Home / Blog / Security
Security

Securing Active Directory: the critical points of an audit

EntraGUARD·2026-03-31·8 min

On-premises Active Directory remains the backbone of identity for most organisations, and compromising it usually means compromising everything. These are the areas a serious AD audit focuses on first.

Privileged groups

Domain Admins, Enterprise Admins and Schema Admins are the crown jewels. An audit checks who is in them, whether membership is justified, and whether it changes unexpectedly. The guiding rule: these groups should be as small as possible, and no service accounts or day-to-day admin accounts should live in them.

Delegation

Unconstrained and misconfigured delegation is a classic path to privilege escalation. Accounts trusted for delegation — especially unconstrained delegation — can impersonate others, including domain admins. An audit flags where delegation exists and whether it is constrained appropriately.

Kerberos hygiene

Weak Kerberos configuration opens the door to Kerberoasting and related attacks. Key checks include service accounts with weak passwords and SPNs, the health of the krbtgt account, and encryption settings. Rotating krbtgt on a schedule is a control worth confirming.

Password and lockout policy

Password length and complexity, lockout thresholds, and the presence of fine-grained password policies for privileged accounts all shape how resistant the domain is to guessing and spraying attacks. An audit compares your policy against recognised baselines.

Stale and risky accounts

Accounts that never expire, have passwords set to never expire, are inactive but enabled, or use reversible encryption are all findings. Each is a small crack; together they widen the attack surface considerably.

Trusts and structure

Domain and forest trusts extend your security boundary to other domains. An audit reviews which trusts exist, their direction and whether they are still needed — a forgotten trust is an inherited risk.

Hybrid matters. Because AD is often synced to Entra ID, a weakness on-premises can propagate to the cloud. Auditing AD and Entra ID together closes the gap that attackers love to exploit at the hybrid seam.

Turning findings into action

A good AD audit does not just list problems — it ranks them by impact and gives concrete remediation. Start with privileged group membership and delegation (highest impact), then Kerberos and password policy, then clean up stale accounts and unneeded trusts.

Audit your Microsoft environment

Put this into practice. EntraGUARD runs 283 automated controls across Entra ID, Active Directory and Azure — try the free demo.

Download the free demo