Expert insight

NIS2 survival: secure your Active Directory in 90 days

A three-step working framework — see, reduce, detect — to fix the risks nobody will regret having addressed.

NIS2 is not an Active Directory standard. But AD sits underneath enough critical mechanisms — identities, privileges, delegations, administration paths — to be the best place to start when you want evidence rather than a “NIS2 ready” badge.

Reading time: about 9 minutes

NIS2 is not an Active Directory project

NIS2 is an EU Directive, not an Active Directory standard. Article 21 covers a much broader range of measures: risk analysis, incident handling, business continuity, backup and recovery, supply-chain security, vulnerability management, control effectiveness, cyber hygiene, access control, asset management and multi-factor authentication.

Securing Active Directory therefore does not make an organisation “NIS2 compliant”. Yet AD sits underneath enough critical mechanisms to make it an excellent place to start: identities, authentication, groups, delegations, service accounts, privileges, security policies and administration paths.

The objective is not to obtain a “green” Active Directory. It is to reduce the probability that one identity can be used to take control of the information system.

A PingCastle score or configuration assessment is valuable, but it does not tell you whether an attacker can chain three ordinary weaknesses into a path to Domain Admin. The same applies to Tier 0: it extends beyond domain controllers and Domain Admin membership. Poorly secured AD CS, a service account, an old delegation or a legacy authentication mechanism can create an equally critical path.

What NIS2 expects, and what AD will not solve

It helps to draw the boundary early between what directory work genuinely covers and what remains to be handled elsewhere. That avoids the classic double failure: over-promising to the executive committee, and under-estimating the rest of the programme.

Six expectations, read from the Active Directory side

  • Analyse risk → identify Tier 0, privileges, delegations and attack paths. AD does not replace enterprise-wide risk analysis.
  • Control access → govern groups, sensitive accounts and admin rights. AD does not cover authorization inside every application.
  • Detect and handle incidents → monitor sensitive changes and abnormal behaviour. AD does not replace the SOC or incident response.
  • Maintain continuity → back up and recover the directory. AD is not the enterprise disaster recovery plan.
  • Assess control effectiveness → measure, re-test and retain evidence. AD does not carry overall NIS2 governance.
  • Strengthen authentication → protect administrative access and connect AD with MFA and Entra ID. AD does not set the enterprise authentication strategy.

The score measures. The expert interprets. The attacker looks for a path.

Service: identity and Active Directory securityUse case: secure Active Directory and its attack paths

Before day 1: establish the starting point

There is no need to start with a heavy engagement. The Ariovis Active Directory security assessment provides an initial view of maturity, highlights improvement areas and creates a starting point for the roadmap. Its first purpose is simple: where should we look first?

But a posture assessment remains an assessment. For critical environments, or when an organisation wants to measure how exploitable its weaknesses really are, controlled offensive testing of identity paths is particularly useful.

The Ariovis × Ballpoint identity and access penetration-testing offer examines over-privileged accounts, delegations, service accounts, paths to Domain Admin, GPOs, LDAP, DNS, lateral movement and hybrid identity environments. Ballpoint performs the offensive testing; Ariovis turns the findings into an actionable IAM and Active Directory remediation path.

Run the Active Directory security assessmentScope an identity and access penetration test

Days 1–30 — SEE: understand how AD could fall

The first month should produce a risk map rather than a collection of recommendations.

What we look at

  • domains, forests, trusts and dependencies;
  • the assets that genuinely make up Tier 0;
  • privileged groups and delegations;
  • dormant, orphaned, generic and service accounts;
  • the paths leading to critical resources;
  • Kerberos posture and Kerberoasting exposure;
  • NTLM usage and other legacy mechanisms;
  • local administrator management and LAPS;
  • AD CS and certificates that can become escalation paths;
  • obsolete systems and the AD / Microsoft Entra ID relationship;
  • audit visibility, backup status and actual recovery capability.

Tools such as Netwrix PingCastle and the posture capabilities of Netwrix 1Secure accelerate this step and help prioritise.

Day-30 outcome: a map of critical assets, privileges and attack paths, with a remediation backlog prioritised by real security impact. Fixing a configuration that removes twenty paths to Tier 0 comes before cosmetically improving one isolated indicator.

Our Netwrix acceleratorsExpert insight: detecting abnormal access

Days 31–60 — REDUCE: remove what attackers can use

The second month breaks the paths that have been identified.

Depending on the environment

  • separate administrative and office identities;
  • protect Tier 0 and reduce highly privileged memberships;
  • remove or fix dangerous delegations;
  • clean up generic accounts and govern service accounts;
  • deploy or fix LAPS, harden Kerberos, gradually reduce NTLM;
  • fix dangerous AD CS configurations;
  • remove legacy identity mechanisms that are no longer needed;
  • strengthen administrative authentication and segment administration paths.

This is also the point where standing privilege should be challenged. When an administrator needs a permission for two hours a month, there is little reason for it to exist during the remaining 728 hours. Netwrix Privilege Secure can support Just-in-Time approaches, but the product follows the principle.

Day-60 outcome: an objective comparison between the initial and remediated situation — which paths disappeared, which privileges were reduced, and which risks remain accepted or open.

Fewer standing privileges mean fewer paths available to an attacker.

Service: privileged access and secretsUse case: reduce standing privileges

Days 61–90 — DETECT, RECOVER, PROVE

A clean Active Directory on Monday can become dangerous again by Friday. The final phase makes the posture sustainable.

Detect first: quickly see changes to privileged groups and Tier-0 assets, new delegations, sensitive GPO changes, unusual escalation, inconsistent administrative behaviour and suspicious service-account usage. Netwrix 1Secure or Netwrix Auditor provide change monitoring, alerting and investigation evidence.

Then recover. Ask the uncomfortable question: if our Active Directory forest is compromised tomorrow morning, can we return to a known-good state? Netwrix Identity Recovery provides granular object and attribute rollback as well as forest recovery. But owning the backup is not the same as knowing you can recover: recovery must be tested.

Finally, re-test. When identity penetration testing was performed at the start, a Day-90 counter-assessment verifies that the previously exploitable paths have actually been neutralised. That is not a NIS2 certificate: it is a demonstration that paths which used to work no longer do.

A successfully authenticated identity can still be compromised. A successful login is never the end of the security reasoning.

Plan a counter-assessment with BallpointIAM operations: keeping the posture over time

At day 90, the deliverable is not “Netwrix is installed”

The expected result is a small Active Directory control evidence pack.

  • initial posture;
  • critical assets and identities;
  • the main attack paths identified;
  • treatment decisions and completed remediation;
  • privileges removed or made temporary;
  • active monitoring controls and incident procedures;
  • recovery test result and optional offensive re-test;
  • residual risks and the next six-month roadmap.

It is not a NIS2 certificate. It does, however, demonstrate that a major identity risk is understood, treated, monitored and tested. That is far more useful than a “NIS2 ready” badge.

What happens after day 90?

If excessive accounts and groups return a few weeks after the clean-up, the underlying problem is probably no longer Active Directory itself: it sits upstream. Poor Joiner / Mover / Leaver processes, ownerless service accounts, ungoverned entitlement requests and delayed offboarding will recreate the same debt.

That becomes an IGA problem. Netwrix Identity Manager, or another platform appropriate to the organisation, automates lifecycle processes, structures roles, manages requests and access reviews, and stops the cleaned-up debt from returning.

Likewise, when the findings extend beyond AD into authentication, PAM, governance, cloud identities or authorization, the Ariovis IAM Zero Trust roadmap places the directory inside a broader identity trajectory.

Active Directory is often a very good place to start. It should not be confused with the destination.

Expert insight: Netwrix Identity ManagerService: identity governanceService: IAM strategy and Zero Trust

Decision aid

Three questions come up every time an executive committee discovers the topic. Here is how we answer them, without promising compliance.

Does securing Active Directory make an organisation NIS2 compliant?

No. NIS2 covers a much broader scope. Active Directory does, however, contribute directly to risk management, access control, privileged access, detection, continuity and authentication.

In practice, it is often the workstream that produces the most tangible evidence within a quarter.

See our identity and Active Directory security service

Does a good PingCastle score mean Active Directory is secure?

No. A posture score is a useful indicator. It needs to be complemented by analysis of privileges, Tier 0, AD CS, hybrid identities and the attack paths that are genuinely exploitable.

Run the Active Directory security assessment

Should penetration testing happen before or after remediation?

Both answer different questions. Before remediation, it demonstrates exploitability and supports prioritisation. Afterwards, a re-test verifies that the identified paths have actually been removed.

Offensive security is therefore often most useful twice: first to prove the risk, then to prove the fix.

Scope an identity and access penetration test

Where should we start if we must decide this week?

If you need a first objective view, run the assessment and get your initial priorities. If you need to know what an attacker can actually reach, scope an identity and access penetration test. If you already know the weaknesses and want to fix them, let's discuss the remediation path directly.

Book a conversation with an expertExplore identity and Active Directory security

Where do you stand?

Under control

  • Tier 0 defined and protected
  • Privileges reviewed and mostly temporary
  • Monitoring of sensitive changes in place
  • Forest recovery tested

Consolidate: annual counter-assessment and IGA governance so the debt does not return.

To be structured

  • Posture assessment done but backlog not prioritised
  • Service accounts without a clear owner
  • Partial audit logging
  • Backups exist but were never tested

Start the 90 days: map, prioritise by real impact, then prove it.

Exposed

  • No inventory of delegations
  • Administrative accounts used for office work
  • AD CS never assessed
  • No demonstrated recovery capability

Start by seeing: assessment, then identity penetration testing to measure real exploitability.

Key takeaways

NIS2 goes far beyond Active Directory, but AD is where tangible evidence of control appears fastest.

Ninety days rarely fix everything. They are enough to see, break the major paths, put detection in place and demonstrate recovery capability.

Let's talk about your directory

We work on the initial assessment as well as remediation, monitoring and keeping the directory in a secure state over time.

The simplest starting point is your actual situation: number of forests, history, past incidents, production constraints.

Three ways to start

Establish your posture, measure what an attacker would really reach, or begin remediation with a team that understands production constraints.