Reduce privileged AD exposure in 3 weeks with a scored assessment and a costed Entra ID plan.
Built for the IT Director or CISO who inherited a twenty-year-old Active Directory with unknown privileged accounts and a cyber-insurance questionnaire asking about tiered administration. This engagement will reduce privileged account exposure and lower the identity attack surface before an attacker or an auditor finds it first.
Who this is for
IT and security leaders running an Active Directory forest older than five years, particularly after a merger, a ransomware scare, or a failed cyber-insurance renewal. The buying committee is the IT Director who owns the domain, the CISO carrying the risk, and increasingly a compliance officer responding to an insurer or a regulator asking specifically about privileged access management.
What we deliver
- A full privileged access review: every account in Domain Admins, Enterprise Admins, and every group nested inside them, with last-logon evidence, service account mapping, and a tiering proposal.
- Attack path analysis covering Kerberos unconstrained and constrained delegation, AS-REP roastable and Kerberoastable accounts, SID history, ACL misconfiguration, and certificate services templates that permit escalation.
- Hybrid identity posture: Entra Connect sync scope and health, password hash sync versus federation, seamless single sign-on, and what breaks on the path to Entra ID.
- A prioritized, costed remediation plan separating what to fix this month, this quarter, and this year, with a written business case for the Entra ID target state.
Outcomes our customers see
A 4,000-seat customer found 47 accounts with unconstrained delegation and reduced Domain Admin membership from 31 accounts to 4 within 30 days of the report. One assessment identified 2,300 stale computer objects and 180 dormant privileged service accounts, 14 percent of the total account population, none of which had authenticated in over a year. Customers have used the resulting evidence pack to close cyber-insurance renewal questions in a single cycle, cutting the clarification round trip from 21 days to 5 days.
How this compares
A tooling scan produces a 400-page export nobody reads. This assessment produces a ranked remediation plan with effort estimates against your actual estate, delivered by engineers who then have to live with the recommendations. Compared with a generic penetration test, the scope here is the identity plane specifically, which is where the majority of ransomware escalation actually happens, and the output is a costed roadmap rather than a findings list.
Architecture and Microsoft alignment
Assessment tooling runs read-only inside your environment against Active Directory Domain Services, Microsoft Entra Connect, and Active Directory Certificate Services where present. Findings are mapped to the Microsoft Enterprise Access Model and the Entra ID tiered administration topology. Where Microsoft Defender for Identity is licensed, its signal is folded into the attack path analysis. No agent is installed on domain controllers and no data leaves your tenant without written approval. Aligned to the Microsoft solution plays Migrate and Modernize Your Estate and Data Security.
Plans
Plans, prices, and full scope per plan are on the Plans tab of this listing.
Prerequisites
Read access to Active Directory with an account able to enumerate objects and group membership, a domain-joined workstation to run collection from, and Global Reader in Microsoft Entra ID. A named customer identity owner must be available for a kickoff and a findings review session.
Limitations
This is an assessment, not a remediation engagement: fixes are planned and costed here and delivered separately. Non-Microsoft directory platforms, Linux and Unix identity integration, and third-party privileged access management products are out of scope. No exploitation or password cracking is performed, so the output is a configuration and exposure review rather than a penetration test.
How to buy
Buy through the Azure portal, using Get it in Azure portal on this listing, so the purchase is billed through your existing Microsoft agreement. Private offers on request.
Next step
Get it now in the Azure portal, or request a private offer if the scope or the price needs adjusting first.