A directory one workstation cannot own.
Active Directory design and remediation, Group Policy that is readable, and Windows Server and IIS administration. The work is mostly about one question: which credentials can reach which machines, and what happens when one of them is stolen.
Almost every domain compromise is the same compromise.
Someone gets a foothold on a workstation. A helpdesk account with local admin everywhere has logged into that workstation at some point, and its credentials are still in memory. That account can write to a server. On that server, a service account with excessive rights is running. Two hops later the attacker is domain admin, and none of it required an exploit.
The controls that break that chain are not exotic. Tiering, so an administrative credential is only ever typed on machines at its own tier. LAPS, so the local administrator password is different on every machine. Constrained delegation and managed service accounts, so a service is not carrying a password that was set in 2019 and never changed.
What makes them hard is not the technology, it is the rollout. Enforcing AppLocker on a Monday morning without knowing what it will block is how these projects get abandoned halfway. Everything we deploy runs in audit mode first, long enough to produce a list of what enforcement would have stopped, so the enforcement date is a scheduled change rather than a support incident.
Where a policy applies, and what it actually does.
The structure carries the security model. Each OU exists because something is linked to it, and every link has a reason written next to it.
Server OU
- Linked GPOs
- 6
- Inheritance
- blocked, explicit links
- Tiering
- T0 / T1 separated
- Local admin
- LAPS, rotating
Tier 0 assets never accept a logon from a tier 1 credential, which is the control that stops one workstation becoming domain admin.
What we take on
Directory design and remediation
Forest and OU structure, functional levels, replication, and the FSMO layout.
Whether it is a greenfield design or a directory that has grown for fifteen years, the output is the same: a structure where every OU exists for a reason, roles are split rather than stacked on one box, the recycle bin is on, and a restore has actually been performed rather than assumed to work.
Privileged access tiering
Tier 0 credentials usable from a handful of machines, and nowhere else.
Accounts that can rebuild the directory are separated from accounts that administer servers, which are separated from accounts that read email. Logon restrictions are enforced with policy rather than requested in a document, and administration happens from dedicated workstations, which is the control that stops one compromised laptop becoming a domain compromise.
Group Policy that is readable
Fewer objects, explicit links, and a written record of what each one is for.
Most estates have accumulated dozens of GPOs, several contradicting each other, with inheritance patched by blocks and enforcements until nobody can predict the result. We consolidate to a set you can hold in your head, model the resultant policy before anything moves, and document each link.
Service accounts and delegation
Managed accounts with rotating passwords, and delegation that is constrained.
Static service passwords get migrated to group managed service accounts wherever the application supports it. Unconstrained delegation is removed, duplicate SPNs are cleaned up, and the accounts that cannot be migrated yet are listed as a backlog rather than quietly excluded from the report.
Windows Server and IIS
Server builds, roles, and web estates with isolated application pools.
Standard builds for file, print, application, and web servers, with each IIS pool running as its own identity so one compromised application does not inherit the rights of every other site on the box. TLS configuration, request filtering, and certificate automation included rather than left as a follow-up.
Patching and endpoint policy
A ring-based update schedule and endpoint controls that were tested before enforcement.
Updates released in rings, with a pilot group, a schedule, and reporting on what actually installed rather than what was approved. AppLocker or WDAC, BitLocker with a recovery key you can find, and legacy protocols removed once the audit logs show what would break.
Nothing gets enforced before it has been watched.
Assess
A read-only collection across the directory: privileged group membership, delegation, GPO sprawl, stale objects, and the paths between them.
Design
The target structure and tier model, written down, with the exceptions your applications need recorded as accepted risks.
Stage
Policy deployed in audit mode to a pilot group, the blocked-by list reviewed with you, then enforcement on an agreed date.
Operate
Patch rings, directory hygiene, and a quarterly review of privileged membership, because it grows back if nobody looks.
Find out what a stolen laptop reaches.
The assessment maps the paths from an ordinary workstation to domain admin, and most of them close without buying anything.