Safeguard Docs
Enterprise Software Supply Chain Manager (ESSCM)IntegrationsVAPT Scans (CLI)

Active Directory Scan

Read-only assessment of Active Directory / LDAP identity posture

Active Directory Scan

The Active Directory scan performs a read-only review of your directory's identity posture. It queries Active Directory / LDAP for common identity and configuration weaknesses without making any changes.

Run it from the Safeguard CLI on a machine with access to the directory.

Prerequisites

  • The Safeguard CLI installed and signed in.
  • Network access to the directory and, where required, read credentials.
  • Authorization (--i-am-authorised or an authorizing scope.yaml).

Usage

safeguard ad-scan --ad-url ldap://dc.example.internal --i-am-authorised

What you get

  • Findings — identity-posture issues discovered in the directory.

Results upload to a project in your console when the scan completes.

Notes

  • The scan is read-only — it does not modify directory objects or accounts.
  • Provide the directory URL for the environment you administer, and run only against directories you are authorized to assess.

On this page