m365expertise MICROSOFT SECURITY EXPERTISE

AdGUARD features

Below is every screen of AdGUARD, in the order of a real engagement: steer, frame the scope, audit, deliver, operate. Click any screenshot to enlarge it.

Steer

The dashboard opens on the figure that matters: the weighted compliance score, then the breakdown that says where the effort belongs. Categories are sorted from weakest to strongest, and the trend curve shows the effect of remediation over time — as well as silent drift.

The dashboard: overall compliance and per-category breakdown
The compliance trend over time

Frame the scope

The catalog is grouped by category, with a level on every control. A baseline freezes the agreed scope: which controls are in, which are out, and why. Ten framework templates — ANSSI, ISO, NIST, CIS, NIS2, DORA — pre-select the right subset without typing anything.

The catalog, grouped by category
Framework templates, with the count of runnable controls
The baseline editor: included, excluded, re-levelled

Audit

The run is parallel and takes seconds. Each control returns a verdict and, above all, a named finding: not « non-compliant », but which objects are at fault. The history keeps every run with its scope, and comparing two audits separates what was fixed from what regressed.

An audit running, with the live stream of evaluated controls
The result of a control, with the objects observed and the remediation
The history: one run per row, with its change in points

Attack paths and trusts

This is what sets an Active Directory audit apart from a checklist. An attack path is not a software vulnerability: it is a legitimate delegation gone dangerous, granted years ago for a reason that no longer exists. The graph shows who can take control of what, in one hop. The figure to watch is not the total, but how many paths start from a principal every domain user belongs to — those are within reach of any compromised account.

The attack path graph: who can compromise what
The trust graph: partners, direction and weaknesses found

Deliver

Six report types for six audiences — executive, detailed technical, prioritized remediation plan, compliance by framework, situation report, and attack paths. Five file formats. The report carries your logo and your contact details, and the audited client's logo on the cover. See what each report contains, with extracts →

Choosing the report type and the formats

Operate

One record per audited client, with its own connector, its own history and its own report cover logo — two clients' data never mix. The application shows the licence holder's name, carried by the licence itself, so each report goes out under that name; the audited client's own logo sits on their report cover. The licence is verified offline, with no activation server to reach.

The portfolio of audited clients
What exactly does it check?
The catalog, the frameworks it draws on, and how deep it goes.
See the controls →