Remediation Assistance

Need help fixing what
Insight Recon found?

We can work through the findings with your team or handle approved remediation directly. The work is scoped around your environment, your priorities, and the changes you are comfortable making.

AD and hybrid identity Advisory or hands-on Breach Point practitioners
Subscriber Rate Discounts
No minimums
Enterprise
Active Enterprise subscription
40% off
Auditor
Active Auditor subscription
25% off
Standard
Active Standard subscription
15% off
Free / No Plan
No paid subscription required
Base rate
You do not need a paid plan to use the service. Work is billed hourly. Hands-on implementation is scoped separately when access or production changes are required.

When this helps

Some AD findings are simple.
Some are not.

The report gives you the finding, affected objects, attacker context, remediation guidance, validation steps, and evidence to retain. Sometimes you still want another person in the room before changing Tier 0.

Internal Teams

You know what needs to change, but want someone to review the plan.

We can validate the remediation path, work through dependencies, review commands, and help your team avoid turning a security fix into an outage.

Consultants & MSSPs

Your client wants help after the assessment.

We can work behind the scenes with your team or directly with the client, depending on how you want the engagement structured.

Complex Findings

The finding touches parts of AD you do not change every day.

ADCS, delegated permissions, krbtgt rotation, hybrid identity, trusts, and Tier 0 changes deserve more care than copying a command from a report.

How engagements work

Start with the findings.
Scope only what you need.

We use the Insight Recon report as the starting point, identify the findings you want help with, and decide how much of the work should stay with your team.

1

Review

We review the findings, affected objects, remediation guidance, and relevant environment details.

2

Scope

We agree on which findings need help, expected effort, and whether the work is advisory or hands-on.

3

Remediate

Your team makes the changes with us, or we implement approved changes under the agreed scope.

4

Validate

We verify the change, review expected evidence, and rescan where appropriate to confirm the finding is gone.

What we work on

The same parts of AD
attackers care about.

Remediation can range from a single account setting to a broader redesign of privileged access. These are some of the areas we regularly help teams work through.

Accounts & Authentication

Credentials, Kerberos, and service accounts

  • Password and account-control issues
  • Kerberoastable and AS-REP roastable accounts
  • krbtgt rotation planning and validation
  • Stale, privileged, or unnecessarily exposed accounts
Privileged Access

Groups, ACLs, and Tier 0 permissions

  • Dangerous control over privileged objects
  • Excessive Domain Admin and Enterprise Admin membership
  • Delegated permissions and inherited access
  • Privileged access model cleanup
ADCS

Certificate Services

  • ESC1 through ESC16 findings
  • Certificate template permissions
  • Enrollment and issuance configuration
  • Certificate Authority hardening
Domain Configuration

GPOs, trusts, delegation, and hygiene

  • Group Policy security settings
  • Kerberos delegation and protocol configuration
  • Trust configuration and SID filtering
  • LAPS, legacy protocols, and domain hygiene
Hybrid Identity

The on-premises footprint of Entra ID

  • Directory synchronization account permissions
  • AZUREADSSOACC$ rotation and control
  • Cloud Kerberos Trust and AzureADKerberos exposure
  • Privileged paths created by Entra Connect and related components

How we work

Keep the keyboard,
or hand it to us.

The engagement does not have to be all-or-nothing. Some findings may only need a review. Others may justify a separately scoped implementation.

Advisory
Your team makes the changes. We help you understand the finding, plan the remediation, and validate the result.
Review the affected objects and attack path
Walk through PowerShell, ADUC, GPO, or other remediation paths
Discuss dependencies and potential production impact
Review validation and evidence requirements
Confirm closure after a follow-up scan
Everything included in the advisory workflow
Implementation of agreed remediation steps
Coordination with infrastructure or identity owners
Change and rollback planning where appropriate
Validation after the change

Who you're working with

The team behind
Insight Recon.

Insight Recon came out of the Active Directory problems we kept seeing in offensive security and enterprise identity work. The remediation service is an extension of that work.

You are not being handed to a generic support queue. The people working with you understand why the scanner raised the finding, what an attacker can do with it, and what needs to change for the finding to actually be closed.

Offensive Security

We approach findings from the abuse case first. That matters when deciding which exposures deserve immediate attention and which changes can wait.

Enterprise Identity

Remediation has to work in production. We account for dependencies, delegated administration, hybrid identity, and the operational reality around Active Directory.

Product Context

We know how Insight Recon evaluates the environment and what each finding is intended to detect, so there is no handoff between the scanner and someone learning the finding from scratch.

Get a quote

Tell us what you
need help with.

Send us a little context about the findings and the type of help you want. We will scope the work and come back with an estimate.

Single findings are fine

You do not need a large remediation program. If you only want help with one difficult finding, say so.

No paid Insight Recon plan required

Free users can purchase remediation assistance at the base hourly rate.

Subscriber discounts apply automatically

Standard, Auditor, and Enterprise subscribers receive 15%, 25%, and 40% off the base hourly rate.

Remediation quote request
Tell us what you found and what kind of help you are looking for.

By submitting you agree to our Privacy Policy and Terms of Use. Hands-on implementation may require a separately scoped statement of work.

Request received.
Thanks for reaching out. A member of the team will follow up with you.