Active Directory: security and health
Your domain's posture score, domain controller health, directory security alerts, leavers, the access review of sensitive groups and an account's history.
The Active Directory screen answers three questions about your domain: is it well configured, are its domain controllers healthy, and is someone doing something dangerous in it right now? It changes nothing in the directory.
Prerequisites
The agent must run on every domain controller, with the SI-Tracer module, at version 2026.10.11.3 or later (see Manage agents). It sends a health report every 15 minutes. The controller that holds the PDC role also sends the posture snapshot once a day.
The agent turns on the audit subcategories it needs itself, including user and computer account management. One is left to you: Directory Service Access, too verbose to be turned on by default. Without it, DCSync detection stays silent. Group Policy, SPN and delegation detections also depend on the audit lists (SACLs) set on directory objects: if they have been altered, check that they cover these objects.
Alerts and health incidents go through the SIEM: the module must be active for your organisation.
Open the screen
Open SI-Tracer → Active Directory (#/sitracer/ad). Six tabs: Posture, Health, Alerts, Leavers, Access review, Settings.
Posture
The Posture score is a mark out of 100. Each non-compliant item takes points off, with a cap per item; an item that could not be measured takes nothing off. The score is green from 80, orange from 60, red below that.
Score trend shows the curve over 180 days. Items to address lists the gaps with their severity, the value collected, the target and the penalty; Show the … items displays the accounts or machines involved (at most 50).
| Item | Target |
|---|---|
| krbtgt account password | changed less than 180 days ago |
| Unconstrained delegation outside domain controllers | 0 |
| Administrators outside "Protected Users" and not marked sensitive | 0 |
| Number of enabled administrators | 10 at most |
| Accounts without Kerberos pre-authentication | 0 |
| LAPS coverage of computers | at least 90% |
| NTLMv1 authentications (7 days) | 0 |
| LDAP signing required and LmCompatibilityLevel of domain controllers | required; level 5 |
| Computers running an end-of-life OS | 0 |
| Service accounts with an old password, accounts with SIDHistory, orphaned adminCount | 0 |
| Enabled accounts with no logon for 90 days | at most 2% of enabled accounts |
| Passwords that never expire, computers with no logon for 90 days | as few as possible |
| Domain functional level | 2016 or higher |
Only one posture snapshot is kept per day and per domain, for 400 days. With several domains, choose the one to display from the list.
Health
One card per domain controller, with a green, red or grey (unknown) dot per line: Replication, SYSVOL, Time, FSMO roles, LDAP and Kerberos DNS records, Certificates, Backup. LDAP signing and LmCompatibilityLevel are shown without a dot. After 45 minutes without a report, the card turns red with "report overdue".
Each anomaly opens an incident, which closes on its own when things are back to normal:
| Check | Incident when | Severity |
|---|---|---|
| Replication | failures and no success for more than 1 h | high |
| SYSVOL | state other than "normal" | medium; high in error |
| Time | offset beyond 120 s | high; critical beyond 300 s |
| FSMO | a role is unreachable | high |
| DNS | LDAP or Kerberos SRV record missing | high |
| Certificate | expires in less than 30 days | medium; high under 7 days |
| Backup | more than 7 days old, or unknown | medium; high beyond 30 days or unknown |
Security alerts
The engine reads domain controller events every 2 minutes. When it is first switched on, it starts from the latest events: past history is not replayed. All 14 rules are on by default and open their incidents in the SIEM themselves, with no correlation rule to switch on.
| Rule | What triggers it | Severity |
|---|---|---|
| AD-GROUPE-PRIVILEGIE | addition to or removal from a privileged group (Domain Admins, Administrators, Backup Operators…) | critical (addition), high (removal) |
| AD-MASSE | a single author disables, resets, deletes or removes from a group more than 10 accounts in 10 minutes | high; critical at 5 times the threshold |
| AD-COMPTE-REACTIVE | an account with no authentication for 90 days is re-enabled | medium |
| AD-UAC-RISQUE | risky account flag added (password never expires or not required, no pre-authentication…) | high (no pre-authentication), medium |
| AD-DELEGATION | Kerberos delegation added to an account or a machine | critical (unconstrained), high |
| AD-SPN-AJOUTE | SPN added to a user account | medium |
| AD-SIDHISTORY | SIDHistory set | high |
| AD-KERBEROAST | a single account requests RC4 tickets for 5 or more distinct services in 10 minutes | high |
| AD-ASREP | ticket issued without pre-authentication | high |
| AD-DCSYNC | replication requested by an account that is not a domain controller | critical |
| AD-GPO | Group Policy changed, created or deleted | medium; high (deletion, link at the domain root) |
| AD-JOURNAL-EFFACE | security log cleared on a controller | critical |
| AD-STRATEGIE-AUDIT | audit policy changed | high |
| AD-RDP-DC | RDP logon on a domain controller | medium |
The Alerts tab lists Active Directory incidents (AD-* rules, health included) over 7, 30 or 90 days. Click one to open the incident; All incidents takes you to the SIEM.
Leavers
Enabled accounts inactive for 90 days takes the list from the latest posture snapshot (at most 200 accounts). Click one to open the account profile.
If a Microsoft 365 connector is active, Disabled in Microsoft 365, still present in AD cross-checks both sides. An account appears there if it is disabled in Microsoft 365 and either named in the posture snapshot (inactive, administrator, sensitive group, service account…) or still authenticating against the directory in the last 14 days. Administrators and members of sensitive groups come first.
Access review
The review serves as evidence for an audit (NIS2, ISO 27001): who is a member of the sensitive groups, and who decided to leave them there.
- In SI-Tracer → Active Directory, Access review tab, click New review. The members of the sensitive groups from the latest posture snapshot are frozen. Only one review can be open at a time.
- For each member, choose Keep or Remove, with a comment if needed, then Save.
- Click Close review. The console warns you if some members have no decision. A closed review is frozen.
- Export to CSV produces the evidence file: group, member, decision, comment, author and date of each decision.
FirstSI removes nobody from a group. Remove is a decision you apply yourself in the directory.
Creating, deciding and closing are reserved for administrators. Viewing and exporting are open to everyone.
An account's history
The account profile contains a Directory history section: creation, enabling, password change or reset, disabling, group additions and removals, lockouts, renaming, with who did it and on which controller. It covers the last 180 days, whatever period is chosen in the profile (at most 500 events).
Settings
The Settings tab is reserved for administrators. There you choose which rules are active and adjust the thresholds:
| Setting | Default |
|---|---|
| Bulk changes: threshold and window | 10 actions in 10 min |
| Kerberoasting: distinct services and window | 5 services in 10 min |
| Dormant account after (days) | 90 |
| Additional privileged groups | empty (the groups already monitored are shown on screen) |
| Accounts excluded from DCSync detection | Entra sync accounts (starting with MSOL_, AAD_ or Sync_) |
| Accounts excluded from RDP-on-DC detection | empty |
Thresholds accept a minimum of 2, and a minimum of 7 days for a dormant account. Every save is recorded in the audit log, and the tab shows who changed the settings and when.
Frequently asked questions
"No posture snapshot received yet". The snapshot is sent once a day by the controller that holds the PDC role. Check that the agent is installed there, at version 2026.10.11.3 or later, with SI-Tracer active.
No DCSync alert despite a test. Turn on the Directory Service Access audit on the domain controllers.
The review lists an account that has already left the group. The review freezes the members from the posture snapshot at the time it is created. Close it and create a new one after the next snapshot.
Source: · FirstSI Docs · updated 2026-10-11