Embedded Image

SMART PROFILER

SECURITY ASSESSMENT REPORT

Technology: Microsoft Active Directory

Tenant: DynamicPacks.net

Assessment Date: 03/06/2025 18:24:15

This Introduction contains a global summary of the health and security scans performed on the company infrastructure with SmartProfiler for Active Directory Assessment. Detailed information about the scans can be found in the Health & Security Maturity Framework and Technical Findings sections of this report. The assessment was performed according to ANSSI and MITRE ATT&CK definition. ANSSI is French National Agency for the Security of Information Systems. For more information, please check out here: https://www.cert.ssi.gouv.fr/uploads/guide-ad.html. There are tests that also recommended by Microsoft have been performed too.

SmartProfiler’s Active Directory tests are divided into three main categories: AD Security, AD Configuration , and AD Health Check. You can click on each category in the left section or select the Score Category to view the associated tests and their status. Please note there are no sub-categories for AD Health Issues.

Embedded Image

9Embedded Image

CRITICAL

109Embedded Image

HIGH

14Embedded Image

MEDIUM

8Embedded Image

LOW

145Embedded Image

PASSED

0Embedded Image

MANUAL CHECK

50.35%

Shows overall Security score for AD Forest based on the tests executed by SmartProfiler. Overall Score includes Security-Config and Health AD Tests.

OVERALL SCORE

42.92%

Shows overall score settings that need to be configured correctly in AD Domains. These settings are recommended by Microsoft.

SECURITY SCORE

66.1%

Shows overall score settings that need to be configured correctly in AD Domains. These settings are recommended by Microsoft.

CONFIGURATION SCORE

88.24%

Shows health score for AD and Domain Controllers. Health issues can be found in AD Health Status category in left pane.

HEALTH SCORE

Technology Categories and Status

Embedded ImageCRTIICAL
Embedded ImageHIGH
Embedded ImageMEDIUM
Embedded ImageLOW
Embedded ImagePASSED
Embedded Image
AD FEATURES
16.67%
Embedded Image
RISKY ITEMS
69.57%
Embedded Image
DC SECURITY
63.16%
Embedded Image
AD SITES
64.29%
Embedded Image
AD GPO
47.37%
Embedded Image
AD DNS
100%

Embedded Image

AZURE ENTRA ID SSO

52.63%

OVERALL SCORE

Test Severity
Items Affected Objects
Ensure On-Prem AD Users are not Privileged Users in Azure Entra ID Embedded Image Status:Configured correctly Configured correctly
Ensure Azure Administrative Units are used Embedded Image Administrative Units Status:Not Defined Not Defined
Ensure Azure Guests cannot invite other Guests Embedded Image Guests can Invite Other Guests Status:Guests can Invite Other Guests Guests can Invite Other Guests
Ensure non-Admins cannot register custom applications Embedded Image Users can register their Own Applications Status:Users can't register their Own Applications Users can't register their Own Applications
Ensure no Guest Accounts in Azure Privileged groups Embedded Image Status:No Guest Users in Privileged Roles No Guest Users in Privileged Roles
Ensure Security Defaults is enabled Embedded Image Status:Disabled Disabled
Ensure Normal Azure Users do not have Permissions to provide unrestricted user Consent Embedded Image Status:Allowed: Full Allowed: Full
Ensure Conditional Access Policy with signin user-risk location as Factor Embedded Image Status:No Conditional Access Policy found with Sign-in risk No Conditional Access Policy found with Sign-in risk
Ensure no Guest accounts that are inactive for more than 45 days Embedded Image Inactive Guests:Not Found Not Found
AAD Connect sync account password reset Embedded Image Status:Not Configured correctly Not Configured correctly
Ensure Guest users are restricted Embedded Image Status:Restricted but can see membership of all non-hidden groups Restricted but can see membership of all non-hidden groups
Conditional Access Policy that does not require a password change from high risk users Embedded Image Status:No Conditional Access Policy for High Risk Users No Conditional Access Policy for High Risk Users
Conditional Access Policy that does not require MFA when sign-in risk has been identified Embedded Image Status:No Conditional Access Policy found. No Conditional Access Policy found.
Ensure Synced AAD Users not privileged Users in Azure Embedded Image Status:Configured correctly Configured correctly
Ensure No Private IP Addresses in Conditional Access policies Embedded Image Status:No Private IP Address in Conditional Access Policies No Private IP Address in Conditional Access Policies
Ensure Number Matching enabled in MFA Embedded Image Status:Number Matching Not Enabled Number Matching Not Enabled
Ensure AD privileged users are not synced to AAD Embedded Image Status:Configured correctly Configured correctly
Ensure no more than 5 Global Administrators Embedded Image Status:
Ensure TLS 1.2 is enforced on Entra Connect Server Embedded Image TLS 1.2 Status:TLS 1.2 enforced TLS 1.2 enforced

Users Info

AD DomainBlank PasswordLastPassword UnsetStaleDisabledPass Never ExpiresExpiredReversible EncDES EncPrimaryGroupID ModifiedPWDLastSet UnsetKerberos Pre-AuthWith SPNsSending Bad LogonsPassword Not RequiredUnconstrained Delegation

Computers Info

AD DomainDisabledStaleWith SPNsSending Bad LogonsPrimaryGroupID ModifiedUnmanagedUnconstrained Delegation

Admin Groups

DisabledAdminsDisabledMembersDomainNameEnabledMembersGroupNameInactiveMembersPasswordNeverExpiresTotalMembers
0
0
DynamicPacks.net
0
Enterprise Key Admins
0
0
0
0
0
DynamicPacks.net
0
Key Admins
0
0
0
0
0
DynamicPacks.net
0
DNSAdmins
0
0
0
0
0
DynamicPacks.net
0
Domain Controllers
0
0
0
0
0
DynamicPacks.net
0
Enterprise Read-only Domain Controllers
0
0
0
0
0
DynamicPacks.net
0
Print Operators
0
0
0
0
0
DynamicPacks.net
0
Server Operators
0
0
0
0
0
DynamicPacks.net
0
Backup Operators
0
0
0
0
0
DynamicPacks.net
0
Account Operators
0
0
0
Embedded Image12
Embedded Image12
DynamicPacks.net
190
Administrators
Embedded Image201
Embedded Image201
202
0
0
DynamicPacks.net
1
Schema Admins
0
Embedded Image1
1
Embedded Image12
Embedded Image12
DynamicPacks.net
190
Enterprise Admins
Embedded Image201
Embedded Image201
202
Embedded Image12
Embedded Image12
DynamicPacks.net
190
Domain Admins
Embedded Image201
Embedded Image201
202

Password Policies

ComplexityEnabledDomainNameLockoutDurationLockoutThresholdMaxPwdAgeMinPwdAgeMinPwdLengthPasswordHistoryCountReversibleEncryption
True
DynamicPacks.net
00:30:00
0
42 Day(s)
1 Day(s)
7
24
False

Server OS Info

AD_DomainCountDisabledEnabledInactiveOperatingSystem
DynamicPacks.net
10
Embedded Image2
8
Embedded Image10
Windows Server 2008
DynamicPacks.net
10
0
10
Embedded Image10
Windows Server 2022
DynamicPacks.net
10
0
10
Embedded Image10
Windows Server 2019
DynamicPacks.net
1
0
1
0
Windows Server 2019 Standard Evaluation

Client OS Info

AD_DomainCountDisabledEnabledInactiveOperatingSystem
DynamicPacks.net
10
Embedded Image3
7
Embedded Image10
Windows 7
DynamicPacks.net
10
Embedded Image2
8
Embedded Image10
Windows XP

DC Info

DomainHostNameIPv4AddressIPv6AddressIsGlobalCatalogIsReadOnlyOperatingSystemOperatingSystemServicePackSiteSslPort
DynamicPacks.netdc114.DynamicPacks.net172.16.31.114TrueFalseWindows Server 2019 Standard EvaluationDefault-First-Site-Name636

FGPP Info

AppliedonGroupsAppliedonUsersComplexityEnabledDomainNameLockoutDurationLockoutThresholdMaxPwdAgeMinPwdAgeMinPwdLengthPasswordHistoryCountPolicyNameReversibleEncryption
True
DynamicPacks.net
00:30:00
0
30 Day(s)
1 Day(s)
8
5
FGPP_Policy5
True
True
DynamicPacks.net
00:30:00
0
30 Day(s)
1 Day(s)
8
5
FGPP_Policy4
True
True
DynamicPacks.net
00:30:00
0
30 Day(s)
1 Day(s)
8
5
FGPP_Policy3
True
True
DynamicPacks.net
00:30:00
0
30 Day(s)
1 Day(s)
8
5
FGPP_Policy2
True
True
DynamicPacks.net
00:30:00
0
30 Day(s)
1 Day(s)
8
5
FGPP_Policy1
True

Critical Infra. Info

AppliedonGroupsAppliedonUsersComplexityEnabledDomainNameLockoutDurationLockoutThresholdMaxPwdAgeMinPwdAgeMinPwdLengthPasswordHistoryCountPolicyNameReversibleEncryption
True
DynamicPacks.net
00:30:00
0
30 Day(s)
1 Day(s)
8
5
FGPP_Policy5
True
True
DynamicPacks.net
00:30:00
0
30 Day(s)
1 Day(s)
8
5
FGPP_Policy4
True
True
DynamicPacks.net
00:30:00
0
30 Day(s)
1 Day(s)
8
5
FGPP_Policy3
True
True
DynamicPacks.net
00:30:00
0
30 Day(s)
1 Day(s)
8
5
FGPP_Policy2
True
True
DynamicPacks.net
00:30:00
0
30 Day(s)
1 Day(s)
8
5
FGPP_Policy1
True

GPO Info

DomainNumberOfGPOsTotalComputerSettingsDisabledTotalDisabledGPOsTotalUserSettingsDisabled
DynamicPacks.net
3002
0
0
1

The Consolidation/Migration Score displays information about the scores for two categories of items: security risks and Stale objects. The Stale Objects Score shows which users, groups, administrators, computers, and operating systems need to be fixed. The risks that must be reduced prior to the migration are indicated by the Security Risks Score. Additionally, it indicates whether or not the source AD Domain is prepared for migration.

Domain: DynamicPacks.net

MIGRATION SCORE

54.17%

% of Migration Ready

Categories % Stale
Inactive/Disabled
% Security Risks
Users

0%

66.67%

Computers

Admins/Privileged Groups

35.09%

100%

Servers

103.23%

Operating Systems

STALESCORE%

SESCORE%

Groups

STALESCORE%

SESCORE%

AD GPOs

250.1%

100%

AD Permissions

0%

83.33%

Organizational Units

0%

SERVERS

STALE

Item # Of Items
Disabled Servers 2
Inactive Servers 30

RISKY ITEMS

Item # Of Items
Unauthenticated Servers 10
Secrets not renewed Servers 10

OPERATING SYSTEMS

FILLOPERATINGSYSTEMTABLESHERE

GROUPS

FILLALLGROUPSTABLEHERE

ORGANIZATIONAL UNITS

STALE

Item # Of Items
Ogranizational Units without Objects 4998

RISKY ITEMS

Item # Of Items

---APPENDIX---

SmartProfiler scoring method is determined by using following formulas:

1
For each category, we check number of tests in category and total number of passed items. For example, if AD GPO category has 10 tests and if 4 tests have been passed then to calculate score for AD GPO category we use Total Passed / Total Tests * 100 = Security Score.
2
Not executed tests are not included in above formula.

As you can see in below score for Sensitive Changes category. There are seven tests in Sensitive Changes category and only FIVE out of seven have been passed.

71.43%

Show overall score for tests executed in Sensitive Changes and make sure Sensitive Objects in AD are not modified.

SENSITIVE CHANGES SCORE

71.43%

Show overall score for tests executed in Sensitive Changes and make sure Sensitive Objects in AD are not modified.

SENSITIVE CHANGES SCORE