The agent delivers facts, the assessment happens on the server
In most organisations Active Directory is the system whose compromise decides everything else, and the BSI module APP.2.2 requires in A23 the regular analysis of permissions and the attack paths that follow from them. The module checks five areas of a domain for that: what is readable in the directory, via LDAP with an ordinary read account; what is only visible on the domain controllers themselves, the certificate authority, the access control lists and the group policies, via the probe of the isidaten agent. The agent delivers states, never passwords, and the check rules live on the server so that a new rule needs no agent release.
Coverage is not a traffic light but a map per family: basic, partial, complete. Risk score and maturity exist only from "partial" upwards, and no aggregate is formed across directories with mixed coverage. A green rating on half a basis would be more dangerous than none at all.
2
Read page by page, or page two counts as clean
Active Directory caps every search server-side at 1000 objects and silently returns nothing beyond that. The module therefore always reads page by page, and a run that did not read to the end writes new findings but closes none. An attribute the read account may not see counts as not assessable, never as passed.
3
Once per rule, not per account
Three hundred accounts without password expiry are not three hundred times as dangerous as one. Every open check rule counts once with its points, in four areas capped at 100, and the overall score is the maximum, not the sum. If the probe reports a gap the report also knows, it counts once.
Domain controllers via the agent probe: 18 rules on SMB and LDAP signing, NTLM, TLS, RPC filters, audit policy, Kerberos armoring, OS level
Certificate authority: 16 rules, ESC1 to ESC16 plus key length, signature algorithm and expiry of the CA certificate
Access control lists: 14 rules from DCSync delegation via AdminSDHolder and shadow credentials to LAPS read rights
Group policies: 14 rules from passwords in preferences to hardened paths for SYSVOL and NETLOGON
Registry values only from a server-side allowlist, passwords in preferences reported only as presence, never as value
Second read path: the probe delivers the directory inventory as a snapshot, so the instance needs no network path to the domain controller
Import of PingCastle reports as a second opinion; the rules carry own German and English wording
Finding lifecycle as for vulnerabilities, exceptions per object, directory or global with approval and deadline (ISO 27001 A.5.18)
Remediation as copyable PowerShell on the finding, never executed by the agent; the module never writes to the directory
Measure, task, risk register from severity high, rule chain, SIEM event and account lock via immediate actions after approval
MFA coverage report under Section 30(2) no. 10 BSIG from smartcard requirement and mirrored Entra status, with CSV of accounts without a factor
Standards overview per requirement: evidenced, open, partially checked, not checked, not covered, for BSI APP.2.2, ORP.4, ISO 27001 Annex A and Section 30 BSIG
Cockpit with coverage per family, tier-0 findings, 90-day history and a daily run
Result
Evidence for APP.2.2 A23 that says what was checked and what was not, instead of a grade that blurs the two.
Experience Directory security live
Schedule a no-obligation demo – we will show you the module with your own use cases.