Enterprise Software Supply Chain Manager (ESSCM)IntegrationsVAPT Scans (CLI)
Active Directory Scan
Read-only assessment of Active Directory / LDAP identity posture
Active Directory Scan
The Active Directory scan performs a read-only review of your directory's identity posture. It queries Active Directory / LDAP for common identity and configuration weaknesses without making any changes.
Run it from the Safeguard CLI on a machine with access to the directory.
Prerequisites
- The Safeguard CLI installed and signed in.
- Network access to the directory and, where required, read credentials.
- Authorization (
--i-am-authorisedor an authorizingscope.yaml).
Usage
safeguard ad-scan --ad-url ldap://dc.example.internal --i-am-authorisedWhat you get
- Findings — identity-posture issues discovered in the directory.
Results upload to a project in your console when the scan completes.
Notes
- The scan is read-only — it does not modify directory objects or accounts.
- Provide the directory URL for the environment you administer, and run only against directories you are authorized to assess.