Identity

On-Premises AD AuditNew

Provides comprehensive security auditing of your on-premises Active Directory environment — detecting misconfigurations, weak policies, privileged account risks, and lateral movement paths that attackers routinely exploit.

On-Premises AD Audit

Deep security auditing for Active Directory

What it does

Key capabilities

Privileged Account Audit

Identifies over-privileged accounts, dormant admin accounts, and accounts with sensitive delegation that widen your attack surface.

Misconfiguration Detection

Flags dangerous AD misconfigurations — Kerberoastable accounts, AS-REP roasting targets, unconstrained delegation, and DCSync rights.

Password Policy Assessment

Audits domain password policies and fine-grained password policies for compliance with security baselines and best practices.

Lateral Movement Path Analysis

Maps privilege escalation and lateral movement paths attackers could use to reach domain administrator from standard user accounts.

Change Monitoring

Tracks changes to AD objects, group memberships, and GPOs — with alerting on high-risk modifications in real time.

AD Security Report

Export a comprehensive AD security audit report for compliance evidence, remediation prioritisation, and board-level risk reporting.

Highlights

Why On-Premises AD Audit?

  • Kerberoasting, AS-REP roasting, and delegation attack path detection
  • Privileged and dormant account auditing
  • Password and GPO policy compliance assessment
  • Lateral movement path visualisation from any user to DA
  • Change monitoring with high-risk modification alerting
Included in OneView

On-Premises AD Audit is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.

24/7 Support Available
Phone: +27 060 984 1210
FAQs

Frequently asked questions

The module detects the most commonly exploited AD attack paths: Kerberoastable accounts (SPNs assigned to user accounts with weak passwords), AS-REP roasting targets (accounts with pre-authentication disabled), unconstrained Kerberos delegation (computers that can impersonate any user), DCSync rights (accounts with replication permissions), and AdminSDHolder misconfigurations.

AD Audit analyses group memberships, delegation settings, and access control lists across your directory to identify privilege escalation paths — chains of permissions that would allow an attacker who has compromised a standard user account to reach Domain Admin through a sequence of legitimate AD relationships. These paths are visualised for analyst review.

Yes. AD Audit includes continuous change monitoring for high-risk AD modifications — changes to Domain Admins or Enterprise Admins group membership, modifications to GPOs linked to tier-0 assets, changes to AdminSDHolder permissions, and SPN additions to user accounts. High-risk changes generate immediate alerts via the Event Manager.

ISO 27001 Annex A.8.18 and A.5.15 require privileged access management and identity governance. AD Audit's privileged account review, attack path analysis, and password policy assessment directly address these controls — providing documented evidence that your AD environment is hardened and that privileged access is properly controlled and audited.

See On-Premises AD Audit in action

Request a personalised demo and we'll show you exactly how On-Premises AD Audit works within your environment.