← Consultancy
Active Directory security

Close the paths to domain admin

Most ransomware ends in Active Directory. We map every attack path to domain admin, harden AD and Entra ID, and our engineers can implement the fixes.

On-prem AD & Entra IDAttack-path mappingTiered admin modelRecovery planning
Attack paths to Domain AdminsAD review
Path 1 Kerberoastable service accountWeak password, DA rights Critical
Path 2 Unconstrained delegationLegacy file server High
Path 3 Helpdesk groupCan reset admin passwords High
Fixed LAPS deployedLocal admin reuse removed Closed
Why it's different

Built from real ransomware recoveries

The usual way With Touchpoint
A generic hardening checklist Real attack paths to domain admin, mapped and ranked
Findings with no owner A tiered admin model your team can run
Hardening applied, then undone Changes monitored so drift is caught
No plan for when AD is lost A tested forest recovery plan
Cloud identity reviewed separately AD and Entra ID reviewed together
What we review

Where attackers take over

Privileged accounts Admins, service accounts and nested groups.
Attack paths Delegation, ACLs and Kerberos weaknesses.
Hybrid identity Entra Connect, synced admins and cloud roles.
Group Policy Insecure settings and privilege-granting GPOs.
Tiered administration Separating admin tiers to stop lateral movement.
Backup & recovery Forest recovery, protected backups and rebuild plans.
How it works

Two weeks from access to a hardened directory

  1. 01 Collect Read-only data collection from AD and Entra ID.
  2. 02 Map Every path to domain and global admin, ranked.
  3. 03 Advise A prioritised hardening plan.
  4. 04 Implement Your team or our engineers apply the changes.
  5. 05 Verify Paths re-mapped to confirm they’re closed.
What you get

A directory attackers can’t walk through

Clear findings, a plan your team can run, and proof it worked.

✓ Attack-path mapEvery route to domain admin.
✓ Hardening planPrioritised by risk and effort.
✓ Tiered admin modelDesign and rollout plan.
✓ Recovery planForest recovery, tested.
✓ Verification reportBefore and after.
✓ Monitoring rulesAlerts on the techniques we found.
Engagement options

Choose your depth

Assess AD review Find the paths and get a plan.
  • ✓Attack-path mapping
  • ✓Hardening plan
  • ✓Entra ID review
  • ✓Executive summary
Get a fixed quote →
Most chosen Review + implement We find it and fix it.
  • ✓Everything in the review
  • ✓Engineers apply fixes
  • ✓Tiered admin rollout
  • ✓Verification re-test
Get a fixed quote →
Resilience Recovery readiness For when AD is lost.
  • ✓Forest recovery plan
  • ✓Backup protection review
  • ✓Recovery exercise
  • ✓Runbooks
Get a fixed quote →
Questions

Before you ask

Is data collection safe?+

Yes. It’s read-only and uses standard tooling agreed with you in advance.

Can you implement the fixes?+

Yes. Our engineers can apply hardening and tiering changes in agreed change windows.

Do you cover Entra ID?+

Yes. Hybrid identity is where many modern attack paths start.

How is this different from a pentest?+

A pentest proves one path. An AD review maps all of them.

Find out how close an attacker is to domain admin

Book a review. Most organisations have a critical path they don’t know about.

Book an AD review
Other consultancy services Penetration testing→ Cloud security→ Tabletop exercises→ vCISO→