m365expertise MICROSOFT SECURITY EXPERTISE
Home · Blog · Methodology
Methodology

ANSSI maturity in five tiers, and why it beats the percentage

m365expertise·12 May 2026·7 min

A percentage treats every gap as equal. A five-tier maturity model does not: it says what is genuinely achieved, and what single failure is blocking the next tier. It also makes a far better remediation plan — and a far better contractual objective.

The limit of a percentage

A weighted score is a real improvement on a raw ratio, but it still summarises everything into one number. Yet a service account sitting in Domain Admins and a missing diagnostic setting are not two instances of the same thing, and averaging them produces a figure that is accurate and unhelpful at the same time.

The ANSSI maturity model answers differently. Every control is placed on a scale from 1 to 5 according to its category, from identity foundations up to governance and advanced hardening. The result is not a score but a level — and a level is a sentence rather than a number.

The five tiers

TierActive Directory
1Privileged accounts, delegations, the objects that grant domain controlRole assignments, custom roles, classic administrators, owner service principals
2Authentication, Kerberos, password policy, LAPSKey Vault and secrets, encryption, backup vaults, immutability
3Service hardening, legacy protocols, certificate templatesNetwork, storage, databases, App Service, virtual machines, containers, AI services
4Logging, monitoring, detectionDiagnostic settings, retention, flow logs, Defender for Cloud
5Governance and advanced hardening

The distribution is informative in itself. On Active Directory, the weight sits low: the risk is in the escalation paths, not in the services.

The rule is deliberately harsh

The level reached is the highest tier N such that no non-compliant control remains in tiers 1 to N. Not a percentage of tier 1, not an average — none. Two failures at tier 1 and the level is zero, whatever the rest of the estate looks like.

Why so strict? Because the alternative encourages exactly the wrong behaviour. A model that let you claim tier 3 with a residual tier 1 failure would reward polishing the visible layer while leaving the foundation open. There is no such thing as good monitoring on a directory where every user can become an administrator.

Controls in error or not evaluated are excluded from the count, as they are from the score. A tier with no evaluated control at all is considered clean — which is worth remembering when a role assignment is missing and half a tier comes back unevaluated.

Four ways to use it

  • As the thread of the debrief. “Your estate is at level 1 out of 5” lands where “your compliance is 58%” does not. Present the level before the percentage.
  • As a natural remediation plan. Handle tier 1 first. On Active Directory that means closing the escalation paths before touching protocols.
  • As a contractual objective. “Reach level 3 within six months” is measurable and verifiable by a follow-up audit. “Improve our security posture” is not.
  • Alongside the attack paths. The tier gives depth, the attack path graph gives urgency. Together they make the debrief; separately, each one is arguable.

What it does not do

The model is not a certification and carries no legal weight. It is a reading grid — a way of ordering findings that matches how an attacker actually proceeds. Its value is that it converts an audit into a sequence of decisions rather than a list of grievances, and that it survives contact with an executive committee, which a control-by-control table does not.

Applies to Active Directory
All articles
23 articles on Microsoft security auditing.
Back to the blog →