A holistic approach to Active Directory Domain Services


A security first approach

We literally wrote the book on Active Directory, so you can be confident you're working with the experts to design and implement a secure Active Directory Domain Services strategy that addresses your company requirements and is resilient to modern threats.

Health check service

Our Health Check Service scans your current configuration for hundreds of configuration, security, and operational best practices. Based on the scan, we make actionable improvement recommendations.

Cutting edge security

A compromised Active Directory can give attackers access to almost everything. We design and build security solutions like tiered access, privileged access workstations (PAWs), and admin (red) forests.

Design reviews and remediation

Active Directory is such a foundational technology that many organization can benefit from a holistic review of their design and implementation. We have extensive experience performing these reviews and helping organizations transition to a stable and secure foundation for the future.

Cloud readiness

Any future move to cloud infrastructure or services relies on a stable on-premises foundation. We can ensure your Active Directory Domain Services strategy is cloud proof.

Active Directory Domain Services

Our expertise


Active Directory Domain Services is the foundation of many networks. Configuring AD DS to be reliable and secure while meeting the specific needs of your organization requires in depth knowledge. If AD DS becomes compromised, the security of your network is fundamentally at risk.

Our consultants have unparalleled knowledge of AD DS. We have the experience to help make sure your AD DS forest is designed for the realities of today’s IT environment. While we prefer to help optimize and secure your AD before something happens, we often are called in to remediate situations after a security incident occurs.

From the blog


Azure Active-Directory Health Check

How To Get the MIM Synchronization Service Groups

Learn how to find out what security groups grant access to the MIM Synchronization Service


Microsoft Intune Compliance

Three Things to Plan for When You Add Single Sign-On

Enabling single sign-on (SSO) for SaaS applications adds convenience for end users, as well as reduces security risks and enables…


Multi-Factor Authentication

Secure Anywhere Access to Business Applications without a VPN

With the Azure AD Application Proxy, you can provide remote access to web applications and Remote Desktop Services (RDS) farms…


Multi-Factor Authentication

How to Mitigate Privilege Escalation with the Tiered Access Model for Active Directory Security

One of the most important security controls in an Active Directory (AD) forest is the prevention of privilege escalation paths.…