---
title: Active Directory Security Controls: 3 Checks | Wartiva
description: The 3 checks Wartiva runs for Active Directory, beyond the CIS Benchmarks: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/wartiva/active-directory.html
updated: 2026-10-07
---

Wartiva Security Controls

# Active Directory: 3 Checks

Wartiva's Active Directory controls: active Directory hygiene: domain health, desktops acting as domain controllers, and how securely macOS endpoints are bound to the domain.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## Overall Active Directory domain health

### [Ensure Active Directory Is Not Reporting A Problem State](https://wartiva.com/policy-rules/wartiva/active-directory.html#active-directory-is-not-reporting-a-problem-state)

Medium severity · Wartiva Security Controls · Active Directory

**Finding:** The endpoint's Active Directory service is reporting a problem state.

This rule inspects the endpoint's Active Directory service status. This rule fails when the status is a problem state (`ERROR`, `DEGRADED`, `PRED_FAIL`, `STRESSED`, `NON_RECOVER`, `NO_CONTACT`, or `LOST_COMM`).

**Rationale:** A degraded or disconnected AD service indicates authentication, policy, or connectivity problems that can weaken identity security controls.

**Impact:** Group Policy and authentication may not apply correctly, leaving the endpoint in an unmanaged or insecure state.

#### Remediation

Investigate the Active Directory service on the endpoint: verify domain connectivity, time synchronization, DNS resolution of domain controllers, and the machine account/secure channel. Rejoin the domain if the trust relationship is broken.

Risk

Reliability Impact

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

## Which endpoints act as domain controllers

### [Ensure Desktop Endpoints Are Not Operating As Domain Controllers](https://wartiva.com/policy-rules/wartiva/active-directory.html#desktop-endpoints-are-not-operating-as-domain-controllers)

High severity · Wartiva Security Controls · Active Directory

**Finding:** A desktop-class endpoint is operating as a domain controller.

This rule inspects the Active Directory role of a desktop-class Windows endpoint. This rule fails when the role is `PRIMARY_DOMAIN_CONTROLLER` or `BACKUP_DOMAIN_CONTROLLER`.

**Rationale:** Domain controllers are highly sensitive infrastructure and should run on hardened, dedicated servers — not desktop workstations, which have a broader attack surface and weaker physical controls.

**Impact:** A compromised desktop acting as a DC exposes the entire domain's credentials and directory to attackers.

#### Remediation

Do not run domain controller roles on desktop workstations. Migrate Active Directory Domain Services to a dedicated, hardened server and demote the desktop (dcpromo / Remove-ADDSDomainController), then verify the workstation no longer holds directory roles.

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Insecure Application

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

## How endpoints are bound to the domain

### [Ensure macOS Active Directory Binding Is Securely Configured](https://wartiva.com/policy-rules/wartiva/active-directory.html#macos-active-directory-binding-is-securely-configured)

High severity · Wartiva Security Controls · Active Directory

**Finding:** A macOS endpoint's Active Directory binding has insecure connection settings.

This rule inspects the Active Directory connection settings of a macOS endpoint. This rule fails when cleartext authentication is allowed (`noCleartextAuth == false`), man-in-the-middle detection is disabled (`manInTheMiddle == false`), packet encryption is not required (`packetEncryption` is not `REQUIRED` or `SSL`), or packet signing is disabled (`packetSigning == DISABLED`).

**Rationale:** These settings protect the directory-binding channel against interception, tampering, and credential capture.

**Impact:** Weak binding settings expose directory traffic and credentials to eavesdropping and adversary-in-the-middle attacks.

#### Remediation

Harden the macOS Active Directory binding: disable cleartext authentication, enable man-in-the-middle (mutual authentication) detection, require packet encryption, and require packet signing. Apply these via a Directory Utility configuration profile / MDM policy and re-bind if necessary.

Framework mappings

- **CIS Controls v8**: 3.10 Encrypt Sensitive Data in Transit
- **NIST SP 800-53 Rev. 5**: AC-17 Remote Access; IA-5 Authenticator Management; SC-8 Transmission Confidentiality and Integrity
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.5.10 Store and transmit only cryptographically-protected passwords; 3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; IA.L2-3.5.10 Store and transmit only cryptographically-protected passwords; SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards
- **PCI DSS v4.0.1**: 2.2.7 Encrypt every remote administrative session with strong cryptography; 4.1.1 Transmission encryption policies and procedures kept documented, current, and applied; 4.2.1.2 Apply strong cryptography to wireless networks carrying PAN or touching the CDE; 4.2.2 Encrypt PAN sent through end-user messaging technologies; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risks

Unprotected Data, Insecure Application

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
