Active Directory Security Audit Kit for Solo IT Teams
A fillable AD audit checklist covering privileged access, stale accounts, GPO hygiene, MFA gaps, and event log review — everything an auditor expects, packaged for the sysadmin who has no security team.
- ▸AD Audit Checklist — 25 fillable items across 6 sections with evidence fields, risk decisions, and a sign-off attestation block ready for submission
- ▸Privileged Access Reference — group inventory, "what good looks like," and 5 PowerShell commands to audit Domain Admins and tier-0 accounts
- ▸Stale Accounts Reference — thresholds, service account exceptions, offboarding guidance, and discovery commands
- ▸GPO Hygiene Reference — security baseline settings, LAPS check, SMBv1/NTLMv1 remediation
- ▸MFA Gap Assessment — posture by tier, insurer expectations, MFA method quality table, coverage inventory worksheet
- ▸Event Log Coverage Reference — 20 critical Event IDs, audit policy configuration, log sizing, and WEF setup overview
- ▸README — 3-step usage guide, PDF render instructions, and FAQ
## goes-well-with
From the same shelf
Windows Event Log Analysis Field Guide for Sysadmins
A practical reference guide covering the 20 most critical Windows Event IDs every sysadmin must monitor — with detection logic, triage steps, and copy-paste PowerShell queries for each.
Microsoft Entra ID Migration Starter Kit for Sysadmins
A practical guide + checklist bundle for IT admins migrating on-premises Active Directory to Microsoft Entra ID in 2026 — covering Cloud Sync, legacy auth deprecation, Intune join strategy, and a phased migration checklist sysadmins can actually execute.
Windows Server Patch Management Playbook
For solo sysadmins and small IT teams managing Windows Server patching at SMBs — a practical guide and checklist bundle that turns a monthly fire drill into a repeatable process.
## not-ready-to-buy
Take the field notes instead
One practical write-up a week from the same workbench these kits come from — plus reader pricing when new kits ship.