Active Directory pentest: we show the shortest path to Tier 0.
One standard account, one network foothold or one exposed sign-in - and then the question that matters: how many steps separate that from domain-admin-equivalent rights? We walk the path manually, document every step reproducibly, and record what your detection saw along the way.
Four realistic starting positions - you decide which one we test.
External, no access
Exposed authentication surfaces: ADFS, Entra sign-in, VPN portals, OWA, password spraying against known naming conventions, leaked credentials from public dumps.
Assumed breach, standard account
An ordinary user account, no local admin. From there: enumeration, ACL abuse, Kerberos attacks, delegation flaws, credential exposure in shares, GPOs and scripts.
Internal, network access
Network access in a client or server segment with no account: name-resolution poisoning, relaying onto unhardened hosts and coercion techniques against domain controllers.
Cloud-first / Entra ID
Starting in Entra ID: app registrations, consent grants, privileged roles, device-join paths - and the question of what of that reaches on-prem.
What we actually test.
Not a scanner report. Every chain is verified manually and documented with command, timestamp and evidence so your team can reproduce it.
- →Tier 0 definition and exposure: domain controllers, ADCS, Entra Connect, backup systems, password vaults, jump hosts.
- →Kerberos layer: kerberoasting, AS-REP roasting, unconstrained / constrained / resource-based delegation, S4U abuse.
- →ACL and object rights: GenericAll, WriteDACL, WriteOwner, AddMember, gMSA read rights, LAPS access, OU delegations.
- →Certificate services (ADCS): template misconfigurations, enrollment agents, web-enrollment relay paths.
- →Credential exposure: cleartext in shares, scripts, GPO preferences, task definitions, application configs, ticket and hash material on reachable hosts.
- →Hybrid identity: Entra Connect / Cloud Sync, ADFS trust and token signing, seamless SSO, PRT usage, roles with cross-boundary effect.
- →Forest and domain boundaries: trust direction and type, SID filtering, SID history abuse, trust-ticket paths.
- →Lateral movement in practice: SMB/WinRM/WMI/DCOM, MSSQL linked servers, session hunting, admin logons on untrusted hosts.
Detection observations
For each phase we record whether telemetry existed, whether an alert fired and whether anyone responded. This is not a purple teaming exercise, but it produces the data points to scope one sensibly.
Rules of engagement
Testing windows, named contacts on both sides, documented stop conditions, mandatory approval for potentially disruptive techniques, an emergency abort path by phone.
Evidence & deletion
Collected artefacts are stored encrypted, referenced in the report and deleted once the agreed retention period ends. Deletion is confirmed in writing.
Common questions about AD pentests
+What is an Active Directory penetration test?
A manual assessment of your Windows identity infrastructure - Active Directory, Entra ID, ADFS and the hybrid join - aimed at proving real attack paths from a standard domain account or from the outside up to Tier 0 rights. What matters is not the number of findings but the shortest demonstrable path to domain-admin-equivalent privilege.
+What does assumed breach mean here?
We start from an ordinary domain account with no special rights - what an attacker holds after phishing or a compromised workstation. That skips the weeks an attacker spends on initial access and focuses the engagement on what goes wrong afterwards: privilege escalation, lateral movement and missing detection.
+Do you also test Entra ID and hybrid environments?
Yes. In most environments today the risk sits at the seam: Entra Connect / Cloud Sync, pass-through or federated authentication via ADFS, seamless SSO, application and app-registration permissions, and privileged Entra roles that reach on-prem resources. We test both directions - on-prem to cloud and cloud to on-prem.
+Is the test safe to run in production?
We work with documented stop conditions, agreed testing windows and a named technical contact on your side. Destructive techniques (for example bulk DCSync extraction, golden tickets against production accounts, account lockouts from spraying) are only executed after explicit written approval and within an agreed scope.
+What information do you need for scoping?
Number of forests, domains and domain controllers, rough user and server counts, an existing tiering model if any, whether Entra ID / ADFS are in use, ADCS yes or no, the EDR and SIEM in place, and whether detection should be tested alongside. That determines tester-days and the testing window.
+What do you deliver?
A report with reproducible attack paths (step, command, evidence), Tier 0 exposure, prioritised remediation with effort estimates, detection observations per phase, a management summary for the board and supervisors - and a retest of the remediated findings.
Request scoping - confidentially.
Describe in a few sentences what needs testing. We come back with concrete questions, the right type of exercise and an effort range - before you commit to anything.
Not ready to talk yet? The Scope Check returns exercise type, tester-days and a budget range in two minutes - no email gate.
Specialist assessments - which page fits your scope
Entry point: test types, delivery, reporting, price ranges.
Open pageManaged pentest programme: calendar, retests, findings management, audit evidence.
Open pageSAP-specific assessment: RFC gateway, authorisations, BTP integration.
Open pageCombines the technical test with ISMS / compliance evidence.
Open pageJoint detection work with your SOC instead of a covert operation.
Open pageGoal-oriented, covert attack simulation against people, technology and process.
Open page