AdGUARD controls
AdGUARD does not invent its own rules. Every one of its 176 controls is drawn from a recognised public framework, and carries the mapping in its own record — which is what allows a report to answer a compliance requirement without retyping anything.
The frameworks the controls draw on
Each line shows how many controls of the catalog are mapped to that framework. A control usually answers several at once — that is the point of the mapping.
The French agency's Active Directory recommendations and control points — points de contrôle, chemins de contrôle, hygiène. They are the backbone of this catalog, and the reason it goes deeper than a generic checklist.
The Center for Internet Security hardening benchmark for Windows Server and domain controllers.
18 distinct techniques — Kerberoasting, AS-REP roasting, unconstrained delegation, DCSync, DCShadow, certificate abuse. Where the other frameworks say which requirement a control satisfies, ATT&CK says what an attacker loses when it is fixed.
Annex A clauses, organizational (A.5) and technological (A.8).
Control families: access control, identification and authentication, audit, configuration management.
Microsoft's benchmark, for the parts that apply to a hybrid directory.
The risk-management measures of article 21.
ICT risk management, for the financial sector.
What is checked, domain by domain
Representative controls, not the full list: the complete catalog ships with the tool and is available to network members.
Privileged accounts and groups37
- Limit the membership of Domain Admins
- Restrict Enterprise Admins membership
- Audit the Azure AD Connect synchronisation account
- Audit backup service accounts
ACL delegation and attack paths29
- Audit the ACLs of critical objects
- Detect GenericAll rights on critical objects
- Detect DCSync rights granted outside domain controllers
- Detect WriteDACL on the domain head
Kerberos15
- Eliminate unconstrained Kerberos delegation
- Rotate the krbtgt account password regularly
- Detect accounts vulnerable to Kerberoasting
- Detect accounts with pre-authentication disabled
AD CS · ESC16
- ESC1 — template allowing an arbitrary SAN with authentication
- ESC2 — template with Any Purpose EKU or no EKU
- ESC4 — template whose ACL allows it to be rewritten
- ESC8 — certificate authority web enrolment over HTTP
Tradecraft and hygiene20
- Eliminate residual GPP passwords (cpassword)
- Detect DCShadow indicators
- Reset the machine account creation quota
- Raise the domain functional level
Trusts, LAPS and directory DNS21
- Disallow TGT delegation across trusts
- Enable selective authentication on external trusts
- Detect wildcard records in ADIDNS zones
- Detect WPAD / ISATAP entries in ADIDNS zones
What a control looks like
Every control carries the same fields, in the interface and in every export — which is what makes a finding traceable months later.
The ANSSI maturity scale
Each control sits on a tier from 1 to 5. The level attained is the highest tier at which no non-compliant control remains below it: you cannot claim tier 3 while a tier 1 gap persists. It is a far more honest reading than a percentage.