Skip to content
FirstSIDocs

Active Directory: security and health

Your domain's posture score, domain controller health, directory security alerts, leavers, the access review of sensitive groups and an account's history.

The Active Directory screen answers three questions about your domain: is it well configured, are its domain controllers healthy, and is someone doing something dangerous in it right now? It changes nothing in the directory.

Prerequisites

The agent must run on every domain controller, with the SI-Tracer module, at version 2026.10.11.3 or later (see Manage agents). It sends a health report every 15 minutes. The controller that holds the PDC role also sends the posture snapshot once a day.

The agent turns on the audit subcategories it needs itself, including user and computer account management. One is left to you: Directory Service Access, too verbose to be turned on by default. Without it, DCSync detection stays silent. Group Policy, SPN and delegation detections also depend on the audit lists (SACLs) set on directory objects: if they have been altered, check that they cover these objects.

Alerts and health incidents go through the SIEM: the module must be active for your organisation.

Open the screen

Open SI-Tracer → Active Directory (#/sitracer/ad). Six tabs: Posture, Health, Alerts, Leavers, Access review, Settings.

Posture

The Posture score is a mark out of 100. Each non-compliant item takes points off, with a cap per item; an item that could not be measured takes nothing off. The score is green from 80, orange from 60, red below that.

Score trend shows the curve over 180 days. Items to address lists the gaps with their severity, the value collected, the target and the penalty; Show the … items displays the accounts or machines involved (at most 50).

ItemTarget
krbtgt account passwordchanged less than 180 days ago
Unconstrained delegation outside domain controllers0
Administrators outside "Protected Users" and not marked sensitive0
Number of enabled administrators10 at most
Accounts without Kerberos pre-authentication0
LAPS coverage of computersat least 90%
NTLMv1 authentications (7 days)0
LDAP signing required and LmCompatibilityLevel of domain controllersrequired; level 5
Computers running an end-of-life OS0
Service accounts with an old password, accounts with SIDHistory, orphaned adminCount0
Enabled accounts with no logon for 90 daysat most 2% of enabled accounts
Passwords that never expire, computers with no logon for 90 daysas few as possible
Domain functional level2016 or higher

Only one posture snapshot is kept per day and per domain, for 400 days. With several domains, choose the one to display from the list.

Health

One card per domain controller, with a green, red or grey (unknown) dot per line: Replication, SYSVOL, Time, FSMO roles, LDAP and Kerberos DNS records, Certificates, Backup. LDAP signing and LmCompatibilityLevel are shown without a dot. After 45 minutes without a report, the card turns red with "report overdue".

Each anomaly opens an incident, which closes on its own when things are back to normal:

CheckIncident whenSeverity
Replicationfailures and no success for more than 1 hhigh
SYSVOLstate other than "normal"medium; high in error
Timeoffset beyond 120 shigh; critical beyond 300 s
FSMOa role is unreachablehigh
DNSLDAP or Kerberos SRV record missinghigh
Certificateexpires in less than 30 daysmedium; high under 7 days
Backupmore than 7 days old, or unknownmedium; high beyond 30 days or unknown

Security alerts

The engine reads domain controller events every 2 minutes. When it is first switched on, it starts from the latest events: past history is not replayed. All 14 rules are on by default and open their incidents in the SIEM themselves, with no correlation rule to switch on.

RuleWhat triggers itSeverity
AD-GROUPE-PRIVILEGIEaddition to or removal from a privileged group (Domain Admins, Administrators, Backup Operators…)critical (addition), high (removal)
AD-MASSEa single author disables, resets, deletes or removes from a group more than 10 accounts in 10 minuteshigh; critical at 5 times the threshold
AD-COMPTE-REACTIVEan account with no authentication for 90 days is re-enabledmedium
AD-UAC-RISQUErisky account flag added (password never expires or not required, no pre-authentication…)high (no pre-authentication), medium
AD-DELEGATIONKerberos delegation added to an account or a machinecritical (unconstrained), high
AD-SPN-AJOUTESPN added to a user accountmedium
AD-SIDHISTORYSIDHistory sethigh
AD-KERBEROASTa single account requests RC4 tickets for 5 or more distinct services in 10 minuteshigh
AD-ASREPticket issued without pre-authenticationhigh
AD-DCSYNCreplication requested by an account that is not a domain controllercritical
AD-GPOGroup Policy changed, created or deletedmedium; high (deletion, link at the domain root)
AD-JOURNAL-EFFACEsecurity log cleared on a controllercritical
AD-STRATEGIE-AUDITaudit policy changedhigh
AD-RDP-DCRDP logon on a domain controllermedium

The Alerts tab lists Active Directory incidents (AD-* rules, health included) over 7, 30 or 90 days. Click one to open the incident; All incidents takes you to the SIEM.

Leavers

Enabled accounts inactive for 90 days takes the list from the latest posture snapshot (at most 200 accounts). Click one to open the account profile.

If a Microsoft 365 connector is active, Disabled in Microsoft 365, still present in AD cross-checks both sides. An account appears there if it is disabled in Microsoft 365 and either named in the posture snapshot (inactive, administrator, sensitive group, service account…) or still authenticating against the directory in the last 14 days. Administrators and members of sensitive groups come first.

Access review

The review serves as evidence for an audit (NIS2, ISO 27001): who is a member of the sensitive groups, and who decided to leave them there.

  1. In SI-Tracer → Active Directory, Access review tab, click New review. The members of the sensitive groups from the latest posture snapshot are frozen. Only one review can be open at a time.
  2. For each member, choose Keep or Remove, with a comment if needed, then Save.
  3. Click Close review. The console warns you if some members have no decision. A closed review is frozen.
  4. Export to CSV produces the evidence file: group, member, decision, comment, author and date of each decision.

FirstSI removes nobody from a group. Remove is a decision you apply yourself in the directory.

Creating, deciding and closing are reserved for administrators. Viewing and exporting are open to everyone.

An account's history

The account profile contains a Directory history section: creation, enabling, password change or reset, disabling, group additions and removals, lockouts, renaming, with who did it and on which controller. It covers the last 180 days, whatever period is chosen in the profile (at most 500 events).

Settings

The Settings tab is reserved for administrators. There you choose which rules are active and adjust the thresholds:

SettingDefault
Bulk changes: threshold and window10 actions in 10 min
Kerberoasting: distinct services and window5 services in 10 min
Dormant account after (days)90
Additional privileged groupsempty (the groups already monitored are shown on screen)
Accounts excluded from DCSync detectionEntra sync accounts (starting with MSOL_, AAD_ or Sync_)
Accounts excluded from RDP-on-DC detectionempty

Thresholds accept a minimum of 2, and a minimum of 7 days for a dormant account. Every save is recorded in the audit log, and the tab shows who changed the settings and when.

Frequently asked questions

"No posture snapshot received yet". The snapshot is sent once a day by the controller that holds the PDC role. Check that the agent is installed there, at version 2026.10.11.3 or later, with SI-Tracer active.

No DCSync alert despite a test. Turn on the Directory Service Access audit on the domain controllers.

The review lists an account that has already left the group. The review freezes the members from the posture snapshot at the time it is created. Close it and create a new one after the next snapshot.

Source: · FirstSI Docs · updated 2026-10-11