Skip to content
IDENTITY SECURITY / AD · ENTRA

Active Directory and Entra ID penetration testing

We connect trust relationships, delegation and excessive permissions into attack paths leading to critical systems.

The assessment does not end with weak passwords and GPO settings. We analyse what a compromised account, workstation or application can reach and which relationship enables the next step.

AD · ENTRA ID
Hybrid identity
ATTACK PATHS
Relationship analysis
SAFE PoC
Controlled validation
HARDENING
Risk reduction plan
01 / DECISION CONTEXT

When to test identity

  • 01Before migration, domain consolidation or a major Entra ID rollout.
  • 02After account compromise, an incident or a material administrative change.
  • 03Ahead of assurance, cyber insurance or resilience testing.
  • 04When isolated issues are known but paths to critical assets are not.
02 / TEST SURFACE

Technical scope

01

Active Directory

We assess permissions, delegation and domain configuration.

  • ACLs, privileged groups and tiering
  • Kerberos, SPNs, delegation and RBCD
  • GPO, AD CS, service accounts and secrets
02

Entra ID and Microsoft 365

We test cloud identity and administrative boundaries.

  • Roles, applications, consent and service principals
  • Conditional Access, MFA and recovery methods
  • Synchronisation and hybrid relationships
03

Operational resilience

Weaknesses are connected to detection and response.

  • Lateral movement paths
  • Credential and admin workstation exposure
  • Telemetry, alerts and safe validation options
03 / DELIVERY

How we limit test risk

  1. BR / 01

    Objectives and crown jewels

    We identify accounts, systems and paths with the greatest business impact.

  2. BR / 02

    Relationship analysis

    Approved data is used to model effective permissions, trust and delegation.

  3. BR / 03

    Safe validation

    We do not become Domain Admin for theatre. Minimal proofs, simulations and dedicated test accounts are preferred.

  4. BR / 04

    Attack-path reduction

    Fixes are prioritised by how much they shorten real attack paths, not by raw setting count.

04 / EVIDENCE STANDARD

A service account bridges into privileged administration

ATTACK-PATH MODEL / NO CLIENT DATA

The report presents the chain rather than four disconnected warnings.

This model illustrates the analysis method and does not describe a client environment.

E-1

Excessive ACLs allow service-account modification

E-2

The account is delegated into a higher-trust system

E-3

Admin credentials and workstations are not separated

E-4

The fix removes the relationship, constrains delegation and adds detection

05 / OUTPUT

Outcome

01
Map of material attack paths
Included deliverable
02
Confirmed permission and configuration weaknesses
Included deliverable
03
Evidence without persistence or unnecessary data access
Included deliverable
04
Prioritised AD/Entra hardening plan
Included deliverable
05
Administrator workshop and retest
Included deliverable
06 / QUESTIONS

Common questions

← All services
01Does an AD test require a domain account?+

It depends on the objective. A low-privilege account commonly represents a compromised user; an assumed-breach starting point is also possible.

02Will testing disrupt the domain?+

Destructive activity is excluded. Higher-risk operations require separate approval and dedicated resources or are replaced with a safe proof.

03Do you cover Entra ID?+

Yes. Hybrid assessments cover AD, Entra ID, applications, synchronisation and relationships between both layers.

BR / NEXT STEP

Do you know the real paths to privileged accounts?

We will agree a starting point, crown jewels and a safe validation model.

NDA · clear scope · direct communication