Skip to content

Active Directory

Active Directory security: know who becomes an administrator

On a Friday at 10:41 pm, an account joins the Domain Admins group. Nobody asked for it, and on Monday morning nothing looks out of place. FirstSI watches your directory around the clock, alerts you within the minute with the name of whoever made the change, and scores the health of the directory month after month.

Open-access demo, no sign-up: 138 fictional machines and all twelve modules.

directory — last 24 hours

GROUPS “Domain Admins”: one member added on Friday at 10:41 pm

AUTHOR backup service account, from a head office computer

CONTROLLERS replication, time and backup all compliant

ACCOUNTS 7 accounts of people who have left, still active

POSTURE directory scored 82/100, up six points in a month

What FirstSI watches in the directory

groups

Sensitive groups, in real time

An addition to Domain Admins, Enterprise Admins or any group you consider sensitive sets off an alert straight away, with the author of the change, their computer and the time.

attacks

Credential attacks

Theft of authentication tickets, rogue directory replication, a modified group policy, a cleared security log: these moves turn up in almost every attack, and FirstSI flags them.

posture

A score that goes up

A posture score is calculated every day and tracked over time. It shows what is dragging the score down and what would raise it fastest. It also gives you a simple figure to put in front of the board.

controllers

Domain controllers in good shape

Replication, time synchronisation, a recent backup, certificates close to expiry: every controller is checked continuously, and you hear about a problem before logons start failing.

review

Access reviews, already prepared

A periodic review of sensitive groups, ready to export for the manager who has to sign it off. Accounts belonging to people who have left, yet still active, are listed separately.

accounts

An account's record

Its lockouts and their real origin (a VPN attempt, a phone still on the old password), its usual computers, its addresses, its Microsoft 365 sign-ins. On the service desk, that saves a quarter of an hour per call.

In the console

Screens from the live demo, with the data of a fictional company.

Active Directory screen: posture score out of 100, its trend over six months and the items to fix by severity. Active Directory screen: posture score out of 100, its trend over six months and the items to fix by severity.
Directory posture, scored and explained item by item. Demo data.

Friday, 10:41 pm

An admin addition nobody asked for

The backup service account has broad rights, as these accounts often do. That evening, it is used to add an ordinary user to the Domain Admins group. The whole operation takes two seconds.

FirstSI sends the alert to the on-call engineer within the minute: the group that was changed, the account that acted and the computer the command came from. The SIEM links it to an unusual logon on that same computer two minutes earlier.

The on-call engineer removes the new member, disables the service account and isolates the computer. On Monday, the access review shows the full history, and the posture score points out that this service account had held far too many rights for two years.

SIEM — directory incident

22:39 LOGON unusual logon on a head office computer

22:41 GROUP member added to “Domain Admins”

22:41 AUTHOR backup service account

22:42 ALERT on-call engineer notified by email and webhook

22:58 RESOLVED member removed, service account disabled

How it works

1

The agent on the controllers

It reads the logs Windows already produces. There is no driver to install, and the directory schema is left untouched.

2

Rules ready to use

Risky behaviour is recognised out of the box. You add your own sensitive groups and the accounts you want to watch closely.

3

An alert that says who, what and from where

Each alert arrives with the author, the target and the source computer, then joins the SIEM to be matched against everything else.

Frequently asked questions

Do I need to install anything on the domain controllers?

Yes, the FirstSI agent, the same one used everywhere else. It runs as a Windows service and updates remotely, with signed updates.

Does FirstSI change the directory?

No. It reads the logs and the state of the directory without changing anything. Fixes remain in your hands.

What is the posture score for?

Mainly for measuring your own progress. Every lost point is explained, along with the fix that would win it back.

Does it help with NIS2?

Monitoring privileged accounts, reviewing access periodically and tracing changes are among the expected measures. FirstSI gives you the evidence, ready to export.

What about Microsoft 365 accounts?

They are covered by the Microsoft 365 connector: refused sign-ins explained, bursts of password attempts, sign-ins from an unusual country.

More questions about installation, hosting, GDPR or integrations? All frequently asked questions

Your directory deserves a night watch

Bring your questions about the directory: the guided demo shows what FirstSI would see in it, on a complete estate.