Identity · 3-6 weeks
Active Directory modernization and hardening
On-premises Active Directory is still the backbone of most Microsoft environments, and it is usually the softest target in the building: flat admin rights, decades of stale objects, legacy protocols, and Group Policy nobody has reviewed. We run a security-led modernization: lock down privileged access with a tiered model, remove the legacy attack surface, cut the obvious attack paths, and set the direction toward Entra-first identity.
What's included
- AD security review: privileged group membership, delegation, ACLs, trusts, and Kerberos configuration
- Tiered administration model (Tier 0/1/2) with dedicated admin accounts and Privileged Access Workstation guidance
- Windows LAPS for local administrator passwords
- Legacy protocol removal: NTLMv1, LM, unconstrained delegation, SMBv1, LDAP signing and channel binding
- Kerberos hardening: AES, service account and SPN cleanup, resource-based constrained delegation
- Attack-path review, Kerberoasting, AS-REP roasting, ACL and GPO abuse, and remediation
- Group Policy consolidation and security-baseline alignment
- Stale object, SIDHistory, and trust cleanup
- AD backup and forest-recovery plan
- A roadmap to reduce on-premises AD dependency: Entra join, cloud Kerberos trust, and app migration
How we work
Scope
A fixed statement of work: what we will do, what you receive, and the timeline. Agreed before any work starts.
Execute
We do the work in your tenant with least-privilege access, with updates at defined checkpoints, not radio silence.
Hand off
Documentation, runbooks, and a walkthrough so your team can operate what we built.
Active Directory Modernization & Hardening: common questions
Do we have to get rid of Active Directory?
No. The goal is a hardened AD and a realistic path to depend on it less over time. Many businesses run hybrid for years, the point is that it is secure and intentional, not neglected.
Is this the same as the Cloud Security Assessment?
The Cloud Security Assessment focuses on Entra ID, Microsoft 365, and Azure. This is the on-premises Active Directory counterpart, and the two are often done together.
Will hardening break applications?
Legacy-protocol and Kerberos changes are staged: we inventory what depends on them, audit first, communicate, then enforce. Nothing goes to enforcement without your sign-off.
Related services
Talk to a senior architect about active directory modernization & hardening
A short call to understand your environment, then a fixed-scope proposal. Based in Denver, Colorado; we work with clients across the US remotely.