Group Policy is your
actual control plane.
See how it really resolves.
Security Configuration Management (SCM) for Active Directory is the continuous audit of AD's configuration plane: Group Policy, domain controller hardening, and the precedence rules that decide what actually applies. Retrievy SCM for Active Directory audits the configuration plane that GPMC reports never reach: LSDOU-compliant precedence resolution, per-GPO blast radius, 55 CIS hardening checks against the Domain Controller, and Tactical Mutation Alerts on every drift event.
GPO X-Ray. Resolved settings, conflict highlights, blast radius panel.
GPMC was never enough.
The standard Group Policy Management Console shows you the GPOs, sorted by OU. It doesn't show you which setting actually wins after LSDOU resolution. It doesn't show you which assets a GPO impacts. It doesn't tell you when a registry value silently flipped after last week's patch.
Server-hardening regression is the worst kind: it accumulates quietly between Pen Tests, and the next finding is six months old by the time anyone reads the report.
Retrievy SCM for AD continuously walks the config plane and renders the truth.
One MSI.
Both modules.
The Retrievy Windows agent feeds both ISPM and SCM-AD. Install once; both lenses light up.
Thin collector by design. The agent only collects data and ships it (encrypted) to the Retrievy platform. All analysis runs server-side, so the agent stays small and the host stays quiet.
~40 MB MSI
Single-file, code-signed package. No .NET runtime prerequisite on the target.
Token onboarding
Paste an install token from the dashboard. The agent self-registers on first heartbeat. Done.
Outbound HTTPS only
No inbound ports, no exposed services. Works through corporate proxies.
Daily collection @ 00:01
Configurable. Heartbeats every five minutes; missed heartbeats escalate to the dashboard.
Encrypted credentials
Sealed to the host machine. Tokens rotate automatically every 90 days.
AES-256 offline queue
Connectivity blip? Data caches encrypted on disk and retries automatically.
Code-signed auto-update
The agent updates itself in place. You install once.
Read-only by design
LDAP queries use the host's Kerberos machine credentials. No service account, no LDAP password to manage. The agent never writes a GPO, never modifies a registry key, never touches the directory.
Seven audits,
the whole control plane.
LSDOU precedence, resolved.
Precedence resolution surfaces conflicts across enforced/non-enforced links, block-inheritance OUs, and disabled link slots. The conflicts GPMC silently swallows.
"If I change this GPO, who's affected?"
Exact asset count impacted by each policy. Click a GPO, see the user and computer set it actually applies to, including the assets pulled in by inheritance, not just the OU it links to.
DC host hardening, against the CIS benchmark.
The agent reports the Domain Controller's hardening posture against the CIS benchmark: registry, account policy, advanced audit policy, user-rights assignment, security options, secedit baseline. Every check is tied to a CIS Control ID and rolls into the SCM score.
The baseline most environments never re-check.
Domain functional level, SMB signing on DCs, LDAP signing & channel binding, password & account-lockout policy, audit policy baseline, FSMO placement sanity. The post-migration hygiene checklist nobody returned to.
Tactical Mutation Alerts.
Configuration changes are grouped into 30-minute windows with field-level detail. Email alerts when policy changes outside a maintenance window. Routine patching produces zero drift; a real change produces a real alert.
Privileged-group ACL anomalies.
Membership churn on AdminSDHolder-protected groups. ACL anomalies on the SDH set. The exact targets of an attacker's persistence playbook.
Read-only by design.
LDAP queries use the DC's Kerberos machine credentials, no service account required. Read-only registry and WMI on the Domain Controller. Outbound HTTPS only. The agent never has the privilege to break what it's auditing.
Registry path, GPO path,
PowerShell. All on the card.
Verifies that Domain Controllers require SMB packet signing. Without enforcement, an attacker can relay NTLM authentication captured from any client and gain DC-level privileges (NTLM relay → DCSync).
HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters
RequireSecuritySignature = 1 (DWORD)
Computer Config → Policies → Windows Settings →
Security Settings → Local Policies → Security Options →
"Microsoft network server: Digitally sign communications (always)"
→ Enabled
- → Microsoft Learn · SMB signing
- → CIS Microsoft Windows Server 2.3.8
- → MITRE ATT&CK T1557.001 · LLMNR/NBT-NS Relay
Every finding ships with the registry path, the GPO setting path, and the equivalent PowerShell. The engineer fixing it doesn't need a CIS PDF on a second monitor.
Findings flow Triage → Verifying → Hardened. The "Trust but Verify" rule means only the next scan can promote a finding to Hardened. Audit trail intact.
Group findings.
Ship a sprint.
Some fixes are quick. Others are quarterly initiatives. Multi-finding cleanup work that needs an owner, a deadline, and an audit-ready report at the end. That's a Remediation Project.
One project, many findings.
Bundle related findings under a single project. Use it for "deprecate every Kerberoastable account this quarter", "remediate the EU cloud baseline before audit season", or "clean up the FortiGate rule debt".
Owner. Deadline. Observation log.
Each project has an accountable owner, a target date, and a chronological observation log: who changed what, when, and why. The audit trail is intact by default.
Auto-generate a PDF on close.
When the project closes, Retrievy renders a PDF report. Scope, finding inventory, before-and-after posture, observation timeline. Hand it to your auditor without writing a single line.
Trust but Verify, project-wide.
Findings inside a project still follow the scan-verified status model. The next scan promotes them to Resolved. The project closes when every finding it contains is verified.
Four frameworks, one config finding.
Every Domain Controller, GPO and RBAC finding rolls up to the international benchmarks, the federal control catalog, and the proprietary hardening guide built from years of incident response.
CIS Windows Server 2016 v4.0.0, 2019 v4.0.0, 2022 v5.0.0 and 2025 v2.0.0 (Domain Controller profile). Level 1 and Level 2 controls tied to each finding via the official CIS Control ID.
Govern, Identify, Protect, Detect functions, with SP 800-53 Rev 5 controls (Access Control, Identification and Authentication, Audit and Accountability families) layered alongside.
T1557 (Adversary-in-the-Middle), T1484 (Group Policy Modification), T1003 (Credential Dumping), T1098 (Account Manipulation), T1078 (Valid Accounts) and adjacent AD-specific techniques surfaced where applicable.
Proprietary 32 check engine: delegation abuse, Kerberoasting exposure, DC hardening, domain policy drift, and shadow Tier Zero. Catches the operational risk the standards do not name.
SCM for AD, answered.
See your config plane
as it actually resolves.
Install the agent in five minutes. The first GPO X-Ray and CIS hardening report appear the same day.
Try everything free for 14 days on your own data. Request your trial code. No credit card required.