Back to category

Week 1

Conduct an Active Directory Security Assessment

Beginner
IAM Engineer
CIS Controls
Active Directory

Client Background

Evergreen Credit Union is a community credit union (40,000 members, 180 employees) running a single-forest Active Directory domain built over a decade ago. After a rapid merger with a smaller credit union, the security lead worries that group sprawl, stale accounts, and inherited admin delegations are silently expanding the attack surface and wants an independent assessment before an NCUA examination.

Business Environment

Operations span 12 branches and a small data center, with tellers, loan officers, and admins all on the same domain. A flat OU structure with default permissions has grown organically and the AD environment has never been externally assessed; IT is a six-person team, and Entra ID sync covers cloud apps but the authoritative identity store remains on-prem.

Security Incident

No breach; the engagement is a proactive assessment. The trigger was the post-merger integration surfacing multiple legacy Domain Admin accounts and unmanaged service accounts, plus an upcoming NCUA examination that historically scrutinizes IAM hygiene.

Scope

Full Active Directory forest assessment covering user accounts, group memberships, privileged and administrative accounts (Tier-0/1/2 model applicability), stale and orphaned accounts, password and authentication policy, Kerberos configuration, and OU/GPO delegation. Excludes cloud-only Entra ID configuration and live exploitation.

Objectives

  • Understand Active Directory fundamentals
  • Identify inactive and stale accounts
  • Review privileged groups
  • Evaluate password policies

Required Deliverables

Active Directory Security Assessment Report
2 hrs estimated