Security · rules
Findings & security rules
20 open issues · 26 rules evaluated
20All · Open
45Stale objects · 5 Open
63Privileged accounts · 5 Open
30Trust relationships · 2 Open
86Anomalies · 8 Open
Obsolete domain controller Compliant
S-DC-Obsolete
Recent krbtgt password Compliant
A-Krbtgt
SMBv1 disabled on DCs Compliant
A-SMBv1
Forest trust filtered Compliant
T-ForestSID
Schema Admins group empty Compliant
P-SchemaAdmins
AD Recycle Bin Compliant
S-RecycleBin
Password in a GPP (SYSVOL) Critical
A-GPPPassword
Unconstrained Kerberos delegation Critical
P-Delegation
Trust without SID filtering High
T-SIDFiltering
LDAP signing not required High
A-LDAPSigning
Service account in Domain Admins High
P-SvcInDA
Hosts on obsolete OS High
S-OS-Obsolete
Large administrator population High
P-AdminNum
Kerberoastable accounts High
A-Kerberoast
Inactive user accounts High
S-Inactive-User
AS-REP roastable accounts High
A-ASREPRoast
Accounts with SID History Medium
T-SIDHistory
Reversible password encryption Medium
A-Reversible
LAPS not deployed everywhere Medium
P-LAPS
Admins outside 'Protected Users' Medium
P-Protected
Weak password policy Medium
A-PwPolicyWeak
Passwords set to never expire Medium
S-PwdNeverExpires
Default ms-DS-MachineAccountQuota Medium
A-MachineQuota
Inactive computers Low
S-Inactive-Computer
Old forest functional level Low
A-FunctionalLevel
Accounts restricted to DES encryption Low
S-DesEnabled