Active Directory Configuration
GPOs, OU structure, password policies, and domain hygiene
Active Directory is the oldest thing in most environments and the least often reviewed. It accretes. Group policies stack on top of each other, service accounts get domain admin because it was the fastest way to make something work on a Friday, and leavers keep their accounts because disabling them felt risky.
This library is the periodic clean-out that nobody schedules, turned into checks with owners.
What this library checks
- OU structure and whether it still reflects how the organisation actually works
- Group Policy inventory, conflicting policies and unlinked objects
- Domain Admin, Enterprise Admin and Schema Admin membership, reviewed by name
- Service accounts, their privilege level, password age and interactive logon rights
- Stale user and computer objects past a defined threshold
- Password policy, lockout policy and fine-grained policy exceptions
- Domain controller health, replication, FSMO placement and backup posture
- Kerberos delegation settings and unconstrained delegation
Evidence you will be asked for
Every check in Spectra Core carries its own evidence. These are the artefacts an auditor, insurer or board most often wants to see for this area.
- Named list of privileged group members with business justification for each
- Stale account report with the disable or retain decision recorded
- Password and lockout policy export
Where this usually goes wrong
Privileged group membership is the single most common audit finding in small and mid-sized environments, and it is almost never malicious. It is a temporary grant from three years ago that nobody revoked.
Run this library against your environment
Every check comes with a risk level, a review frequency, an assignee and a plain-language rationale, so the output reads for leadership as well as for engineers.
Other libraries
Remote Monitoring & Management
Alerting, patching, agent health, and endpoint visibility standards
Network Environment
Switching, routing, Wi-Fi, DNS, and network segmentation checks
Network Security
Identity, access management, and endpoint protection / EDR standards
Microsoft 365 Security
Identity threat detection and response, conditional access, and tenant hardening
Backup & Disaster Recovery
On-premise DR systems and Microsoft 365 backup configuration checks
Server Rooms
Physical environment, cooling, fire suppression, and monitoring standards