Wartiva Security Controls

Active Directory: 3 Checks

Wartiva's Active Directory controls: active Directory hygiene: domain health, desktops acting as domain controllers, and how securely macOS endpoints are bound to the domain.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 3 checks on this page

Overall Active Directory domain health

Ensure Active Directory Is Not Reporting A Problem State

Medium severity · Wartiva Security Controls · Active Directory

Finding: The endpoint's Active Directory service is reporting a problem state.

This rule inspects the endpoint's Active Directory service status. This rule fails when the status is a problem state (ERROR, DEGRADED, PRED_FAIL, STRESSED, NON_RECOVER, NO_CONTACT, or LOST_COMM).

Rationale: A degraded or disconnected AD service indicates authentication, policy, or connectivity problems that can weaken identity security controls.

Impact: Group Policy and authentication may not apply correctly, leaving the endpoint in an unmanaged or insecure state.

Remediation

Investigate the Active Directory service on the endpoint: verify domain connectivity, time synchronization, DNS resolution of domain controllers, and the machine account/secure channel. Rejoin the domain if the trust relationship is broken.

Risk
Reliability Impact
MITRE ATT&CK tactic
Impact (TA0040)

Which endpoints act as domain controllers

Ensure Desktop Endpoints Are Not Operating As Domain Controllers

High severity · Wartiva Security Controls · Active Directory

Finding: A desktop-class endpoint is operating as a domain controller.

This rule inspects the Active Directory role of a desktop-class Windows endpoint. This rule fails when the role is PRIMARY_DOMAIN_CONTROLLER or BACKUP_DOMAIN_CONTROLLER.

Rationale: Domain controllers are highly sensitive infrastructure and should run on hardened, dedicated servers — not desktop workstations, which have a broader attack surface and weaker physical controls.

Impact: A compromised desktop acting as a DC exposes the entire domain's credentials and directory to attackers.

Remediation

Do not run domain controller roles on desktop workstations. Migrate Active Directory Domain Services to a dedicated, hardened server and demote the desktop (dcpromo / Remove-ADDSDomainController), then verify the workstation no longer holds directory roles.

Framework mappings
  • CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
  • NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
Risk
Insecure Application
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

How endpoints are bound to the domain

Ensure macOS Active Directory Binding Is Securely Configured

High severity · Wartiva Security Controls · Active Directory

Finding: A macOS endpoint's Active Directory binding has insecure connection settings.

This rule inspects the Active Directory connection settings of a macOS endpoint. This rule fails when cleartext authentication is allowed (noCleartextAuth == false), man-in-the-middle detection is disabled (manInTheMiddle == false), packet encryption is not required (packetEncryption is not REQUIRED or SSL), or packet signing is disabled (packetSigning == DISABLED).

Rationale: These settings protect the directory-binding channel against interception, tampering, and credential capture.

Impact: Weak binding settings expose directory traffic and credentials to eavesdropping and adversary-in-the-middle attacks.

Remediation

Harden the macOS Active Directory binding: disable cleartext authentication, enable man-in-the-middle (mutual authentication) detection, require packet encryption, and require packet signing. Apply these via a Directory Utility configuration profile / MDM policy and re-bind if necessary.

Framework mappings
  • CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
  • NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
  • PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
Risks
Unprotected Data, Insecure Application
MITRE ATT&CK tactic
Credential Access (TA0006)