAPS schema support is present.

Group Policy and change

Inspect collected GPO settings and precedence, flag targeted GPO hygiene and delegation issues, and compare snapshots for meaningful policy drift.

What Retrievy examines

Evidence across the directory, not a single scanner category.

Coverage depends on the evidence available to the collector. Retrievy reports partial or unavailable evidence rather than presenting it as a confirmed pass.

Check 01

Privileged membership

Direct members, nested group chains, protected accounts, and standing access to high-value AD groups.

Check 02

Kerberos exposure

Kerberoastable and AS-REP-roastable accounts, weak encryption signals, password age, and krbtgt-related posture checks supported by the AD collector.

Check 03

Delegation and directory control

Unconstrained delegation, selected constrained and resource-based delegation risks, DCSync rights, AdminSDHolder-related control, and dangerous GPO delegation.

Check 04

Certificate services

Supported risky AD CS template conditions, including the selected ESC classes implemented by the collector, without claiming comprehensive AD CS attack coverage.

Check 05

Domain controller protocols

Collected LDAP and SMB protections plus supported Windows protocol, audit, and host-hardening settings that affect domain-controller security.

Check 06

Accounts and local admin controls

Stale computers, inactive or risky administrators, password flags, service-account exposure, and LAPS schema-support signals.

Check 07

Group Policy state

GPO inventory, linked scope, collected setting precedence, hygiene observations, and changes between snapshots.

Check 08

Evidence and ownership

Finding-specific evidence, remediation guidance, assignment state, exceptions, and the scan result that verifies or reopens the work.

Retrievy identity posture dashboard showing Active Directory security findings and remediation priorities
Retrievy identity posture view. Example product data is illustrative.
From assessment to assurance

Detect, prioritize, remediate, and verify in one evidence trail.

  1. 1 Detect

    Collect the current state

    A read-only Windows collector gathers supported directory, identity, host-hardening, and GPO evidence from the environment it can observe.

  2. 2 Prioritize

    Connect exposure to impact

    Severity, privilege reach, account state, affected scope, and shared identity paths help distinguish a dangerous control gap from routine cleanup.

  3. 3 Remediate

    Give the issue an owner

    The finding retains its evidence and guidance while teams assign it, group it into a hardening project, document exceptions, and record the intended correction.

  4. 4 Verify

    Let the next scan prove it

    A later scan checks the security state again. A cleared finding can move to verified resolution; recurring evidence reopens the risk instead of hiding it.

Illustrative example · fictional environment

A nested service account reaches Domain Admins

In this fictional lab, CORP\svc-build is nested through Legacy App Operators and an old administration bridge into Domain Admins. The same account has a service principal name, a non-expiring password, and legacy Kerberos exposure.

Identity
CORP\svc-build
Observed chain
svc-build → Legacy App Operators → Admin Bridge → Domain Admins
Related state
Service principal name; password does not expire; legacy encryption signal
Assessment result
Identity exposure and credential hardening require coordinated remediation

Analysis

The important result is not three unrelated alerts. It is the combined evidence that a roastable service identity has an unintended path into a Tier Zero group.

Remediation

The team reviews the application dependency, removes the unintended nesting, rotates and hardens the service credential, and records the change against the same evidence-backed work item.

Verification

On the next assessment scan, Retrievy checks for the privilege chain and risky account state again. The work is only verified when the collected evidence no longer supports the finding.

Why this is an assessment workflow

Designed for hardening decisions, not vulnerability-volume reporting.

State-aware

The assessment starts from directory and configuration state rather than treating AD as another IP address with open ports.

Evidence-preserving

Findings retain the affected identity or control, collected evidence, rationale, and remediation guidance needed for review.

Relationship-aware

Nested membership and supported privilege relationships add context that a flat privileged-user export cannot provide.

Verification-led

Closing a task is not the final signal. Later scanner evidence determines whether the issue stays resolved or returns.

Related assessment questions

Questions the same evidence can help answer.

  • Which ordinary identities have a collected path into Tier Zero?
  • Which service accounts combine privilege with weak Kerberos or password state?
  • Which delegation and directory-control relationships require review?
  • Which domain-controller protections have regressed?
  • Which GPO changes altered the collected effective setting?
  • Which remediations still need a verifying scan?
Frequently asked

Active Directory Security Assessment, answered.

1. Is this a penetration test or a generic vulnerability scan?
No. Retrievy evaluates supported Active Directory identity and configuration state. It does not exploit the directory, test every attack technique, or replace a scoped penetration test.
2. Does the assessment require Retrievy to change Active Directory?
No. The collector is read-only. Retrievy supplies evidence and remediation guidance, while your team reviews and performs the change through its normal administrative process.
3. Does Retrievy provide complete AD CS attack coverage?
No. The current collector identifies selected vulnerable certificate-template conditions, including supported ESC1 through ESC4 patterns. The page does not claim comprehensive AD CS coverage.
4. Does a LAPS result prove every endpoint is covered?
No. The implemented check establishes whether legacy or Windows LAPS schema support is present. It should not be interpreted as per-computer deployment coverage.
5. How is remediation verified?
A later scan evaluates the relevant state again. If the evidence clears, the finding can move to verified resolution. If it remains or returns, Retrievy keeps or reopens the risk.
Next step

Make the next AD assessment the start of the fix.

Evaluate Retrievy with your own directory evidence and see how findings move from assessment to verified hardening.