NIS2 · French ReCyF · Directories
NIS2 and the French ReCyF: secure Active Directory and LDAP directories
Directories hold part of the accounts, groups, policies and rights used by information systems. Their security does not automatically follow from IAM governance.
This page applies the practical cases in the French ANSSI guidance to the NIS2 identity and access use case.
Intended outcome
Coherent accounts and groups, protected exchanges, limited delegations and usable events.
How to industrialise it
Let IAM govern decisions, execute changes in the directory and apply controls specific to AD or LDAP.
Structure accounts, groups and exchanges
Rights should be assigned to functional groups rather than systematically to individual users. Directory exchanges should be limited and encrypted, including LDAPS where relevant, and internal environments logically separated from exposed ones.
Default secrets must be changed, password policies enforced in the directory, and connections, group changes, creations and deletions logged. Coherence must be checked across the directory, federation, SSO and IAM.
Control administration and exceptions
Administrative delegations must be restricted. Emergency or break-glass accounts need a procedure, approval, strong protection and traces. Regular account and group reviews complement controlled creation, deactivation and documented naming.
IAM governs and orchestrates; the directory executes and holds part of the accounts and groups. Reducing attack paths, protecting administration tiers and restoring service also require controls specific to Active Directory or LDAP.
Evidence to retain
- Naming rules, functional groups and owners
- Secure exchange settings and environment separation
- Logs of connections, group changes and lifecycle events
- Reviews of accounts, groups, delegations and emergency access
Relevant capabilities and content
Identity and Active Directory security
Analyse control paths, delegations and administration surfaces.
Identity governance
Orchestrate decisions and changes into directories.
NIS2 survival: secure Active Directory in 90 days
A 90-day approach to see, reduce and evidence.
Related controls
Identification and lifecycle
Drive creation, change and deactivation.
Certificates and machine identities
Address certificate trust and automated services.
Sources and guidance
ANSSI — ReCyF in practice — Identity management, version 1.0, September 2026 (French source document)
- ANSSI — Secure administration of Active Directory systems (French)
- ANSSI — Secure administration of information systems (French)
Turn the control into a process
Frame responsibilities, events and evidence before selecting the mechanisms to deploy.