Active Directory Security Audit
Fixed project price from 8,400 €, no hourly billing
30 minutes, no preparation needed. You will receive a written offer within a few working days.
Martin Grottenthaler, Founder and Lead Penetration Tester. OSCP, CISSP, GCFA, GWAPT. Pentesting since 2017.

Diese Seite ist auch auf Deutsch verfügbar.
An Active Directory Audit is a white-box security assessment of your on-premises Active Directory that identifies misconfigurations, dangerous permissions, and attack paths leading to domain takeover, before an attacker or ransomware can exploit them.
The ransomware attacks with the biggest impact run through Active Directory: whoever takes over the domain controls every system and every file in the company. A single forgotten permission or an old misconfiguration is often all it takes. These are exactly the vulnerabilities this audit uncovers, before an attacker finds them.
This audit focuses on on-premises Active Directory. Entra ID (Microsoft’s cloud identity platform) is a different system and is covered by a separate Entra ID Audit.
Scope
This type of test is typically performed as white-box, meaning that the testers receive full access to the tested system and its documentation. This allows a comprehensive analysis of vulnerabilities and misconfigurations in a short time frame. These are the main focus points of the test:
- Audit of the implementation status of the tier model and possible vulnerabilities
- Review of all accounts and their password age
- Review of the permissions of users, computers, and groups
- Review of group memberships of highly privileged groups
- Interview with administrators on how they typically administer the system
- If present: domain and forest trusts
- Test for typical vulnerabilities like “Kerberoasting” or (un)constrained delegation
Why
- Whoever takes over Active Directory controls every system and every file in the company. That is exactly why ransomware groups target it first
- A single forgotten permission from an old project can be the missing link in an attack path to Domain Admin
- Active Directory grows over years and administrators change; only a regular review finds the misconfigurations that accumulate
For a comprehensive assessment of the on-premises Active Directory, VidraSec recommends conducting this analysis in conjunction with a penetration test of the internal infrastructure. This approach offers a complete overview of your internal systems’ security posture, and booked as a single combined engagement, the two tests share scoping and setup overhead.
Why VidraSec 🦦
Martin Grottenthaler, Founder and Lead Penetration Tester. OSCP, CISSP, GCFA, GWAPT. Pentesting since 2017. More about me
I have multiple years of experience attacking and securing Active Directory. If I manage to get Domain Admin permissions after a few days of work, I am sure a real attacker can also do it. Thus, let me demonstrate what is wrong and how to fix it to protect yourself against attacks.
Typical Duration
3-5 days (scope-dependent). Reporting takes roughly 30-50% of the test time on top.
Typical Price
from 8,400 €
The final price depends on the scope and is calculated from the planned effort, which the offer itemizes transparently (person-days times daily rate). The offer total is the final price: if the actual effort ends up a little over or under the estimate, the price stays the same.
Not sure whether this fits your environment? In a free 30-minute call you get an honest assessment.
Deliverables
Every engagement includes:
- Written findings report with all vulnerabilities and misconfigurations, prioritized by severity, with remediation steps
- Management summary tailored to your audience (technical or executive)
- Live debriefing to walk through findings and answer questions
- Retesting after remediation available on request
See example reports for what a VidraSec report looks like.
Compliance
Directly relevant for NIS2, ISO 27001, and TISAX (automotive industry). Active Directory security is a standard checkpoint in information security management audits.
Frequently asked questions
What is the difference between an Active Directory Audit and an internal penetration test?
An Active Directory Audit is a white-box configuration review with full read access. An internal penetration test attacks Active Directory from a normal user’s perspective to see whether Domain Admin is reachable. They are complementary and are often combined for a complete picture.How long does an Active Directory Audit take?
Typically 3 to 5 days of analysis depending on the size of the environment, plus roughly 30 to 50 percent of that time for reporting.Will the audit disrupt our production Active Directory?
No. The audit is read-only and white-box. VidraSec reviews configuration and permissions without making changes or running disruptive attacks against your domain controllers.How much does an Active Directory Audit cost?
From 8,400 euros. The final price depends on the scope and the maturity level of your environment and is calculated individually based on the required effort.How does the fixed price work?
The offer itemizes the planned effort transparently (person-days times daily rate), so you see exactly how the price is calculated. The offer total is the final price: if the actual effort ends up a little over or under the estimate, the price stays the same, and you always receive the full agreed deliverables.More questions on pricing, lead times, NDAs, or compliance: see the general FAQ

