Securing Active Directory

Assessment

Everything seems to be ok and nobody complains, but there is always room for improvement. Especially when it comes to security.

Unfortunately, an updated operating system and antivirus solution are no longer sufficient to be safe. Assessment help to get an overview about risks, misconfigurations, legacy configurations and optimisations.

Active Directory Assessments

Microsoft RAP as a Service

Microsoft offers a service called “RAP as a Service” where you can choose (not for free!) assessments of multiple technologies. One of their offering is an Active Directory Security RAP. The assessment opens your eyes to what is not optimally configured and fills the task list of every AD responsible. The services is quite good but there is one problem: You need a “Microsoft Premier Support contract”. Not every company has such a contract as they are expensive and third parties offer similar Support offerings.

Give it a try if you’re eligible to use it: https://services.premier.microsoft.com/assess?Culture=en-US

In addition to these paid offers, there are also freely usable tools.

PingCastle

Ping Castle is an Active Directory Security Assessment tool which helps to detect security issues, get an overview of the technical situation and provide guidance and advice’s to fix the issues.

There is a free version available with basic functionalities. The tool scans you Active Directory objects, permissions, GPOs and many more (remote SMBv1 check, specific user permission scan, …) and generates a report against >100 checks to get an indicator of the Domain risk level. Details on all findings can then be remediated by going trough each documentation:

If you need more features, there are three paid version which come with additional benefits:

Give it a try!

https://www.pingcastle.com/

https://github.com/vletoux/pingcastle

Subscribe
Notify of
guest
3 Comments
Newest
Oldest Most Voted
Inline Feedbacks
View all comments
Gioni
Gioni
September 7, 2021 3:00 pm

hello,
are there any companies providing “Active Directory Assessments” services in Switzerland?
I am struggling finding such a company.
Thank you

Gioni
Gioni
September 8, 2021 8:21 am
Reply to  Andi Wirz

thank you