Reduce Your Risk

Hardening Active Directory without breaking operations

Fifteen years of Active Directory, in a business that had never had an outage it could blame on it. That is the hard case. Nothing was obviously broken, so nothing had ever been urgent enough to change, and the exceptions had quietly accumulated into a structure nobody would design on purpose.

Service accounts with domain administrator rights because it had been quicker at the time. Group policies layered over each other for a decade. Nested groups several levels deep where nobody could say who ended up with what.

The constraint

The client was clear from the start: production could not stop. Manufacturing ran three shifts, and an authentication problem at two in the morning would cost more than the entire engagement.

That constraint shaped everything. We worked in stages, and each stage had to be provably safe before the next one started.

  • Map the real privilege paths, not the intended ones
  • Change one class of thing at a time
  • Test each change against a day of normal operations before rolling it forward
  • Keep a documented way back at every step

The work

We started with the paths that turned one compromised workstation into the whole domain, because those are the ones an attacker actually uses. Service accounts came first, then the tiering of administrative access, then the policies that had accumulated around both.

The riskiest single change was a service account that eleven systems turned out to depend on. We found that before changing it, which is the entire reason for working in stages.

Where it left them

Administrative access is now separated by tier, service accounts hold only the rights they use, and the privilege paths that mattered are closed.

No downtime, across four months. The team can also now answer a question they could not answer before: who can reach what, and how.

← All customers

If you need help, we're here.

Tell us where you are, and we'll help you find the right first step.

Talk to us