Last updated: June 2026
Active Directory Security Assessment
Identify and remediate critical vulnerabilities in your Active Directory and Azure AD environment.

What is Active Directory Security Assessment?
For small projects and ad-hoc work outside our pre-agreed packages or retainers, our standard hourly rate is $460.

Who Needs Active Directory Security Assessment?
Enterprises with complex Active Directory environments that have never been professionally assessed
Organizations migrating to or managing hybrid Azure AD / Entra ID configurations
Companies that have experienced ransomware, identity-based attacks, or lateral movement incidents
Firms needing to comply with DoD STIG, NIST 800-53, SOC 2, or CMMC Active Directory requirements
Organizations with legacy AD environments accumulated over many years with multiple administrators
Companies concerned about Domain Admin escalation paths that ransomware operators routinely exploit

Ready to get started?
Schedule a free scoping call with our Microsoft Security alumni. Fixed-price proposal within 24 hours.
Our Methodology
Discovery
Mapping your AD forest, domains, trusts, and hybrid Azure AD configuration.
Attack Surface Analysis
Identifying misconfigurations, privilege escalation paths, and legacy vulnerabilities.
Risk Prioritization
Scoring findings by exploitability and business impact.
Remediation Roadmap
Providing specific, step-by-step fixes prioritized by risk.


What You Get with Active Directory Security Assessment
- AD Configuration & Group Policy Review
- Privileged Account & Admin Tier Analysis
- Kerberos & NTLM Attack Surface Assessment
- Azure AD (Entra ID) Security Review
- Conditional Access Policy Evaluation
- Trust Relationship & Forest Security Analysis
- Service Account Audit & Credential Hygiene
- Attack Path Mapping & Lateral Movement Analysis
Active Directory Security Assessment Pricing
Basic AD Assessment
Single-domain environments or a focused configuration review.
- Single Active Directory domain
- Configuration and Group Policy (GPO) review
- Unauthenticated and standard-user testing
- Privileged account and escalation-path analysis
- Prioritized vulnerability report with executive summary and remediation steps
Standard AD Assessment
Full documentation audit, technical analysis, and reporting. Typically 5 to 10 days.
- Everything in Basic
- Full documentation and GPO audit
- In-depth technical analysis (Kerberoasting, AS-REP roasting, delegation, DCSync paths)
- Tiering and administrative model review
- Attack-path analysis from standard user to Domain Admin
- Executive and technical reporting with a remediation roadmap
Enterprise / Advanced Review
Multi-site forests, Azure AD / Entra ID integration, and full remediation mapping.
- Everything in Standard
- Multiple domains and multi-site forests
- Azure AD / Entra ID and hybrid identity review
- Estate-wide attack-path analysis
- Full remediation mapping and prioritization
- Retest of fixes included
The final price is driven by the number of domains, forests, and users, and the depth of the technical review, so your quote comes from scoping rather than a list price. Every engagement includes risk analysis (unauthenticated and standard-user testing), a prioritized vulnerability report with an executive summary and remediation steps, and retesting to verify fixes (included on the Enterprise tier, available as an add-on on the smaller tiers). Fixed-price proposal within 24 hours of scoping.

Frequently Asked Questions
Book a Free Consultation
Pick a time that works for you - 30 minutes, no obligation.