
Reviewing Reliably (Part 1)
For the readers who aren't familiar with the Active Directory service. It is a directory service created by Microsoft to manage and administer networks. Designed to centralise authentication, authorisation, and policy enforcements across Window environments.
In this project, I was tasked with reviewing user access within two of our AD servers. The goal was to locate, identify, and automate user access reviews for all the relevant groups. Considering the number of regulations and policies enforced upon financial institutions, automating this process was a big priority for us. Luckily, that is out of the way now.
Sidenote - External auditors absolutely love this initiative because it removes the potential for human error. Making the reviews more robust.
Prerequisites
My project consists of three main files.
The file responsible for extracting all the users for a particular group into a CSV file (PowerShell). This can be used for further processing and is used for evidence storing.
The file responsible for printing out each step as it happens (PowerShell).
The file responsible for generating the pdf (Python).
This article will ONLY be covering the first bullet point.
AD Group Review using LDAP
What is LDAP?
LDAP is not a directory service, but a protocol used to query and modify directory services. It is vendor-neutral and can communicate with various directory implementations, including AD. It is optimized for fast searches and mass queries.
Step 1, 2, 3: Connecting, Searching, & Extracting
We first connect to the Active Directory using LDAP and then search for the group under review. After finding the group in question, we extract the groupEntry path and then retrieve all of the users within that group. This is for processing's sake.
Step 4 & 5: Retrieving Member Properties & Displaying Results
Following the extraction of all users in said group, we process their details and display the results.
To begin with, the purpose of this review is to ensure alignment with regulations and policies, maintain pristine security measures, and ensure company compliance.
These would then be further probed into by the relevant senior figures or auditors.
Step 6: Exporting Evidence
This step is self-explanatory. This is the step where we export all retrieved group members to a CSV file, in a specified output directory, for storing and further processing.
Benefits of an Automated Auditing System
Complete removal of human error
Easy to maintain and modify
Easily scalable with increasing company size
Automatically generated review evidence documents
Saving hundreds of hours manually auditing groups
This article is part one of the Active Directory series. See you in the next one. CIAO!

