ADRiskInsight

LOCAL ACTIVE DIRECTORY SECURITY ASSESSMENT

See Active Directory risk clearly.

ADRiskInsight helps administrators, consultants and MSPs review common Active Directory security risks, inspect supporting evidence and export practical reports—without deploying agents or uploading assessment data to the cloud.

AUTHENTIC PRODUCT INTERFACESANITIZED SAMPLE
Sanitized assessment results in the ADRiskInsight application

Demonstration data · Interface and assessment catalog continue to evolve

Findings, coverage and confidence stay separate—so a technical error never looks like a safe result.

REVIEW AREAS

Common AD risks, organized for action.

The assessment combines directory observations with local-configuration checks on the selected domain controller.

01

Privileged access

Membership and account configurations that require privilege review.

02

Passwords and accounts

Policies, risky attributes, stale accounts and objects that need context.

03

Kerberos and authentication

Legacy or weak configurations related to Kerberos, LDAP and NTLM.

04

Domain controller

Effective local-host configuration and controls applicable to the DC role.

05

Exportable evidence

Affected objects, technical context, available guidance and reviewed sources.

06

Coverage and confidence

Visible limitations that prevent conclusions broader than the evidence.

THE METHOD

An assessment that preserves its reasoning.

Every result keeps execution, applicability, assessment, severity and confidence separate. The reader can trace a conclusion back to evidence and forward to the recommended action.

  1. 01

    Observe

    Collect technical state inside the authorized scope.

  2. 02

    Interpret

    Separate exposure, context, coverage and items needing review.

  3. 03

    Act

    Prioritize with remediation, precautions and validation available.

TWO SURFACES · ONE ASSESSMENT SNAPSHOT

The analysis does not end inside the application.

HTML

Self-contained HTML report

Navigable, filterable, printable and usable offline. No remote scripts, styles, fonts or images.

XLSX

Structured Excel workbook

Summary, results, remediation plan, sources and technical evidence in an operational format.

NOTE / Technical reports may contain environment identifiers. Review and handle them according to the organization's security policy.

Explore the sample report →

CLEAR PRODUCT BOUNDARIES

Designed for environments where knowing what happens to data matters.

01

Local assessment

The assessment and reports are generated on the authorized domain controller. Assessment data is not uploaded to the cloud.

02

Licensing stays separate

Online activation communicates only with the licensing service. An offline licensing flow is also available for restricted environments.

03

Analysis, not automatic change

ADRiskInsight identifies, explains and helps prioritize. It does not automatically repair or modify Active Directory.

BEFORE YOU RUN

An explicit technical scope from the start.

The assessment combines directory information with effective configuration from the selected controller. Coverage depends on the execution point and available access.

01

Execution point

Run the application directly on one authorized domain controller. A single execution queries the available directory scope and that DC's local sources.

02

Identity and access

Use an approved Windows account with access to the required directory and configuration sources. Missing access remains visible as incomplete coverage or an execution error.

03

Connectivity

The assessment does not upload its data to the cloud. Online activation is limited to the licensing service; restricted environments can use the offline flow.

04

Report destination

Choose an organization-approved writable location for the self-contained HTML report or structured Excel workbook.

VISIBLE PRICING · FIXED TERM

Choose the time you need. No automatic renewal.

Each plan provides access for the full term shown; the price is not tied to a single scan.

A straightforward download

Review the plans and download the installer without completing a lengthy sales form or scheduling a call. At purchase, we ask only for the information needed to process payment, deliver the license and meet applicable obligations.

Project1 month

One month of access for assessment and follow-up validation

$79USD
Standard3 months

A three-month window for assessment, remediation follow-up and reassessment

$149USD
Professional1 year

Year-round access for recurring assessments and ongoing validation

$399USD

USD · one payment for the term · no automatic renewal

TWO WAYS TO PUT IT TO WORK

01

Internal teams

Establish a repeatable posture review across infrastructure and security.

02

Consultants & providers

Deliver professional work whose reasoning the client can inspect.

FREQUENTLY ASKED QUESTIONS

Important details, before you run.

01Does ADRiskInsight modify Active Directory?

No. It assesses and reports. Any remediation remains under the control of authorized administrators.

02Where does it run?

Directly on one authorized domain controller. Directory queries cover the available scope, while local checks describe the selected DC; it does not need to be installed on every controller.

03Does an assessment require Internet access?

The assessment and report generation do not upload assessment data. Online activation communicates with the licensing service, and an offline flow is available for restricted networks.

04What formats can it export?

A navigable, printable, self-contained HTML report and a structured Excel workbook generated from the same assessment snapshot.

05Why might the index be withheld?

ADRiskInsight withholds it when methodology coverage or execution quality cannot support a defensible conclusion. Results and limitations remain visible.

06Do plans renew automatically?

No. The planned periods are fixed term and end when the purchased time expires unless the customer explicitly buys another term.

Evidence before conclusion.

Run ADRiskInsight directly on one authorized domain controller. A single execution assesses the available directory scope, while local-configuration checks describe the selected DC; there is no need to install it across every domain controller.