Logo icône Board of Cyber Active Directory - AD Rating®

Continuously audit your Active Directory security

AD Rating

Microsoft reports 95 million attack attempts targeting Active Directory accounts every single day. Taking control of a Microsoft domain controller often means taking control of the entire information system. Cybercriminals exploit vulnerabilities and misconfigurations across numerous attack paths to escalate privileges and reach critical resources.

AD Rating® enables you to:

  • Monitor your Microsoft Active Directory security with a 0–1,000 score and dashboards tailored to every audience
  • Continuously identify critical vulnerabilities, misconfigurations, and attack paths across your domain controllers
  • Detect privilege escalation opportunities, lateral movements, and compromise scenarios before they are exploited
  • Prioritize remediation actions with a clear criticality and severity level
  • Cover multi-domain and multi-forest environments, whether for a single organization or an international group

Why monitoring your Active Directory security is essential

Microsoft Active Directory domain controllers centralize the management of identities, access rights, and critical permissions across the entire organization. This central role makes them the primary target for cybercriminals: compromising the directory service opens unrestricted access to the entire information system.

The market has taken notice: according to the CESIN 2025 Barometer, 92% of large enterprises have deployed or are planning to deploy an Active Directory security posture monitoring solution. The question is no longer whether AD needs to be secured, but how to do it effectively and continuously.

Key risks of a poorly secured Active Directory:

Comptes à privilèges

Exposed privileged accounts — providing unrestricted access to the entire infrastructure

Configurations GPO

Misconfigured GPOs — facilitating privilege escalation and attack propagation

Délégations et droits

Misconfigured delegations and access rights — opening lateral attack paths to critical resources

AD Rating®: Audit, prioritize, and fix your Active Directory vulnerabilities continuously

AD Rating® provides a complete, continuous view of your Active Directory and domain controller security. The solution detects critical vulnerabilities, prioritizes remediation actions, and facilitates governance — whether for a single organization or a multi-subsidiary group operating across multi-domain and multi-forest environments. Its unique AD maturity indicator, the Active Directory security score 0–1,000, enables you to objectively measure your protection level and track your progress over time.

An Active Directory security score to monitor your posture in real time
  • 0–1,000 score summarizing the security maturity of your Active Directory environment
  • 170+ controls covering 11 exhaustive analysis axes
  • Score trend tracking over time by entity, domain, or subsidiary
  • Comparison against global industry benchmarks
  • Simplified communication with the executive team and operational staff
11 analysis axes for comprehensive coverage

AD Rating® performs in-depth analysis of all known attack vectors on Active Directory:

  • Domain Controllers — updates, exposed services, traffic signing, and TLS/SSL configuration
  • Domain Configuration — access rights on DNS records, machine account creation rights, and other AD features
  • PKI and Certificates — certificate authorities, vulnerable templates (ESC1–ESC8)
  • Trust Relationships — inter-domain and inter-forest trusts
  • Privileged Account Management — configuration and practices for administrator accounts: password management, exposure, and delegation scope
  • User Account Management — obsolete accounts, weak passwords, Kerberoastable accounts
  • Access Rights and Delegations — unconstrained delegations, dangerous ACLs
  • GPO — misconfigured or exploitable group policies
  • OS Upgrades — obsolete operating systems and update delays across all domain machines
  • Maintenance — cleanup, inactive accounts, at-risk groups
  • Attack Paths — identification of complete scenarios enabling a standard user to compromise key domain elements, documented with criticality level and associated remediations (2 high-impact control points)
Detailed observables to move from detection to remediation
  • Severity level for each observable
  • Technical risk description and exploitation context
  • Concrete remediation recommendations with priority order
  • Progress tracking and correction validation over time
Centralized dashboard: multi-domain and multi-subsidiary
  • Consolidated view for groups, holdings, and multi-forest environments
  • Security score comparison by entity to identify weak links
  • Alerts and risk trend monitoring over time
  • Simplified governance and executive reporting
Executive and technical reports
  • Executive report — summary, global score, key risks, strategic priorities
  • Detailed technical report — observables, criticality, recommendations, and remediation plan
  • Exportable reports for NIS2, DORA, and ISO 27001 compliance audits
Multilingual platform

Available in French, English, German, Italian, and Spanish — designed for international organizations.

365 Rating

Also managing a Microsoft 365 environment?

AD Rating® focuses on the security of your on-premises Active Directory. To assess and monitor the security of your Microsoft 365 and Microsoft Entra ID environment, discover 365 Rating®, our dedicated solution.

AD Rating® vs. one-time audit: what's the difference?

Traditional Active Directory audits — whether one-time engagements conducted by consultants, homemade PowerShell scripts, or open-source tools — present structural limitations against today's threat landscape.

AD Rating® vs. traditional approaches:

Criterion AD Rating® One-Time Audit / Homemade Scripts
Analysis frequency ✅ Continuous, real-time One-time (1x/year)
Coverage ✅ 170+ controls across 11 axes validated
by our offensive security team
✅ Variable, must be configured
Attack path detection ✅ Yes, compromise scenarios identified
Synthetic score / indicator ✅ Score 0–1,000 ❌ None
Executive reports ✅ Yes, automated ❌ Manual drafting
Multi-domain / multi-subsidiary ✅ Native ❌ Complex to consolidate
Hybrid environments
(Entra ID / 365 Rating®)
✅ Covered ❌ Often excluded
Prioritized remediation ✅ Yes, with criticality level ✅ Often available
NIS2 / DORA / ISO 27001 compliance ✅ Built-in control points ❌ Must be built manually

AD Rating® brings a fundamentally different approach:

  • Continuous analysis rather than an annual snapshot — vulnerabilities evolve in real time
  • A synthetic score understandable by both executive leadership and technical teams
  • Remediation-oriented approach — every observable is linked to a concrete action
  • Designed for complex environments — multi-domain, multi-subsidiary, multi-forest
  • Coverage of modern attacks — Kerberoasting, DCSync, ESC1–ESC8

Deploying AD Rating® in 5 steps

1

Download the AD Rating® installer and retrieve your API key from the Board of Cyber platform

2

Install the AD Rating® agent on a machine in your IT environment that belongs to the AD domain being assessed. The machine does not need to be a domain controller and does not require specific administrator rights

3

Enter the agent-specific API key to complete the installation

4

The agent performs measurements and periodically sends the collected data to the platform. The agent must be able to connect to the AD Rating SaaS platform via the internet

5

Discover risks, scores, and recommendations directly on the Board of Cyber platform

What our customers say about AD Rating®

A poorly secured Active Directory is a prime target for cybercriminals, yet the issue is often underestimated. AD Rating® helped us structure our approach very precisely: managing privileged accounts, identifying critical weaknesses, prioritizing actions. It is a highly operational tool, but also an excellent governance tool. It makes visible risks that would otherwise be difficult to quantify and manage — and helps build a culture of rigor and continuous improvement.

Samuel Bafourd, CIO at Seven2

AD Rating® use cases

Secure your organization's Active Directory

Reduce your attack surface and protect critical resources with continuous analysis of your Microsoft Active Directory configuration.

  • Continuous detection of misconfigurations and critical vulnerabilities
  • Identification of exploitable attack paths and privilege escalation opportunities
  • Monitoring of privileged accounts, dangerous delegations, and risky GPOs
  • Management of multi-forest and multi-domain environments
  • Attack surface reduction through prioritized remediation recommendations

Manage identities and critical accounts

Identity is the cornerstone of information system security. AD Rating® provides continuous monitoring of user accounts, privileged accounts, and sensitive access rights.

  • Monitoring of active, inactive, Kerberoastable, and privileged user accounts
  • Control of access rights, sensitive delegations, and critical group memberships
  • Maintaining a robust security posture for identities
  • Detection of configuration drift between two analyses

Meet regulatory requirements

NIS2, DORA, and ISO 27001 place identity and access security at the heart of compliance requirements. AD Rating® generates the evidence and reports needed for your audits.

  • Automatic identification of critical control points related to NIS2, DORA, and ISO 27001
  • Exportable reports for internal and external auditors
  • Simplified communication with the executive team, CISO, and compliance teams
  • Continuous tracking of security posture improvement over time

Monitor the AD environments of critical third-parties

For international groups, investment funds, or managed service providers, AD Rating® enables continuous assessment and monitoring of the Active Directory security of your subsidiaries, partners, or clients.

  • Continuous monitoring of the AD environments of partners, subsidiaries, or acquired entities
  • Rapid identification of critical vulnerabilities without direct infrastructure access
  • Consolidated dashboard to compare security posture across multiple entities
  • Exportable assessment report for due diligence and third-party audits

Frequently asked questions about Active Directory security audits

What is an Active Directory audit?

An Active Directory audit is a thorough analysis of the configuration, access rights, privileged accounts, and security policies of a Microsoft Active Directory environment. Its goal is to identify vulnerabilities, misconfigurations, and potential attack paths before a cybercriminal exploits them. An audit can be conducted periodically by a consultant or, as with AD Rating®, continuously and automatically.

Why is Active Directory the primary target for cybercriminals?

Active Directory centralizes all identities, access rights, and permissions across an organization. Compromising it means taking full control of the information system. Microsoft reports 95 million attack attempts targeting Active Directory accounts every day — a daily pressure that only continuous monitoring can absorb. This is why AD is systematically involved in the early stages of advanced cyberattacks: once a domain controller is compromised, an attacker can move freely across the network, escalate privileges, and reach all critical resources.

What is the difference between AD Rating® and a tool like PingCastle or BloodHound?

PingCastle and BloodHound are useful tools for one-time analyses, often used during penetration tests or manual audits. AD Rating® is a SaaS platform built for continuous operational use: it automates analysis on a control baseline fully managed by Board of Cyber, with no configuration or AD expertise required on your end. AD Rating® generates an Active Directory security score readable by executive leadership, prioritizes remediations, and produces reports tailored for both technical teams and the C-suite. It is designed for teams that need to manage their AD security over the long term, not just assess it occasionally.

How do you effectively secure an Active Directory?

Securing an Active Directory relies on several pillars: reducing the number of privileged accounts and implementing a tiering model, hardening domain controller configurations, controlling delegations and access rights, keeping systems up to date, and regularly auditing GPOs. But AD security is not a fixed state — it is a continuous process. Configurations drift, accounts accumulate, and new vulnerabilities emerge. That is precisely why a continuous audit solution like AD Rating® is more effective than an annual audit.

Is AD Rating® suitable for small and mid-sized businesses?

AD Rating® is designed for any organization running Active Directory, regardless of size. While large enterprises benefit from multi-domain and multi-subsidiary features, SMBs and mid-market companies also gain from the clear score, prioritized recommendations, and ease of deployment — with no need for a dedicated security team to interpret the results.

Does AD Rating® help meet NIS2 and DORA requirements?

Yes. NIS2 and DORA require organizations to demonstrate active management of identity and access risks. AD Rating® integrates the critical control points associated with these regulations, generates exportable reports for use during audits, and enables documentation of continuous security posture improvement — three key elements for satisfying regulatory requirements.