Active Directory Security Risk Assessment Questionnaire Form
Evaluate your organization's Active Directory security posture by completing this focused assessment. This form uses a clean, minimal design and covers key areas of AD security risk.
How often are user accounts reviewed for inactivity or unnecessary access?
*
Rows
Frequency
Monthly
1
Quarterly
2
Annually
3
Never
4
Which best describes your organization's password policy for Active Directory accounts?
*
Strict (complexity, length, expiration enforced)
Moderate (some requirements enforced)
Minimal (few requirements enforced)
No policy
Rate the effectiveness of privileged account management in your Active Directory environment.
*
1
2
3
4
5
Are administrative accounts separated from standard user accounts?
*
Yes, always
Sometimes
No
How frequently are Group Policy Objects (GPOs) reviewed and updated?
*
Rows
Review Frequency
Monthly
5
Quarterly
6
Annually
7
Rarely/Never
8
Which of the following auditing/logging practices are in place for Active Directory?
*
Logon/logoff auditing
Privilege use auditing
Directory service access auditing
No auditing practices
To what extent are security baselines (such as CIS or Microsoft Baselines) applied to domain controllers?
*
Not at all
1
2
3
4
Fully applied
5
1 is Not at all, 5 is Fully applied
Does your organization use Multi-Factor Authentication (MFA) for privileged Active Directory access?
*
Yes, for all privileged accounts
For some privileged accounts
No
How would you rate your organization's incident response readiness for Active Directory threats?
*
1
2
3
4
5
Please describe any recent security challenges or concerns related to Active Directory.
Submit Assessment
Should be Empty: