Active Directory security assessment

Domain: corp.internal · Fictional organization, isolated lab · Report generated 2026-09-29

Draft — pending lab results. Scores and fixes are not yet measured; this document shows the assessment plan and expected findings.

1. Executive summary

The assessment plan expects 11 findings in the baseline domain; 11 still open. 2 rated critical: each could lead to full control of the domain.

SeverityFindingsOpen
Critical22
High66
Medium33
Low00

2. PingCastle score

PingCastle risk points: lower is better. Maturity level: higher is better.

MetricBeforeAfterChange
Global score (lower is better)PendingPendingPending
Stale objectsPendingPendingPending
Privileged accountsPendingPendingPending
TrustsPendingPendingPending
AnomaliesPendingPendingPending
Maturity level (higher is better)PendingPendingPending

3. Findings

F01 — Service account is a member of Domain Admins (critical)

Evidence: Expected: PingCastle privileged-group rules; BloodHound shows svc-app as a path to Domain Admins

Business impact: Anyone who compromises the application or its host controls the whole domain.

Remediation: Replace the account with a group-managed service account (gMSA) that holds only the rights the app needs.

Status: open

F09 — Domain administrators log on to workstations (no tiering) (critical)

Evidence: Expected: BloodHound sessions of Domain Admins on ws01/ws02

Business impact: Compromising any workstation can expose domain-admin credentials.

Remediation: Tiered administration with separate admin accounts and logon restrictions per tier.

Status: open

F02 — Service account password never expires and is years old (high)

Evidence: Expected: PingCastle stale/privileged rules for passwords that never expire

Business impact: A leaked or guessed password stays valid indefinitely.

Remediation: gMSA passwords are 120 characters and rotated automatically by the domain.

Status: open

F03 — Same local Administrator password on every machine (no LAPS) (high)

Evidence: Expected: PingCastle LAPS rule; Policy Analyzer shows no LAPS policy

Business impact: One stolen local password gives administrator access to every workstation and server.

Remediation: Deploy Windows LAPS so each machine has a unique, rotated password stored in AD.

Status: open

F04 — SMBv1 enabled on the file server (high)

Evidence: Expected: PingCastle SMBv1 rule for app01

Business impact: An obsolete protocol with known critical vulnerabilities and no modern protections.

Remediation: Disable SMBv1 and require SMB signing.

Status: open

F05 — NTLMv1 and LM authentication allowed (high)

Evidence: Expected: PingCastle NTLMv1 rule; Policy Analyzer LmCompatibilityLevel below 5

Business impact: Captured authentication exchanges can be cracked or relayed easily.

Remediation: Set LmCompatibilityLevel to 5 (NTLMv2 only, refuse LM and NTLM).

Status: open

F07 — Helpdesk group can reset passwords of administrator accounts (high)

Evidence: Expected: BloodHound shows GG-Helpdesk → ForceChangePassword → adm.app → AdminTo → app01

Business impact: A compromised helpdesk account takes over a Tier 1 admin account, and every server it administers, in one step.

Remediation: Remove the delegation from the Admin OU; delegate helpdesk rights only on user OUs.

Status: open

F11 — Print Spooler running on the domain controller (high)

Evidence: Expected: PingCastle spooler-on-DC rule

Business impact: A service with a history of critical vulnerabilities, exposed on the most sensitive server.

Remediation: Stop and disable the Print Spooler on domain controllers.

Status: open

F06 — LDAP signing and channel binding not required (medium)

Evidence: Expected: PingCastle LDAP signing / channel binding rules

Business impact: LDAP traffic to the domain controller can be tampered with or relayed.

Remediation: Require LDAP server signing and always enforce channel binding.

Status: open

F08 — Stale enabled user and computer accounts (medium)

Evidence: Expected: PingCastle stale-objects rules (inactive > 90 days)

Business impact: Forgotten accounts are unmonitored entry points.

Remediation: Review, then disable accounts inactive for more than 90 days.

Status: open

F10 — Weak domain password and lockout policy (medium)

Evidence: Expected: PingCastle password-policy rules; Policy Analyzer minimum length below baseline

Business impact: Short passwords and no lockout make guessing attacks practical.

Remediation: Minimum length 14, lockout after 10 attempts, stricter fine-grained policy for administrators.

Status: open

4. Remediation plan

FindingSeverityRemediationAutomationStatus
F01 Service account is a member of Domain AdminscriticalReplace the account with a group-managed service account (gMSA) that holds only the rights the app needs.scripts/harden/Convert-ServiceAccountToGmsa.ps1open
F09 Domain administrators log on to workstations (no tiering)criticalTiered administration with separate admin accounts and logon restrictions per tier.scripts/harden/Set-TieredAdminModel.ps1open
F02 Service account password never expires and is years oldhighgMSA passwords are 120 characters and rotated automatically by the domain.scripts/harden/Convert-ServiceAccountToGmsa.ps1open
F03 Same local Administrator password on every machine (no LAPS)highDeploy Windows LAPS so each machine has a unique, rotated password stored in AD.scripts/harden/Enable-WindowsLaps.ps1open
F04 SMBv1 enabled on the file serverhighDisable SMBv1 and require SMB signing.scripts/harden/Disable-LegacyProtocols.ps1open
F05 NTLMv1 and LM authentication allowedhighSet LmCompatibilityLevel to 5 (NTLMv2 only, refuse LM and NTLM).scripts/harden/Disable-LegacyProtocols.ps1open
F07 Helpdesk group can reset passwords of administrator accountshighRemove the delegation from the Admin OU; delegate helpdesk rights only on user OUs.scripts/harden/Set-TieredAdminModel.ps1open
F11 Print Spooler running on the domain controllerhighStop and disable the Print Spooler on domain controllers.scripts/harden/Disable-SpoolerOnDC.ps1open
F06 LDAP signing and channel binding not requiredmediumRequire LDAP server signing and always enforce channel binding.scripts/harden/Set-LdapSigning.ps1open
F08 Stale enabled user and computer accountsmediumReview, then disable accounts inactive for more than 90 days.scripts/harden/Get-StaleAccounts.ps1open
F10 Weak domain password and lockout policymediumMinimum length 14, lockout after 10 attempts, stricter fine-grained policy for administrators.scripts/harden/Set-PasswordPolicy.ps1open

All testing was performed in an isolated lab environment owned by the author. No real organization's data, hostnames or configurations are included.