02Professional services

A directory one workstation cannot own.

Active Directory design and remediation, Group Policy that is readable, and Windows Server and IIS administration. The work is mostly about one question: which credentials can reach which machines, and what happens when one of them is stolen.

0
Tiers separated in every directory we design
0
Standing domain admin sessions left in place
0%
Policy rolled out in audit mode first
0
Domain controllers minimum, per site
The problem

Almost every domain compromise is the same compromise.

Someone gets a foothold on a workstation. A helpdesk account with local admin everywhere has logged into that workstation at some point, and its credentials are still in memory. That account can write to a server. On that server, a service account with excessive rights is running. Two hops later the attacker is domain admin, and none of it required an exploit.

The controls that break that chain are not exotic. Tiering, so an administrative credential is only ever typed on machines at its own tier. LAPS, so the local administrator password is different on every machine. Constrained delegation and managed service accounts, so a service is not carrying a password that was set in 2019 and never changed.

What makes them hard is not the technology, it is the rollout. Enforcing AppLocker on a Monday morning without knowing what it will block is how these projects get abandoned halfway. Everything we deploy runs in audit mode first, long enough to produce a list of what enforcement would have stopped, so the enforcement date is a scheduled change rather than a support incident.

The directory

Where a policy applies, and what it actually does.

The structure carries the security model. Each OU exists because something is linked to it, and every link has a reason written next to it.

Directory structure

Server OU

Linked GPOs
6
Inheritance
blocked, explicit links
Tiering
T0 / T1 separated
Local admin
LAPS, rotating

Tier 0 assets never accept a logon from a tier 1 credential, which is the control that stops one workstation becoming domain admin.

Scope

What we take on

01

Directory design and remediation

Forest and OU structure, functional levels, replication, and the FSMO layout.

Whether it is a greenfield design or a directory that has grown for fifteen years, the output is the same: a structure where every OU exists for a reason, roles are split rather than stacked on one box, the recycle bin is on, and a restore has actually been performed rather than assumed to work.

AD DSsites and servicesFSMOreplication
02

Privileged access tiering

Tier 0 credentials usable from a handful of machines, and nowhere else.

Accounts that can rebuild the directory are separated from accounts that administer servers, which are separated from accounts that read email. Logon restrictions are enforced with policy rather than requested in a document, and administration happens from dedicated workstations, which is the control that stops one compromised laptop becoming a domain compromise.

Tier 0PAWlogon restrictionsMFA
03

Group Policy that is readable

Fewer objects, explicit links, and a written record of what each one is for.

Most estates have accumulated dozens of GPOs, several contradicting each other, with inheritance patched by blocks and enforcements until nobody can predict the result. We consolidate to a set you can hold in your head, model the resultant policy before anything moves, and document each link.

GPORSoPWMI filterscentral store
04

Service accounts and delegation

Managed accounts with rotating passwords, and delegation that is constrained.

Static service passwords get migrated to group managed service accounts wherever the application supports it. Unconstrained delegation is removed, duplicate SPNs are cleaned up, and the accounts that cannot be migrated yet are listed as a backlog rather than quietly excluded from the report.

gMSASPNKerberosLAPS
05

Windows Server and IIS

Server builds, roles, and web estates with isolated application pools.

Standard builds for file, print, application, and web servers, with each IIS pool running as its own identity so one compromised application does not inherit the rights of every other site on the box. TLS configuration, request filtering, and certificate automation included rather than left as a follow-up.

IISapp poolsTLS 1.2 / 1.3ADCS
06

Patching and endpoint policy

A ring-based update schedule and endpoint controls that were tested before enforcement.

Updates released in rings, with a pilot group, a schedule, and reporting on what actually installed rather than what was approved. AppLocker or WDAC, BitLocker with a recovery key you can find, and legacy protocols removed once the audit logs show what would break.

WSUSIntuneAppLockerBitLockerDefender
How it runs

Nothing gets enforced before it has been watched.

Week 1

Assess

A read-only collection across the directory: privileged group membership, delegation, GPO sprawl, stale objects, and the paths between them.

Weeks 2 to 3

Design

The target structure and tier model, written down, with the exceptions your applications need recorded as accepted risks.

Weeks 4 to 8

Stage

Policy deployed in audit mode to a pilot group, the blocked-by list reviewed with you, then enforcement on an agreed date.

Ongoing

Operate

Patch rings, directory hygiene, and a quarterly review of privileged membership, because it grows back if nobody looks.

Tools we work in
Windows Server 2016 to 2025Active DirectoryGroup PolicyEntra IDLAPSgMSAADCSADFSIISWSUSIntuneDefender for EndpointPowerShellDSCHyper-VDFS-RBitLockerAppLocker

Find out what a stolen laptop reaches.

The assessment maps the paths from an ordinary workstation to domain admin, and most of them close without buying anything.