Embedded Image

SMART PROFILER

SECURITY ASSESSMENT REPORT

Technology: Microsoft Active Directory

Tenant: DynamicPacks.net

Assessment Date: 03/06/2025 18:24:15

This Introduction contains a global summary of the health and security scans performed on the company infrastructure with SmartProfiler for Active Directory Assessment. Detailed information about the scans can be found in the Health & Security Maturity Framework and Technical Findings sections of this report. The assessment was performed according to ANSSI and MITRE ATT&CK definition. ANSSI is French National Agency for the Security of Information Systems. For more information, please check out here: https://www.cert.ssi.gouv.fr/uploads/guide-ad.html. There are tests that also recommended by Microsoft have been performed too.

SmartProfiler’s Active Directory tests are divided into three main categories: AD Security, AD Configuration , and AD Health Check. You can click on each category in the left section or select the Score Category to view the associated tests and their status. Please note there are no sub-categories for AD Health Issues.

Embedded Image

9Embedded Image

CRITICAL

109Embedded Image

HIGH

14Embedded Image

MEDIUM

8Embedded Image

LOW

145Embedded Image

PASSED

0Embedded Image

MANUAL CHECK

50.35%

Shows overall Security score for AD Forest based on the tests executed by SmartProfiler. Overall Score includes Security-Config and Health AD Tests.

OVERALL SCORE

42.92%

Shows overall score settings that need to be configured correctly in AD Domains. These settings are recommended by Microsoft.

SECURITY SCORE

66.1%

Shows overall score settings that need to be configured correctly in AD Domains. These settings are recommended by Microsoft.

CONFIGURATION SCORE

88.24%

Shows health score for AD and Domain Controllers. Health issues can be found in AD Health Status category in left pane.

HEALTH SCORE

Technology Categories and Status

Embedded ImageCRTIICAL
Embedded ImageHIGH
Embedded ImageMEDIUM
Embedded ImageLOW
Embedded ImagePASSED
Embedded Image
AD FEATURES
16.67%
Embedded Image
RISKY ITEMS
69.57%
Embedded Image
DC SECURITY
63.16%
Embedded Image
AD SITES
64.29%
Embedded Image
AD GPO
47.37%
Embedded Image
AD DNS
100%

Embedded Image

AZURE ENTRA ID SSO

52.63%

OVERALL SCORE

Test Severity
Items Affected Objects
Ensure On-Prem AD Users are not Privileged Users in Azure Entra ID Embedded Image Status:Configured correctly Configured correctly
Ensure Azure Administrative Units are used Embedded Image Administrative Units Status:Not Defined Not Defined
Ensure Azure Guests cannot invite other Guests Embedded Image Guests can Invite Other Guests Status:Guests can Invite Other Guests Guests can Invite Other Guests
Ensure non-Admins cannot register custom applications Embedded Image Users can register their Own Applications Status:Users can't register their Own Applications Users can't register their Own Applications
Ensure no Guest Accounts in Azure Privileged groups Embedded Image Status:No Guest Users in Privileged Roles No Guest Users in Privileged Roles
Ensure Security Defaults is enabled Embedded Image Status:Disabled Disabled
Ensure Normal Azure Users do not have Permissions to provide unrestricted user Consent Embedded Image Status:Allowed: Full Allowed: Full
Ensure Conditional Access Policy with signin user-risk location as Factor Embedded Image Status:No Conditional Access Policy found with Sign-in risk No Conditional Access Policy found with Sign-in risk
Ensure no Guest accounts that are inactive for more than 45 days Embedded Image Inactive Guests:Not Found Not Found
AAD Connect sync account password reset Embedded Image Status:Not Configured correctly Not Configured correctly
Ensure Guest users are restricted Embedded Image Status:Restricted but can see membership of all non-hidden groups Restricted but can see membership of all non-hidden groups
Conditional Access Policy that does not require a password change from high risk users Embedded Image Status:No Conditional Access Policy for High Risk Users No Conditional Access Policy for High Risk Users
Conditional Access Policy that does not require MFA when sign-in risk has been identified Embedded Image Status:No Conditional Access Policy found. No Conditional Access Policy found.
Ensure Synced AAD Users not privileged Users in Azure Embedded Image Status:Configured correctly Configured correctly
Ensure No Private IP Addresses in Conditional Access policies Embedded Image Status:No Private IP Address in Conditional Access Policies No Private IP Address in Conditional Access Policies
Ensure Number Matching enabled in MFA Embedded Image Status:Number Matching Not Enabled Number Matching Not Enabled
Ensure AD privileged users are not synced to AAD