AD Hardening Assessment
We review your Active Directory for privileged accounts, password policy and legacy protocols, and leave you with a prioritised action plan.
What this campaign is
The problem is rarely one dramatic hole. It is the small decisions that pile up over the years: permissions granted in a hurry and never revoked, accounts of people who left, legacy protocols kept alive for one old application, policies nobody remembers writing. On their own none of them raise an alarm. Together they make an attacker's path much shorter.
This campaign looks at your Active Directory with that in mind. What you get at the end is not a list of findings but an ordered plan: which step lowers risk the most, and which one can wait. The review is part of the campaign and comes with no purchase commitment.
Who should take part?
Directories that grew for years
Environments touched by many admins, handed over between teams, where the original design decisions are long forgotten.
Unclear privilege model
If "who has which rights, and why" is not a question you can answer quickly, the review maps it out for you.
Before an audit or project
Teams that need the current state on paper before an audit, an insurance questionnaire or a security project.
What we look at
• Privileged accounts: members of admin groups, service accounts, forgotten delegations.
• Authentication: password and lockout policy, how far multi-factor authentication reaches.
• Legacy surface: old protocols still enabled and exceptions made for compatibility.
• Administrative habits: which machines admin work is done from, where privileged sessions are opened.
• Recovery: whether the directory backup and restore path has ever been rehearsed.
Every finding is weighted against the size of the organisation and its business priorities. The goal is not to say "close everything" — it is to show which door to close first.
How the review runs
1. You apply
You fill in the form below; we get back to you and check together whether the review fits.
2. Discovery call
We talk through the size of the environment, the critical applications and any issues you already know about.
3. Data collection
Directory configuration data is collected; the method and scope are agreed with you beforehand.
4. Analysis and read-out
Findings are prioritised, then the report and action plan are reviewed together with your team.
What stays with you
Findings report
The issues we found, what each of them means in practice and which attack path it shortens.
Prioritised action plan
An ordered set of steps: what lowers risk the most, and what is a quick win.
Closing session
A session where we walk your team through the report and answer questions.
Common questions
How long does it take?
Do you change anything in our systems?
Do we have to buy anything afterwards?
Who should join from our side?
Apply for the review
Leave a short note and we will come back to you about fit and timing.
Fill in the form and we will reply within one business day. The campaign you came from is recorded with your request.
-
Phone +90 216 706 38 80
-
E-mail info@newup.com.tr
-
Office hours Weekdays 09:00–18:00