Active Directory security assessment

A read-only assessment of what your directory permits, who really holds privilege in it, and how that exposure connects to the rest of the estate.

What is examined

MagenX reads Active Directory and reports what the directory says about its own security.

  • Permissions and who really holds them, including rights inherited through nested groups
  • Delegation, Kerberos and NTLM configuration, and service accounts
  • Certificate services templates and enrolment rights
  • Group policy, domain trusts, and local administrator passwords managed by LAPS
  • Dormant privileged accounts that still hold rights

One picture, not four reports

Active Directory is scored alongside Entra ID and Azure, network topology and firewall policy, so a directory weakness is read against what can actually reach it. Attack simulation walks that graph from a chosen foothold and names the single change that closes the most routes.

What you get

A scored posture with the evidence behind each finding, and, where scans are scheduled, an append-only history of what changed between them. Everything installs from one installer on hardware you control, and air-gapped installation is supported.

FAQ

Can it assess more than one domain?

Yes. Additional domains are scanned and scored separately, and presented alongside the primary domain.

How often should an assessment run?

Scans can be scheduled. Repeat scans build an append-only history of the directory, so drift between them stays visible.

Every finding above is evidence you can hand to the person who owns the object.

Get a demo