..

This design element requires flash & JavaScript to be enabled to play. Download the latest version of flash from Adobe.com.

Optimising Active Directory

Ensure your investment in Microsoft solutions provides maximum return while remaining reassuringly secure.

commissum will ensure your Active Directory is fit for purpose with our Active Directory Maturity Audit, and will minimise costs by making full use of existing licences.

Active Directory Audit

commissum's AD Structural Audit can optimise your Active Directory and Microsoft security tools.

commissum's Active Directory Structural Audit is a higher-level audit than the Permissions Audit, but in terms of issue resolution it is of vital importance. The Permissions Audit focuses on which users can access which objects from a current and historical perspective. 

The Structural Audit, on the other hand, ensures that the fundamental AD structure does not contain loopholes in the permissions set-up. Such loopholes might be exploited by users to create new objects which can be used as "stepping stones" to access data that the users are not authorised to access. A Permissions Audit alone is not sufficient to prevent this, and so an Active Directory Structural Audit is needed in addition.

The AD Structural Audit focuses on the business fitness of your Active Directory set-up, rather than individual permissions. It will determine whether individual permissions, objects and policies can be used to circumvent one another (as is often the case). It is measured in terms of security and stability as well as regulatory and best practice compliance. While the Permissions Audit can address short-term issues, the Structural Audit will prevent problems occurring in the future. Both audit types are essential to a comprehensive review, with robust recommendations to address future situations.

The AD Structural Audit has no impact on your infrastructure. The consultant will spend a day on-site evaluating the structures within your AD. During that day, he/she will need three to four hours, ideally with the senior AD administrator, to ask questions about why certain structures are used and how some requirements are fulfilled.

If the senior AD administrator is unavailable, then the consultant will work with someone who can grant administrative access to a domain controller. While no changes are made to your systems, we usually expect that the consultant has access to a local employee that he/she can question, in order to get the most out of the engagement.

At the end of this consultancy day, we hold an informal meeting for an hour, which both the senior administrator and the CIO/IT manager should attend. At this meeting, we discuss the overall audit findings, their impact on the business, and what actions could be taken to optimise the Active Directory.

You will be able to ask any questions you might have. The extra depth of explanation that this meeting provides will make our report more meaningful when you receive it.

The final stage of the AD Structural Audit is the writing of the full report, including metrics taken from the audit observations. Once the report is complete, we can return to deliver the report in person, or we can discuss it remotely by conference call.

Get in touch with one of our security consultants today

  • No obligation
  • Expert advice
  • Tailored solutions
"commissum was particularly responsive and the project was well managed under demanding conditions. I was very happy with the technical standard. Very good value for money as well”

Mr Kenneth Y, Head of IT Risk & Compliance, International Retail Bank

Latest News

Alleged Chinese Government Hacking Department back in action

Alleged Chinese Government Hacking Department back in action

Allegedly the Chinese state sponsored cyber division named as Unit 61398 are back in action after a lull in their activities. This group that allegedly specialises in governmental and industrial espionage was very active and successful up until February this year. The targets of Unit 61398, also known as APT1, have ...
Tue 21 May, 2013 // Martin
cyber-war

Leading USA military contractor QinetiQ hacked and ransacked by Chinese hackers for three years

A new report from Bloomberg, the business information provider (www.bloomberg.com/news/2013-05-01/china-cyberspies-outwit-u-s-stealing-military-secrets.html) outlines how hackers from China stealthily infiltrated the computer systems of QinetiQ North America, a leading espionage and military contractor to the US government, and the US branch of the British defence technology company QinetiQ. A vast range of highly ...
Wed 08 May, 2013 // Briony
cyber-tanks

Suspected hacker arrested after “biggest-ever DDoS attack”

Police in Spain have arrested a Dutch national on suspicion of launching the largest-ever “Distributed Denial of Service” (DDoS) attack. Sven Olaf Kamphuis, 35, was arrested on April 25th near Barcelona, Spain. At the time, he was in possession of a specially-equipped van set up as a mobile computing and ...
Tue 30 Apr, 2013 // Briony