Server hardware illuminated in blue inside a data center

Microsoft Active Directory Your domain. Under scrutiny.

Active Directory
penetration testing.

Hire experienced BlackSight specialists to manually test your Active Directory setup. Get validated attack paths, clear evidence, and fixes your IT team can act on.

Call to discuss your AD scope +1 (615) 200-7888
Across domains. Across your business. Your Active Directory AD DS

Forest root

company.example

DC-01
DC-02

West domain

Trusted regional domain

DC-03
DC-04

East domain

Trusted regional domain

DC-05
DC-06
Users & groups
Workstations
App servers
Group Policy
Illustrative enterprise environment

Experienced specialists. Manual testing.

Remote and on-site testing worldwide

Completion certificate included

Follow the access. Find the risk.

One account can open a lot of doors.

Our specialists manually investigate accounts, permissions, trusts, and systems, then validate what an attacker could reach within your agreed scope.

Microsoft directory services icon Microsoft Active Directory An AD attack path Illustrative · your test follows the evidence

Standard domain account

The agreed starting point

Exposed credentials
Excessive permissions
Trusts & delegation

Privileged access

Critical systems. Business impact.

AD Certificate Services, Entra ID, and hybrid identity can be included in the agreed scope.

Engineer using a laptop beside server racks

Testing that fits how you operate

Remote access.
Or boots on the ground.

Remote AD penetration testing

Through a secure VPN or internal test host, with access and testing windows agreed in advance.

On-site AD penetration testing

At your premises worldwide, with travel and site access agreed in advance. Internal network and wireless testing can be scoped alongside AD.

Find the right scope for your team

Evidence for the people who need it

Proof of testing.
Ready to share.

  • Certificate for your cyber insurer

    A completion certificate you can submit to your cyber insurance provider after the AD pentest.

  • Findings for your IT team

    Documented attack paths, technical evidence, and an executive summary.

  • A practical remediation plan

    Prioritized fixes and a results walkthrough. Retesting is defined in your proposal.

blacksight.

Security assessment

Certificate
of completion

Active Directory penetration testing

Prepared for

Your organization

Scope

Agreed AD environment

Assessment date

Your engagement dates

Approved With observations Example assessment BlackSight LLC

Documented assessment.
Issued by BlackSight.

Illustrative certificate layout

AD testing pricing

Get a price for
your AD pentest.

Request a quote for manual Active Directory testing. We’ll follow up to confirm the scope and price. No technical details needed to get started.

Want to discuss pricing first?

Discuss pricing with an expert

You can request pricing without sharing technical details about your environment.

We use your details to respond to this inquiry. Privacy policy

Before we test your Active Directory.

Who performs our Active Directory penetration test?

Experienced BlackSight specialists carry out manual testing of your agreed AD environment, validate attack paths, and document the evidence and remediation priorities.

What is Active Directory penetration testing?

Our specialists manually investigate whether an attacker could turn a standard domain account or internal network access into greater access. We validate attack paths within your authorized scope and report evidence, impact, and fixes.

Do we receive a certificate for our cyber insurance?

Yes. After your AD pentest, BlackSight provides a completion certificate you can submit to your cyber insurance provider, alongside your assessment report. Share any insurer-specific evidence requirements during scoping so we can confirm what the engagement will document.

Can you test Active Directory remotely?

Yes, through an agreed secure connection such as a VPN and an internal test host. We confirm access, accounts, and testing windows together. Domain controllers do not need to be exposed to the public internet.

When should we choose on-site testing?

Choose on-site testing when access must stay local or your scope includes work across locations and network segments. We travel worldwide and agree site access and travel costs in your proposal.

How is this different from an Active Directory health check?

A health check reviews configuration and operational health. A pentest investigates how weaknesses combine into attack paths and validates their impact within agreed boundaries.

Does the assessment include Microsoft Entra ID or AD Certificate Services?

These can be included when explicitly scoped. Tell us about Entra ID, hybrid identity, federation, or AD Certificate Services during scoping so your proposal covers the right systems.

How much does an AD penetration test cost?

Your quote depends on domains and forests, access, testing depth, delivery, and travel. We confirm pricing, timing, deliverables, and any retesting before work begins.

What access do you need, and how do you protect operations?

We agree starting access, systems, exclusions, testing windows, and escalation contacts with your team. A standard domain account can support an assumed-breach scenario. Privileged access and disruptive techniques require separate agreement.