Active Directory security auditing

It runs on its own.That doesn't mean you're on your own.

Engineers in front of a wall of animated AdGUARD audit screens
173 real controls
Every verdict is a live LDAP read
No cached assumptions — each control queries the directory over LDAP and returns the objects it actually found.
Read-only
No write access, anywhere
A standard domain account, read-only over LDAP — no agent, no schema change, nothing installed on a DC.
10 control families
Privileged access to GPOs
Privileged accounts, Kerberos, AD CS, attack paths, ADIDNS, LAPS, trusts and GPO hygiene — one audit.
Your brand
White-label reports & licences
Four report types under your name — and a licence generator for your own clients.

Read-only  ·  Runs on your workstation  ·  No agents

Know what changed.
Prove what you fixed.

AdGUARD runs 173 implemented security controls against Active Directory — then turns the result into a report you hand a client under your own brand.

Sold once, at one fixed price. No subscription, no domain cap, no revenue share.

  • Never writes to the directory
  • Nothing leaves your machine
  • 10 AD control families
  • CIS · NIST · ISO 27001 · ANSSI · MITRE

The gap

A screenshot is not an audit trail.

Most Active Directory reviews end the same way: a spreadsheet built by hand, a few portal screenshots, and no reliable way to answer the only question that matters three months later — did anything drift?

Manual review

Two days per domain, and it ages instantly

Clicking through admin centers, copying settings into a sheet, formatting a document. The work is gone the moment a global admin changes one toggle.

A one-off script

A snapshot with no paper trail

A PowerShell script or a point-in-time tool prints a list once, for reasons you can't reconstruct three months later. It isn't scoped per control, it isn't repeatable, and it isn't yours to brand.

Enterprise platforms

Priced and built for one domain

Posture management suites assume you own the environment. A consultant auditing eleven clients needs eleven isolated workspaces, not eleven subscriptions.

Coverage

173 controls. Every one of them runs.

No placeholders, no planned entries padding a marketing number. Each control in the catalog is backed by a live LDAP read against the directory — across ten control families from privileged access to attack-path analysis — and returns a verdict with the objects it found. Every control has a stable unique ID and carries its framework references — CIS, NIST, ISO 27001, ANSSI, NIS2, DORA, MCSB — in the app and on every report.

43

Privileged accounts & groups

Domain/Enterprise/Schema Admins, operators, adminCount, Protected Users, nesting, dormant admins

35

Attack paths

Dangerous ACLs (GenericAll, WriteDACL), DCSync, shadow admins, delegation, escalation chains to Tier 0

21

Kerberos & encryption

Kerberoasting, AS-REP roasting, unconstrained/constrained/RBCD delegation, DES/RC4, krbtgt

18

AD CS (ESC1–ESC16)

Vulnerable certificate templates, CA misconfiguration, NTLM relay, weak mappings, SID extension

16

DC hardening & legacy protocols

SMBv1, NTLMv1, LDAP/SMB signing, Print Spooler, LSA protection, anonymous access, patch level

13

Passwords & lockout

Length, complexity, history, age, reversible encryption, lockout policy, fine-grained policies

11

Domain configuration

Functional level, machine account quota, AD Recycle Bin, SID history, trusts inventory

7

Trusts & LAPS

SID filtering, TGT delegation, selective authentication, RC4 trusts; LAPS coverage and confidentiality

6

ADIDNS

Wildcard records, WPAD/ISATAP, insecure dynamic updates, broad record-creation rights

3

Group Policy hygiene

Orphaned GPOs, empty or disabled GPOs, broken gPLink references

Each control carries a level — L1 for foundational, L2 for hardening — and the score weights them accordingly. A failed L1 costs three times a failed L2, because it should.

Framework mapping

Every control cites its source.

Auditors don't accept findings without a reference. Each control carries its CIS benchmark number, its NIST 800-53 family and its ISO 27001 annex clause — and where applicable, its ANSSI recommendation, its MITRE ATT&CK technique or its NIS2/DORA article.

Microsoft Cloud Security Benchmark

IM and PA privileged-access families, mapped where they apply on-premises

CIS Windows Server Benchmarks

Domain controller and member server hardening — the source of the controls

NIST SP 800-53

AC, IA, SC, SI, AU control families from the US federal catalog

ISO/IEC 27001:2022

Annex A.5 organizational and A.8 technological clauses

ANSSI

Identity and cloud hardening control points from the French agency

NIS2 — EU 2022/2555

Article 21.2 risk-management measures: access control, MFA, cryptography, incident detection

DORA — EU 2022/2554

ICT protection and prevention (Art. 9) and detection (Art. 10) for financial entities

MITRE ATT&CK

Kerberoasting, DCSync, AD CS abuse, delegation and credential-access techniques, per control

Built for service providers

You audit other people's domains. The tool should know that.

AdGUARD was written for consultants and managed service providers first. Every client lives in its own workspace — separate connectors, separate history, separate reports — and you move between them in one click.

Isolation

One workspace per client

Connectors, audit history, saved baselines and report branding are stored per company. Nothing crosses over, and no dashboard ever mixes two clients' data.

White label

Your logo on the cover, not ours

Set your firm's name, website and logo once. Every exported report carries your identity in the header and footer — and the audited company's own logo on the executive cover page.

Reusable scope

Baselines you build once

Include or exclude any control, adjust its level, save it as a baseline — global across every client, or specific to one engagement. Twelve framework templates ship with it. See the editor.

The product

A desktop application, not a portal.

It installs on Windows, authenticates to the domains you choose, and keeps every byte of evidence on the machine you control.

AdGUARD dashboard showing overall compliance and per-service scores

Posture at a glance

A weighted score per service, ranked from weakest to strongest, plus a trend line that carries each service's last known result forward — so a targeted re-audit never fakes a drop.

Comparison between two audits highlighting regressions and improvements

What changed since last time

Pick two runs. Regressions come first — controls that were compliant and no longer are. Improvements, additions and scope changes follow. This is the slide that renews an engagement.

Client list with per-company audit counts and scores

Your whole book of business

Every client in one table: last audit, current score, connectors configured. Sort it, search it, and open any engagement without touching another one's data.

Company record showing details, activity, last audit breakdown and the detected Active Directory licences

A record per client, with its licences detected

Each company carries its own details, engagement reference and activity: audits run, last score, overall score, configured connectors and the breakdown of the last run. The domain and forest are read straight from LDAP the first time you connect — functional level, DC inventory, trusts and the AD CS role shown as present or absent — so you know a client's topology before you scope the audit. The domain then prints under the company name on every report.

Control catalog grouped by category with level badges

The catalog, open to inspection

Browse all 173 controls before you run anything. Each shows its category, level and framework mapping, so you can tell a client exactly what you will and won't be testing.

Connector configuration screen for Microsoft services

Connect only what you need

Each domain has its own connection. Audit one domain on Monday and add another next month — controls without a configured connector are skipped, and the app says so rather than failing quietly.

See everything — the full tour, screen by screen →

Scoping

Not every audit should run all 173 controls.

A first pass, an ISO 27001 certification file and a monthly re-check are three different questions. A baseline is how you decide in advance — and in writing — which controls a given engagement answers, so the scope is a deliberate decision rather than whatever the tool happened to test.

Baseline editor: control list with include checkboxes, referential column and per-control level override

The baseline editor

Include or exclude any control, and override its level where your judgment differs from the default. Three counters — active, excluded, re-levelled — show how far the scope has moved from the full catalogue, and modified only filters straight to what you changed. Nothing is committed until you save: an unsaved baseline is flagged as a draft.

Template gallery showing framework templates with the number of controls kept and how many are runnable

Twelve templates to start from

Each template keeps the controls mapped to a framework and excludes the rest. The count is computed from the live catalogue rather than written into a brochure — and a second figure tells you how many of those controls are actually runnable given the connectors you have configured, so you know what a template will really cover before you commit to it.

Scope

Global, or specific to one client

A global baseline is your firm's house methodology, reused on every engagement. A client baseline covers the exception you agreed with one customer — the control they have formally accepted the risk on — without polluting anyone else's audit.

Levels

Severity is a judgment call, so it's editable

A control that is standard in a fifty-seat firm can be critical in a regulated one. Re-level it per baseline and the weighting in the score and the remediation ordering follow, with the count of re-levelled controls visible so a reviewer can see you did it.

Traceability

The baseline is recorded with the run

Applying a baseline to an audit stores which controls were in scope and at what level. Two audits run under the same baseline are directly comparable; a scope change shows up in the comparison instead of quietly distorting the score.

Running an audit

One click. The audit does the rest.

The scope is already decided by the baseline, so starting an audit is a single button. What follows is not a progress bar you leave running over lunch: the controls in scope are evaluated live across the selected services, with each finding appearing the moment it is produced.

Audit in progress: overall percentage, per-service counters and controls being analysed with their status

You watch it work

A counter per service and one overall — 81 / 194 here — with the controls streaming past as they are evaluated. Each row carries its service, its level and its verdict, and a finding that needs explaining gets its sentence immediately: "7 service principals hold a directory role: these identities escape MFA and PIM, their justification must be documented." Nothing is buffered until the end.

Completed audit showing 100% done, compliance score, compliant, non-compliant and warning counts, and duration

And it tells you how long it took

Done: 51 % compliance, 64 compliant, 48 non-compliant, 82 warnings — in 16.1 seconds. The header keeps controls enabled out of 173 in view throughout, so a partial run can never be mistaken for a full one, and one click goes straight to the detail.

Audit detail: counters for controls, compliance, compliant, non-compliant and warnings, filters, HTML and PDF export, and an expanded control showing result, description, remediation and framework references

Then every control, one click deep

Five counters across the top, a search box and filters by referential and by level. Open a row and you get what an assessor has to write anyway: the observed state — "krbtgt password last set 1,240 days ago — rotation overdue" — what the control tests, the remediation as a portal path, and the references it satisfies: CIS Active Directory · NIST IA-2 · ISO 27001 A.8.5. Export is HTML or PDF, and the screen states that it covers the whole audit rather than the filtered view.

Audit history listing each run with its scope, score, counts and trend against the previous run

Every run is kept, with its scope

Date, number of controls evaluated, the services actually included, the score and the three counts — plus the movement against the previous run, already computed. A run over 19 controls sits next to one over 194 and is visibly not the same exercise, which is exactly what you want before you compare them.

Three outcomes

Compliant, non-compliant, or a judgment call

82 of those 194 results are warnings — a setting that isn't a failure but that an assessor should look at, like certificate-based authentication being disabled. A pass/fail tool has to round every one of those in some direction; here they stay visible as what they are.

Trend

Movement without arithmetic

Each history entry shows how it moved against the run before it — stable, up two points, down thirteen. You know whether last month's remediation worked before opening anything, and the full comparison is one button away.

Export

The whole audit, not the filtered view

HTML and PDF from the results screen, and the app states plainly that the export covers the entire audit rather than whatever your current filter shows — a small thing that stops a client receiving an accidentally truncated report.

Performance

Speed is a setting, not luck.

Controls are evaluated in parallel. The right number at once depends on the workstation and on how much load LDAPs will tolerate — so instead of hard-coding a guess, the application exposes the setting and measures the correct value on the machine that will actually run the audits.

Performance settings: concurrent analysis thread slider and a parallelism benchmark comparing run times at 1, 2, 4, 8 and 16 threads
Settings › Performance — the thread slider and the on-device benchmark.
  1. Eight controls at a time, adjustable from one to sixteen

    The default suits most machines. Lower it on a constrained VM or a fragile domain, raise it on a workstation with headroom — it takes effect on the next run, with nothing to reconfigure.

  2. Throttling is accounted for, not ignored

    The screen states the trade-off plainly: more threads means more concurrent LDAP reads against the domain controllers. The queries are read-only and lightweight, so a high setting mainly changes audit speed, never the integrity of a client's directory.

  3. A benchmark that runs on your hardware

    One click simulates an audit at each thread level and times it. On the machine in that screenshot: 0.99 s sequential, 0.34 s at eight threads — 2.9× faster — and slower again at sixteen. The curve is measured, not assumed, so the tool recommends eight instead of maxing the slider, and applies it for you.

This is the mechanism behind the sixteen-second run in the section above, and it is the kind of thing that decides whether an auditor uses a tool twice. Anyone who acquires the product gets the knob and the benchmark along with the rest of the source.

What you hand over

Four reports, four audiences.

The same audit produces the document each reader actually needs — from a one-page board summary to a line-by-line remediation plan an engineer can work through.

Executive summary

Cover page under your brand and the client's, overall posture, per-service breakdown, and the findings that matter to a board.

PDFHTMLXLSXCSVJSON

Detailed audit

Every control, its verdict, the objects concerned, and the reference it was tested against.

PDFHTMLXLSXCSVJSON

Framework compliance

The same results re-cut by CIS, NIST, ISO 27001 and ANSSI — the view an assessor asks for.

PDFHTMLXLSXCSVJSON

Remediation plan

Failures ordered by weight, with the portal path and PowerShell command for each fix.

PDFHTMLXLSXCSVJSON

Download sample reports

Real AdGUARD output on a demo domain — domain details blurred, results untouched.

Executive report (PDF) Executive (HTML) Remediation plan Framework matrix Detailed report

How an engagement runs

First audit in an afternoon.

Add the client

Create the company record. Its name is what appears on every report you export for them.

Connect the services

Register a read-only application in the domain — the app walks you through it — or point it at an existing one.

Choose the scope

Run the full catalog, or apply a baseline: CIS level 1 for a first pass, ISO 27001 technological controls for a certification file, or your own saved selection.

Run it and deliver

The audit executes read-only against the APIs. Export the report your client needs, under your brand, and keep the run in history for the next comparison.

Read the full audit guide — scope, pitfalls and cadence →

Security & privacy

The audit tool shouldn't be the weak link.

You're asking a client for access to their identity platform. Here is exactly what happens to it.

Read-only

Every check is a read. The application holds no write permission and changes no setting in any domain — a client can verify it on their own consent screen.

On your machine

No vendor backend, no telemetry, no upload. Audit results, findings and reports are written to your workstation and go nowhere else.

Encrypted secrets

Client secrets and service account passwords are encrypted with Windows DPAPI, scoped to your user account. A copied settings file is unreadable elsewhere.

Retained evidence

Audit history is kept for three years — a full ISO 27001 certification cycle — so you can show a trajectory, not just a snapshot.

Under the hood

Written for the engineer who has to approve it.

The person who decides whether an audit happens is rarely the person who commissioned it. It is the client's IT or security lead, who will want to know what gets installed, what it is allowed to touch, and what happens on a domain considerably larger than a demo.

Windows desktop LDAP API OAuth 2.0 client credentials Certificate authentication Windows DPAPI Local storage, no backend HTML · PDF · XLSX · CSV · JSON

Delivery

An executable, not a platform

A Windows desktop application. There is no server to stand up, no agent to deploy on endpoints or domain controllers, no inbound firewall rule and no service account running permanently somewhere. It runs under the consultant's own session, for as long as the audit takes, and then it stops.

Data path

Workstation to Microsoft, and nowhere else

Outbound HTTPS to Microsoft endpoints. Results are written to a local store on the machine that ran the audit. There is no vendor backend in the path, so there is no third party to add to a client's processor register.

Execution

Parallel, read-only, deterministic

Controls are evaluated concurrently with a configurable thread count, and the LDAP client serialises reads against each domain controller, so an aggressive configuration changes audit speed, not the load profile on a client's directory. The same baseline evaluates the same controls in the same order every time.

Scale

Tested where it matters

Run against production domains with several thousand users, where collections have to be paged rather than fetched in one call and where a naive implementation either times out or silently truncates. Directory size changes how long the paging takes; it does not change which controls run or what they conclude.

Partial coverage

Missing connector, honest result

Audit one domain today and add another next month. Controls with no configured connector are reported as out of scope and counted as such, never as failures — the compliance score is computed on what was actually evaluated, and the run states how many controls that was.

Credentials

Encrypted, per user, per client

Certificates, client secrets and service account passwords are encrypted with Windows DPAPI scoped to the user account, stored per client workspace. A settings file copied to another machine is unreadable, and one client's credentials are never loaded while auditing another.

What each connector is granted

Connector Authenticates as Rights required Write access
Microsoft Active Directory A standard domain account, used to bind to the directory over LDAP (389) or LDAPS (636) with integrated Windows authentication. No application registration, no certificate and no secret to store or rotate. Read directory objectsRead nTSecurityDescriptorRead schema & configuration NC
Ordinary read access any authenticated user already has — visible to the client, and nothing is written back.
None
Forest & configuration The same domain account reads the configuration and schema partitions — AD CS, sites, trusts and ADIDNS checks reuse it. No additional grant, and no second credential to store or rotate. None
LDAPS (optional) Where certificate-signed LDAP is enforced, the same account binds over LDAPS on 636 — recommended so directory reads are encrypted in transit. No extra privilege; only the DC's LDAPS certificate needs to be trusted by the workstation. None

The column that matters is the last one. Not “write access we promise not to use” — write access that was never requested, which is why a client can verify the claim on their own consent screen in about fifteen seconds rather than taking your word for it.

For auditors & assessors

Evidence, not opinion.

An assessment stands or falls on whether someone else can re-run it and reach the same conclusion. AdGUARD was built around that constraint: every verdict carries the control it came from, the objects it looked at, and the date it was taken.

Traceability

Every finding names its objects

A non-compliant control doesn't just say "fail". It lists the accounts, mailboxes, policies or resources that caused it, timestamped and attributed to the domain it was read from — the level of detail a working paper actually needs.

Reproducibility

Same baseline, same result

Scope is declared as a baseline and stored with the run. A second assessor applying the same baseline to the same domain evaluates the same 173 checks in the same order, and any difference is a real change in the environment.

Independence

Read-only, so it can't disturb what it measures

The tool holds no write permission, so running an audit never alters the environment under assessment and never competes with the client's own change process. The consent screen is the proof.

Framework view

Re-cut by CIS, NIST, ISO 27001 and ANSSI

The same run produces a compliance view per framework, with the clause reference on each control — so a certification file, a client questionnaire and a gap analysis all come out of one execution.

Working papers

CSV and JSON, not just PDF

Results export as structured data for sampling, for a GRC platform, or for whatever spreadsheet your methodology already runs on. Nothing has to be retyped out of a report.

Continuity

Three years of history

Runs are retained for a full ISO 27001 certification cycle, so a surveillance audit can be answered with a trajectory — what was found, what was fixed, and when — instead of a fresh snapshot.

Why now

The demand isn't a trend. It's a calendar.

Active Directory are the identity layer for most organisations, credentials are how most intrusions now begin, and a run of regulations has turned “we take security seriously” into “show us the evidence.” None of those three reverses next year, which is what separates a market from a wave.

The install base

Everyone is a candidate

Active Directory is the backbone every workstation, server and application authenticates against. Auditing it means auditing the thing everything else depends on — and there is no vertical to specialise into, because the domain is the same shape at a law firm, a hospital and a manufacturer.

The attack path

Intrusions start with a valid login

Incident reporting has converged on the same finding for several years running: attackers increasingly sign in rather than break in. That moves identity configuration out of IT hygiene and into the first question an insurer, a board or a forensic team asks after an incident — and the first one asked before it.

The obligation

Evidence, on a deadline

NIS2, DORA, ISO 27001:2022, SOC 2, CMMC, HIPAA. Different scopes and different regulators, one shared requirement: documented, repeatable proof that access controls are configured the way you say they are. A screenshot pasted into a Word document stopped being an answer.

The bottleneck

Demand is not the constraint

The organisations being asked mostly cannot answer for themselves, so they ask their MSP or their consultancy — who answer by hand, in a spreadsheet, over two days per domain. What limits this market is not appetite. It is the number of people who can produce the evidence, which is exactly what a tool changes.

NIS2EU Directive 2022/2555

Member states had to transpose it by October 2024; national enforcement has been ramping since. It pulls in far more mid-sized entities than the directive it replaced, and requires risk management measures to be demonstrable rather than declared.

DORAEU Regulation 2022/2554

Applicable since January 2025 to EU financial entities and, critically, to their ICT service providers. Access control and authentication sit squarely inside the resilience requirements.

ISO 27001:2022Annex A.5 and A.8

Certificates issued against the 2013 version had to migrate by October 2025. The 2022 Annex A puts configuration, access management and logging explicitly in scope — the exact ground a domain audit covers.

CMMCUS Department of Defense

Phased into defense contracts from 2025, flowing down the supply chain to companies with no security team at all. Access control and identification and authentication account for the largest share of the requirements.

SOC 2 · HIPAAongoing, and tightening

Neither is new, but the evidence bar keeps rising: anyone selling software to a US enterprise is asked for CC6 and CC7 evidence, and any organisation touching health data is asked for its technical safeguards in writing.

Deliberately absent from this section: a market-size forecast. Anyone can buy one, nobody can verify it, and every line above can be checked against a published text instead. The point is not that the market is large — it is that the obligations have dates on them, and the people being asked still answer by hand.

For consultancies & MSPs

Buy it once, then use it for all your own clients.

Most Microsoft-focused consultancies and MSPs sell licenses, migrations and managed services, then subcontract the security review. Here you bring it in-house: you buy the right to use the product across your whole client base, under your own brand — you are not reselling the software, you are adding an audit line to your own services, priced however you want.

Your price list

You decide what an audit is worth

Charge per audit, per domain, per quarter, or fold it into an existing retainer. Nobody sets a floor, nobody sets a ceiling, and no part of what you invoice comes back to us.

Your economics

One capex line, then pure margin

A single fixed cost paid once, against revenue that repeats on every engagement. The tenth audit you sell costs you nothing to deliver beyond your engineer's time.

Your organisation

Deploy it as widely as you like

Every consultant, every office, every legal entity in the group. There is no seat count to declare and no license server to check in with.

Your methodology

Adapt it to how you work

Add your own controls through importable packs, apply your baselines, and export straight into the GRC platform your practice already runs on — without touching the source code.

Your clients

No vendor behind you

We never appear in front of your clients, because after the sale there is no relationship to appear in. No co-branding to negotiate, no deal registration, nobody to lose the account to.

Your differentiation

A product your competitors don't have

Competing firms bid the same subcontracted review at the same day rate. A tool carrying your own name, producing evidence in a day, is a different conversation in a tender.

Your activation machinery

You issue the licence keys. We never see your clients.

Using the product across your own engagements only works if you can activate an installation without asking anyone's permission. The generator that produces those keys is part of what you buy — a separate tool you keep, alongside the activation screen it feeds.

Licence generator: client name, validity in days, maximum domains, generate, copy or save to license.key

The generator, delivered with the product

A client name, a validity in days — 365 for a year, 3650 for ten — and a domain ceiling. Generate, copy, or write it straight out as license.key. Every commercial decision you make is expressed in those three fields, which means your price list can be whatever you want it to be: annual, multi-year, metered by domain, or a fortnight's trial for a prospect.

Activation screen showing licence status with client name, expiry date, allowed domains and identifier, plus a field to paste a new key

What activation looks like

Paste, activate, done — operational immediately, with no restart. From then on the status card states plainly which engagement the licence covers, when it expires, how many domains it allows and its identifier, so an internal check starts with facts rather than questions. Nothing here carries our name.

Your terms

Duration and domain count, per key

The two fields that define a key are yours to set for every engagement. A one-year, five-domain key for a small mandate and a ten-year unlimited one for a large programme are the same amount of work: fill in two boxes.

Your ceiling

Unlimited across your own organisation

The domain cap is there so you can scope each installation — 9999 is unlimited in practice, and that is what your main key looks like. How you split keys across offices, teams or mandates is your call, not a product limitation.

Your pipeline

No activation goes through us

You generate keys on your own machine. We are not in the loop, which means no waiting on our office hours to start an engagement, and no list of your clients sitting in someone else's records.

Your evaluations

A short-lived key costs you nothing

Issue a fourteen-day key for a scoping exercise or a prospect audit you run yourself. It expires on its own, so there is no licence to chase and no reason to be cautious about running evaluations.

Price & licence

One price. One transaction. Yours to use.

There is no licensing ladder, no domain count to declare, no renewal and no revenue share. You buy AdGUARD once, at a fixed price that is the same for everyone, and use it for all your own clients under your own brand — perpetually, without limit. The one condition, written into the sale contract, is that you do not resell or redistribute the application itself: you sell your audit service, not the software.

  • The application, packaged and ready to run
  • The 173-control catalog with its CIS, NIST, ISO 27001 and ANSSI mappings
  • Report templates and technical documentation
  • Complete rebranding: name, logo, icons, installer, domain
  • The licence generator, so you activate it across your own organisation
  • A transition period with the author
  • Optional, by separate agreement: access to the source code

Yours in name

Nothing refers to us

Product name, logo, icon set, installer, in-app identity, documentation and every exported report carry your brand. Once delivered, the word AdGUARD appears nowhere in what you ship.

Yours to adapt

Extensible without the source

Add your own controls through importable packs, apply your baselines, brand every report and plug it into your GRC stack. Source-code access, for deeper changes, is available only under a separate prior agreement.

Yours to use

You set the prices

Per audit, per domain, bundled into a retainer, or given away to win the migration behind it — your commercial model, your contracts, your margin. We take no share of anything you invoice. What you may not do is resell the application itself.

Yours to run

No limit to declare

Unlimited domains, unlimited clients, unlimited engineers, unlimited installations, in as many offices or entities as you have. Nothing meters your use and nothing expires.

How it runs: a mutual NDA, a technical review so you see exactly what you are buying, one contract, then handover. Ongoing maintenance — AD schema and framework changes, CIS revisions, new controls — is available as a separate annual contract if you want it, and entirely optional: the product you bought keeps working either way.

For investors & acquirers

What is actually being sold.

The market case is set out above. What is on the table here is a finished, shipping product positioned inside it: the asset is the control catalog, the framework mappings and the engine that runs them.

173

Implemented controls

Every one backed by a live LDAP read — the catalog is the barrier to entry, and it took years of Active-Directory-specific work

8

AD control families

Privileged access, attack paths, Kerberos, AD CS, DC hardening, passwords, domain config, trusts, LAPS, ADIDNS, GPO

4

Frameworks mapped

CIS, NIST 800-53, ISO 27001 and ANSSI — the mapping layer is what makes the output sellable to auditors

0

Cloud infrastructure

Desktop delivery means no hosting cost, no data-processor liability and gross margin that doesn't degrade with volume

The market

Sold to the people who audit, not the people audited

MSPs, consultancies and audit firms buy the product outright and monetise it across their whole client portfolio — a single high-ticket transaction instead of a per-seat grind, with an optional annual maintenance contract behind it.

Defensibility

The catalog is the moat

Building 173 working checks across the Active Directory attack surface, then keeping them aligned with CIS revisions and Microsoft's own changes, is slow work that cannot be shortcut with a wrapper around a point-in-time script.

Expansion

Adjacent products already scoped

The same connectors and control model extend to guest lifecycle governance, continuous monitoring and a hosted multi-domain portal — near-term additions rather than a second product to invent.

What transfers

Code, catalog, brand and domain

A transaction can cover the source code and IP, the control catalog and its framework mappings, the report templates, the AdGUARD name and domains, and a defined transition period with the author.

Structures

Outright, majority, or a build partnership

Full acquisition, an equity stake with the founder continuing development, or a funded roadmap with exclusive distribution rights — the structure is open.

Diligence

Data room under NDA

Financials, customer detail, roadmap, architecture documentation and a technical walkthrough of the codebase are available to qualified parties once an NDA is in place.

Serious enquiries only, please — use the form below and select Investment or acquisition. An NDA can be executed the same week.

After the purchase

It runs on its own. That doesn't mean you're on your own.

Nothing in the agreement obliges you to come back to us, and nothing in the product requires it — it ships ready to run, with its full documentation. But the engineers who wrote it are still available, and most buyers would rather have a change built in a week than staffed internally in a quarter.

Evolution requests

Ask for a change, get a build

A new control, another connector, a different report layout, an export one of your clients insists on. The engineers who built the 173-control catalogue turn it around fast and hand it back as a build you can ship — no source-code access required on your side.

Documentation

A complete guide, and the technical set

An end-to-end application guide you can put your own cover on and hand to your consultants or your clients, plus what your engineers need: architecture, control catalogue, connector model, build and release process.

Web presence

A professional site for the product under your name

Exactly what you are reading. This page is the example: a one-page site built around the product, its screenshots and its argument — rebuilt under your brand, your name and your positioning, ready to publish.

Content

And a blog, if you want to be found

What makes a site like this rank is not the design but what sits behind it — the fourteen articles already published here are the example. We can write and structure the content — Active Directory auditing, CIS benchmarks, Active Directory hardening — for a product that carries your name rather than ours.

All of it is optional and quoted separately. The purchase price covers the product: none of these are gates you have to pay to get through, and the application works without a single one of them.

Questions we get

Before you commit.

Does it need Domain Admin?

No. The audit runs read-only over LDAP with a standard domain account — any authenticated user can read the directory. No privileged role is required, nothing is installed on a domain controller, and the schema is never modified.

How many domains does it cover?

There is no limit, because there is nothing to meter. The application manages client companies side by side, each with its own connectors, history and branding, and the purchase covers as many as you ever open — one or five hundred.

Exactly which access are we granting?

Read access to Active Directory over LDAP (389) or LDAPS (636) with integrated Windows authentication — a standard domain account is enough. No write access is requested anywhere, no agent is deployed, and nothing on the domain controllers is changed.

Does anything leave our network?

Nothing. The tool talks only to your domain controllers over LDAP, from your workstation. There is no vendor backend, no analytics, and no upload of findings. Reports are files on your disk until you choose to send them.

Can we add our own controls?

Yes. The catalog loads from control packs, and you can import additional packs alongside the official ones. Custom checks can be defined declaratively with an LDAP filter.

How long does an audit take to run?

Seconds, not minutes. A full 173-control run completes in well under a minute on a normal workstation, because the controls are direct LDAP reads rather than scripts spawning sessions. The time in an engagement goes into reading the findings, not waiting for the tool.

Does running controls in parallel strain the domain controllers?

No. Queries are read-only, lightweight LDAP reads serialised against a domain controller, so parallelism speeds up the audit without adding write load. The default is eight concurrent controls, adjustable from one to sixteen, and a built-in benchmark measures the optimum on your own machine.

Can we see it working before buying?

Yes, and you should. We run a full audit against one domain of yours, with your engineers watching, and you keep the reports whatever you decide afterwards.

Is there really only one price?

Yes. One figure, the same for a two-person consultancy and for a group with forty offices, covering the product and the right to use it commercially for your own clients, under your own brand. There is no tier above it. The only optional extra is an annual maintenance contract, and the product works without it.

Is the source code included?

No. The standard offer is the application as a ready-to-run product, with its control catalog, framework mappings, report templates and technical documentation. Source code is not part of the package — it can be provided only under a separate prior agreement.

How do we deploy it across our clients?

You generate the keys yourself, with the licence generator that ships with the product: a client name, a validity in days and a maximum number of domains. You activate it on the installations you run for your own engagements — it is operational immediately, with no restart. The software stays yours to use, not to hand over.

Can we resell it to our own clients?

No. You buy the right to use the product for your own clients — running the audits and delivering the reports under your own brand — but reselling or redistributing the application itself is not permitted, and that restriction is written into the sale contract. You sell your audit service, not the software.

Is there any support after the sale?

Yes, and all of it optional. Our engineers take evolution requests on demand — new controls, new connectors, report changes — and we can supply a complete application guide, the technical documentation, a professional website for the product under your name, and the blog content behind it. Priced separately; the product needs none of it to work.

Are you open to investment or an acquisition?

Yes, and to structures short of a full sale — an equity stake, a funded roadmap, or exclusive distribution. Financials, architecture documentation and a code walkthrough are available under NDA. Ask through the form and say which structure interests you.

Get the terms

One price, and nothing hidden behind it.

Ask and you get the figure, the contract and what happens on handover — not a discovery call to qualify you first. Answers usually come the same business day.

  • The price, in writing, with the contract terms
  • A mutual NDA, signed the same week if you want one