m365expertise MICROSOFT SECURITY EXPERTISE

AdGUARD controls

AdGUARD does not invent its own rules. Every one of its 176 controls is drawn from a recognised public framework, and carries the mapping in its own record — which is what allows a report to answer a compliance requirement without retyping anything.

176controls
8built-in packs
32categories
96 / 80level 1 / level 2

The frameworks the controls draw on

Each line shows how many controls of the catalog are mapped to that framework. A control usually answers several at once — that is the point of the mapping.

ANSSI176 / 176

The French agency's Active Directory recommendations and control points — points de contrôle, chemins de contrôle, hygiène. They are the backbone of this catalog, and the reason it goes deeper than a generic checklist.

CIS Microsoft Windows Server Benchmark56 / 176

The Center for Internet Security hardening benchmark for Windows Server and domain controllers.

MITRE ATT&CK81 / 176

18 distinct techniques — Kerberoasting, AS-REP roasting, unconstrained delegation, DCSync, DCShadow, certificate abuse. Where the other frameworks say which requirement a control satisfies, ATT&CK says what an attacker loses when it is fixed.

ISO/IEC 27001:2022176 / 176

Annex A clauses, organizational (A.5) and technological (A.8).

NIST SP 800-53176 / 176

Control families: access control, identification and authentication, audit, configuration management.

Microsoft Cloud Security Benchmark143 / 176

Microsoft's benchmark, for the parts that apply to a hybrid directory.

NIS2176 / 176

The risk-management measures of article 21.

DORA176 / 176

ICT risk management, for the financial sector.

What is checked, domain by domain

Representative controls, not the full list: the complete catalog ships with the tool and is available to network members.

Privileged accounts and groups37

  • Limit the membership of Domain Admins
  • Restrict Enterprise Admins membership
  • Audit the Azure AD Connect synchronisation account
  • Audit backup service accounts

ACL delegation and attack paths29

  • Audit the ACLs of critical objects
  • Detect GenericAll rights on critical objects
  • Detect DCSync rights granted outside domain controllers
  • Detect WriteDACL on the domain head

Kerberos15

  • Eliminate unconstrained Kerberos delegation
  • Rotate the krbtgt account password regularly
  • Detect accounts vulnerable to Kerberoasting
  • Detect accounts with pre-authentication disabled

AD CS · ESC16

  • ESC1 — template allowing an arbitrary SAN with authentication
  • ESC2 — template with Any Purpose EKU or no EKU
  • ESC4 — template whose ACL allows it to be rewritten
  • ESC8 — certificate authority web enrolment over HTTP

Tradecraft and hygiene20

  • Eliminate residual GPP passwords (cpassword)
  • Detect DCShadow indicators
  • Reset the machine account creation quota
  • Raise the domain functional level

Trusts, LAPS and directory DNS21

  • Disallow TGT delegation across trusts
  • Enable selective authentication on external trusts
  • Detect wildcard records in ADIDNS zones
  • Detect WPAD / ISATAP entries in ADIDNS zones

What a control looks like

Every control carries the same fields, in the interface and in every export — which is what makes a finding traceable months later.

ControlEliminate unconstrained Kerberos delegation
LevelL1
FindingThe named objects at fault, read from the estate itself.
RemediationThe correction path, plus a PowerShell command to verify it.
FrameworksANSSI R44 · NIST AC-6 · ISO 27001 A.8.2 · DORA Art. 9 · NIS2 21.2(i) · MITRE T1558

The ANSSI maturity scale

Each control sits on a tier from 1 to 5. The level attained is the highest tier at which no non-compliant control remains below it: you cannot claim tier 3 while a tier 1 gap persists. It is a far more honest reading than a percentage.

1Tier 0 and privilege foundations89
2Kerberos, legacy protocols and secrets33
3Policies, configuration and directory DNS35
4Estate hygiene and detection17
5Governance and advanced hardening2
Want to see it run?
Every screen of the tool, in the order of a real engagement.
See the features →