What is an AD security audit?
A systematic review of your Active Directory or Entra ID tenant against known misconfigurations, privileged-access weaknesses, password policies, Kerberos attacks, ADCS issues and lateral-movement paths. EtcSec runs 498 checks across both directories in under 5 minutes.
How often should I audit Active Directory?
Continuously. The threat surface shifts with every new user, group, GPO or permission change. Most teams run a full audit weekly and a lightweight scan daily. EtcSec Premium automates the schedule.
Does this replace a pentest?
No. A pentest validates exploitability against a human attacker; an audit catches misconfigurations before they become the pentester's opening move. Use both — EtcSec feeds the pentest scope.
Is EtcSec aligned with ANSSI requirements?
Yes. Every finding is mapped to ANSSI PA-099 (v1.0, 2023), BP-039 and the ANSSI Hygiene Guide, plus NIS2, HDS, RGPD, CIS v8, NIST 800-53 and DISA STIG. You can export PDFs structured by framework.
What does the collector do?
It runs read-only LDAP and Graph queries, serializes the result into structured JSON, and uploads it over TLS. It never modifies AD or Entra. Source is on GitHub — audit it yourself.
Can I audit Entra ID only?
Yes. Point the trial or the collector at your tenant with a read-only Graph app and you get 158 Entra ID detectors covering Conditional Access, MFA, PIM, guest users, app permissions and risky sign-ins.
Where is my data stored?
Audit data is encrypted at rest in Postgres hosted in the EU. Credentials are encrypted in memory only — never written to disk. Trial data is purged after 7 days automatically.
Can I try EtcSec without signing up?
Yes — the free trial at /trial runs a full audit anonymously in under 2 minutes. No credit card, no email required. Sign up only if you want to keep the report past 7 days.
Which compliance frameworks are supported?
ANSSI (PA-099, BP-039, Hygiene Guide), NIS2, HDS, RGPD, CIS v8, NIST 800-53, DISA STIG. Each finding carries tags so you can filter by framework.
Can I export the results?
Yes — PDF for stakeholders, JSON for integration with SIEM/SOAR, CSV for spreadsheets. Trial exports are free; Premium accounts get unlimited and historical exports.