For the identity estate behind your business
Active Directory often connects long-lived servers, user accounts and business applications. A cloud identity review may leave that estate only partly understood. Directory administrators, IT leaders and service partners need an account of the configuration and privileges that remain on premises.
Use an audit to establish a baseline, review an inherited domain or prepare a hardening programme. Agree the domains, approved collection hosts and important services first, so the findings can be considered in their operational context.
What the audit can examine
The on-premises collector supports domain and trust information, user and computer settings, privileged-group membership, password-policy configuration and directory access controls. Supported sections also examine Group Policy, SYSVOL exposure and certificate-services configuration where the required components are available.
Host context can include domain-controller hardening, supported protocol settings, patching, endpoint protection and firewall profiles. These sources help distinguish an identity issue from a related host configuration problem and give administrators a more useful starting point for remediation.
Findings with their supporting context
ThreatShield analyses submitted audit sections and retains the evidence behind the findings. The resulting review can identify affected accounts, policies or hosts, explain the observed condition and propose the next investigation or hardening step.
An exposed permission or certificate-template configuration is a posture finding. It does not by itself prove that an attacker used it. Activity evidence and further investigation are needed to assess suspected compromise. Collection failures and skipped sections should remain part of the report rather than disappear from the conclusion.
How collection and follow-up work
Confirm the collection host, permissions and available Windows modules before the audit. Active Directory and Group Policy sections depend on their respective modules and access to the relevant environment. The collector can run on supported Windows systems, but the evidence available from a member host and a domain controller can differ.
Review the completed sections, prioritise findings with the responsible administrator and plan authorised changes around service dependencies. A later collection provides evidence for follow-up. Sensitive password-quality auditing is a separate, explicit opt-in activity with additional prerequisites; it is not part of every routine scan.
Questions about Active Directory security audit
Does this include Group Policy and AD CS?
Supported checks include Group Policy and Active Directory Certificate Services. Actual coverage depends on the components present, collection modules, permissions and agreed scope.
Is an Active Directory audit a penetration test?
This capability assesses collected configuration and available activity evidence. It does not establish that exploitation has been attempted or that every possible attack path has been tested.
Can it support a hybrid Microsoft environment?
On-premises audit findings can be considered alongside Microsoft 365 and Entra ID assessment evidence. Each collection path has its own scope and access requirements.
