Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 3 checks on this page
- Overall Active Directory domain health
- Ensure Active Directory Is Not Reporting A Problem State
- Which endpoints act as domain controllers
- Ensure Desktop Endpoints Are Not Operating As Domain Controllers
- How endpoints are bound to the domain
- Ensure macOS Active Directory Binding Is Securely Configured
Overall Active Directory domain health
Ensure Active Directory Is Not Reporting A Problem State
Finding: The endpoint's Active Directory service is reporting a problem state.
This rule inspects the endpoint's Active Directory service status. This rule fails when the status is a problem state (ERROR, DEGRADED, PRED_FAIL, STRESSED, NON_RECOVER, NO_CONTACT, or LOST_COMM).
Rationale: A degraded or disconnected AD service indicates authentication, policy, or connectivity problems that can weaken identity security controls.
Impact: Group Policy and authentication may not apply correctly, leaving the endpoint in an unmanaged or insecure state.
Remediation
Investigate the Active Directory service on the endpoint: verify domain connectivity, time synchronization, DNS resolution of domain controllers, and the machine account/secure channel. Rejoin the domain if the trust relationship is broken.
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Which endpoints act as domain controllers
Ensure Desktop Endpoints Are Not Operating As Domain Controllers
Finding: A desktop-class endpoint is operating as a domain controller.
This rule inspects the Active Directory role of a desktop-class Windows endpoint. This rule fails when the role is PRIMARY_DOMAIN_CONTROLLER or BACKUP_DOMAIN_CONTROLLER.
Rationale: Domain controllers are highly sensitive infrastructure and should run on hardened, dedicated servers — not desktop workstations, which have a broader attack surface and weaker physical controls.
Impact: A compromised desktop acting as a DC exposes the entire domain's credentials and directory to attackers.
Remediation
Do not run domain controller roles on desktop workstations. Migrate Active Directory Domain Services to a dedicated, hardened server and demote the desktop (dcpromo / Remove-ADDSDomainController), then verify the workstation no longer holds directory roles.
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Insecure Application
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
How endpoints are bound to the domain
Ensure macOS Active Directory Binding Is Securely Configured
Finding: A macOS endpoint's Active Directory binding has insecure connection settings.
This rule inspects the Active Directory connection settings of a macOS endpoint. This rule fails when cleartext authentication is allowed (noCleartextAuth == false), man-in-the-middle detection is disabled (manInTheMiddle == false), packet encryption is not required (packetEncryption is not REQUIRED or SSL), or packet signing is disabled (packetSigning == DISABLED).
Rationale: These settings protect the directory-binding channel against interception, tampering, and credential capture.
Impact: Weak binding settings expose directory traffic and credentials to eavesdropping and adversary-in-the-middle attacks.
Remediation
Harden the macOS Active Directory binding: disable cleartext authentication, enable man-in-the-middle (mutual authentication) detection, require packet encryption, and require packet signing. Apply these via a Directory Utility configuration profile / MDM policy and re-bind if necessary.
- Framework mappings
- CIS Controls v8: 3.10 Encrypt Sensitive Data in Transit
- NIST SP 800-53 Rev. 5: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- PCI DSS v4.0.1: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risks
- Unprotected Data, Insecure Application
- MITRE ATT&CK tactic
- Credential Access (TA0006)