Active Directory Security Audit Checklist Form
Complete this checklist to assess the security posture of your Active Directory environment.
How strong are your password policies (length, complexity, expiration)?
*
Very Weak
1
2
3
4
Very Strong
5
1 is Very Weak, 5 is Very Strong
Are group memberships reviewed regularly for unnecessary or excessive privileges?
*
Always
Sometimes
Rarely
Never
Privileged Account Monitoring
*
Rows
Yes
No
Not Applicable
Are privileged accounts monitored for unusual activity?
1
2
3
Is use of privileged accounts logged and reviewed?
4
5
6
Are auditing and logging enabled for critical changes in Active Directory?
*
Enabled and reviewed regularly
Enabled but not reviewed
Not enabled
Account Lockout Policy
*
Strict (locks after few attempts)
Moderate
Lenient (rarely locks accounts)
No lockout
How often are unused or stale accounts identified and removed?
*
Monthly
Quarterly
Annually
Never
Administrative Delegation Practices
*
Rows
Yes
No
Not Sure
Are admin rights delegated using least privilege principles?
7
8
9
Are changes to administrative roles documented?
10
11
12
How would you rate the enforcement of multi-factor authentication (MFA) for AD access?
*
Not Enforced
1
2
3
4
Fully Enforced
5
1 is Not Enforced, 5 is Fully Enforced
Patch Management
*
All DCs and AD servers patched promptly
Most servers patched, some delays
Occasional patching
Rarely patched
How confident are you in your AD backup and restore procedures?
*
Not Confident
1
2
3
4
Very Confident
5
1 is Not Confident, 5 is Very Confident
Submit Checklist
Should be Empty: