Getting Started with the Active Directory Security On-Demand Assessment

The Active Directory Security assessment is designed to provide you specific actionable guidance to mitigate security risks to your Active Directory and your organization. This solution also provides you with status on your progress relative to Microsoft’s recommended roadmap for Securing Privilege Access (SPA), of which Active Directory is a critical component.

The Active Directory Security Assessment focuses on several key pillars, including:

  • Review of operational processes
  • Review of the privileged accounts/groups membership as well as regular account hygiene
  • Review of the forest and domain trusts
  • Review operating system configuration, security patch, and update levels
  • Review of domain and domain controller configuration compared to Microsoft recommended guidance
  • Review of key Active Directory object permission delegation

Running the Active Directory Security Assessment


In order to take full advantage of the On-Demand Assessments available through Services Hub, you must:

  1. Have linked an active Azure Subscription to Services Hub and added the AD Security Assessment. For more information please see: Getting Started with On-Demand Assessments or watch the how to link video.
  2. Install the Microsoft Monitoring Agent and choose the appropriate agent setup on a supported Windows Server machine. You can also watch the video guide on how to install the agent or how to configure the gateway.
  3. A domain account (User or Managed Service Account) with the following rights:
  • Enterprise Administrator group membership OR
  • Built-in Administrator group membership to every domain in the forest.
  • Membership in Local Administrators group on the Data Collection machine.
  • Administrative access to all Microsoft Domain Name System (DNS) servers that the domain controllers participate with.
  1. Review the Pre-Requisites document for the AD Security Assessment. This document explains the detailed technical documentation of the AD Security Assessment and the server preparation needed to run the assessment. It also documents the different types of data collected by the assessment.


On average, it takes two hours to initially configure your environment to run an On-Demand Assessment. After you run an assessment you can review the data in Azure Log Analytics. This will provide you with a prioritized list of recommendations, categorized across six focus areas. This allows you and your team to quickly understand risk levels, the health of your environments, act to decrease risk, and improve your overall IT health.*

Setup the AD Security Assessment - Watch Video Guide


You will only be able to successfully set up the assessment once you have linked your Azure Subscription to Services Hub and added the AD Security Assessment from Health -> Assessments in Services Hub.*

  1. On the data collection machine create the following folder: C:\OMS\ADS (or any other folder as you may please).
  2. Open regular Powershell (not ISE) in Administrator mode and run the below cmdlet:

Add-ADSecurityAssessmentTask -WorkingDirectory <workingdirectorypath> command,

where workingdirectorypath is a path to an existing directory used to store the files created while collecting and analyzing the data from the environment.

  1. Provide the required user account credentials that satisfy the requirements mentioned in this article earlier.
  2. Data collection is triggered by the scheduled task named ADSecurityAssessment within an hour of running the previous script and then every 7 days. The task can be modified to run on a different date/time or even forced to run immediately from the task scheduler library -> Microsoft -> Operations Management Suite > AOI*** > Assessments > ADSecurityAssessment.
  3. During collection and analysis, data is temporarily stored under the Working Directory folder that was configured during setup.
  4. After a few hours, your assessment results will be available on your Log Analytics and Services Hub Dashboard. You can navigate to see the results by going into Services Hub > Health > Assessments and then clicking on View all recommendations against the active assessment.
  5. If you wish to get a Microsoft Accredited Engineer to go over the issues about your AD Environment with you, you can contact your Microsoft Representative and ask them about the Remote or Onsite PFE Led Delivery.
Contract Remote Engineer Onsite Engineer
Premier ADS Remote Datasheet ADS Onsite Datasheet
Unified ADS Remote Datasheet ADS Onsite Datasheet

For general feedback on the Resource Center or content, please submit your response to UserVoice. For specific requests and content updates regarding the Services Hub, contact our Support Team to submit a case.