Give your IT audit or cybersecurity review the depth of a specialist assessment — without building the methodology from scratch.
This ready-to-use Excel audit program takes you through a complete review of an organization’s Active Directory environment: from forest architecture and domain controller health, right through privileged access, password policy, Kerberos exposure, Group Policy, trusts, logging, backup and DC hardening.
Every one of the 95 test procedures across 14 structured sections comes with the exact PowerShell command or management console you need to run it — no guesswork, no separate cheat sheet to hunt for. Just open the tab, run the command, and record what you find.
Built-in Result and Risk Rating drop-downs keep your workpapers consistent from engagement to engagement, a live Dashboard rolls every section’s results into one risk-exposure view, and a dedicated Findings Log turns exceptions into audit-ready findings with recommendations and management responses tracked to a target date.
The standout feature: a User Data Analysis tab. Export your AD user list with the built-in command, paste it in, and watch department-level breakdowns build themselves — password age bands, inactive accounts, policy exceptions and an HR-reconciliation check for leavers still enabled. Most audit programs tell you what to check. This one helps you analyze what you found.
Whether you’re an internal auditor, an IT security consultant, or an MSP running a client security health check, this workbook turns a multi-day scoping exercise into a program you can start using today.
Note: this program covers on-premises Active Directory.
Section Summary
Architecture & Governance · DC Health & Replication · Privileged Access & Admin Groups · User Account Lifecycle · Password, Lockout & LAPS · Service Accounts & Kerberos · Group Policy · Computer Objects & OS · OU Structure, Delegation & ACLs · Trusts · Audit Logging & Monitoring · Backup, Recovery & Recycle Bin · DNS & Time Services · DC Hardening & Patching
1. Architecture & Governance (8 procedures)
Map the forest and domain structure, confirm functional levels aren’t running on outdated legacy settings, verify FSMO role holders, review site/subnet design, and check for hidden directory synchronization to the cloud — so you know exactly what environment you’re auditing before you go deeper.
2. DC Health & Replication (8 procedures)
Run full domain controller diagnostics and replication health checks to confirm every DC is in sync, reachable, and free of the silent replication failures that quietly undermine everything else in AD.
3. Privileged Access & Admin Groups (8 procedures)
Pull recursive membership of Domain Admins, Enterprise Admins, Schema Admins and every other high-privilege group, flag accounts with lingering elevated rights (adminCount=1), and check whether privilege is properly separated from everyday user accounts.
4. User Account Lifecycle (8 procedures)
A single command exports your full user base for analysis — then test for inactive accounts, accounts that never logged on, missing expiration dates on contractor accounts, and reconcile against HR records to catch leavers who were never disabled.
5. Password, Lockout & LAPS (8 procedures)
Review default and fine-grained password policies, lockout thresholds, KRBTGT password age (a common ransomware-recovery gap), accounts with never-expiring or blank passwords, and whether local admin passwords are managed through LAPS.
6. Service Accounts & Kerberos (7 procedures)
Hunt for Kerberoasting and AS-REP roasting exposure, unconstrained and constrained delegation risks, weak encryption types, and whether service accounts have moved to gMSAs — the section most attackers target first.
7. Group Policy (8 procedures)
Inventory every GPO, catch unlinked and empty policies cluttering the environment, review delegation and permissions, and check applied settings against a recognized security baseline.
8. Computer Objects & OS (5 procedures)
Identify stale computer accounts, unsupported or end-of-life operating systems still joined to the domain, and duplicate or misplaced computer objects.
9. OU Structure, Delegation & ACLs (6 procedures)
Assess whether the OU design supports clean administration, check protection against accidental deletion, and dig into delegated permissions and ACLs for excessive or undocumented access — including the AdminSDHolder object itself.
10. Trusts (5 procedures)
Review every domain and forest trust, confirm SID filtering and selective authentication are configured correctly, and question whether each trust still has a business reason to exist.
11. Audit Logging & Monitoring (7 procedures)
Confirm advanced audit policy is properly configured, logs are retained and forwarded to a SIEM, and pull the specific event IDs that reveal privileged group changes, lockouts, and suspicious Kerberos activity.
12. Backup, Recovery & Recycle Bin (5 procedures)
Verify the AD Recycle Bin is enabled, system state backups are completing, DSRM passwords are documented, and — critically — that a restore has actually been tested in the last year.
13. DNS & Time Services (5 procedures)
Check DNS zone security and dynamic update settings, scavenging configuration, and time synchronization — foundational services that, when broken, break Kerberos authentication across the whole domain.
14. DC Hardening & Patching (7 procedures)
Confirm patch currency, SMB/LDAP signing, NTLM restrictions, and that domain controllers aren’t running unnecessary services like Print Spooler that have been the entry point for real-world domain compromises.








Reviews
There are no reviews yet.