Identity & infrastructure / report template

Active Directory Pentest Report Template & PDF Example

An Active Directory pentest report connects identity and infrastructure findings to the decisions needed to secure a Windows environment. This template brings the domain context, risk summary and remediation roadmap into one structured deliverable.

Cover of the active directory assessment sample report
23 pages · Example report · English

Give identity risks the context they need.

An Active Directory assessment examines how directory configuration, administrative privileges and supporting systems affect an organization's security. The report needs to explain which domains and systems were included, what access the assessment used, and where its conclusions apply. That context helps infrastructure teams distinguish a local issue from a concern that affects shared identity services.

This template separates executive priorities from technical finding details. An environment overview introduces the directory and its tiering model, while a staged remediation roadmap gives readers a clear place to plan follow-up work. Adapt the content, timelines and priorities to the environment you actually assessed.

Active Directory Assessment: scope, evidence and references

The guidance below describes how to scope and document the work. It does not imply that every topic is covered by the sample PDF. Record the reference editions used in your own engagement.

Scope identity control, not just domain controllers

Define the forests, domains, trusts, administrative populations and management systems included in the engagement. Include certificate services, directory synchronization and recovery infrastructure only where access and authorization cover them. A domain inventory alone does not explain who can administer the identity system or change its security controls.

Separate a configuration assessment from a penetration test. State whether conclusions come from directory exports, policy review, interviews, endpoint observations or authorized validation. Record collection dates and permissions: restricted visibility can omit relevant memberships, policy settings and dependencies.

Use the AD tier model in its current context

Microsoft describes the AD DS tier model as part of the broader Enterprise Access Model. Its trust boundaries concern administrative identities, workstations and managed assets, not just network zones. Describe the actual administrative model rather than treating an OU name or a network diagram as proof of separation.

For a privileged-access finding, document the affected identity or management system, the intended boundary, the observed permission or configuration and the business services dependent on it. A broad privilege label without its scope does not give an infrastructure owner enough information to prioritize a correction.

Report dependencies and closure criteria

Group instances of the same underlying configuration problem while preserving the affected-object list. Explain whether a finding is domain-wide, limited to one administrative workflow or confined to sampled systems. Keep confirmed observations separate from unverified consequences.

A useful roadmap identifies the owner, compatibility constraints, interim control and final acceptance evidence. For example, a privileged-account separation change needs reviewed assignments and representative administration records, not only a screenshot of a newly created group. Describe recovery testing separately from the existence of a backup.

Inside this example report

The 23-page PDF shows how the report is organized. Its example content illustrates the layout; adapt it to the scope and evidence of your own engagement.

  1. 01

    Document control

    Confidentiality, version history and a distribution list establish who receives the report and which version they should use.

  2. 02

    Executive summary

    An assessment narrative and severity counts introduce the main risks before readers reach the technical detail.

  3. 03

    Scope and environment

    Scope, methodology, domain information and an administrative tiering overview explain the setting for the findings.

  4. 04

    Findings and recommendations

    A summary leads into individual findings with descriptions, supporting evidence, impact, remediation and references.

  5. 05

    Remediation roadmap

    Immediate, short-term, medium-term and long-term planning sections organize follow-up work, with a prioritized summary table.

  6. 06

    Reference appendix

    A glossary and severity rating scale help technical and management readers interpret the same terminology.

Read the full sample PDF

Make the report useful to its readers

Name the boundaries

State the forests, domains and supporting systems covered, along with exclusions and access limitations. Keep those names consistent across the scope, findings and summary.

Explain the organizational impact

Describe which services, administrative responsibilities or business operations a finding affects. Tie the severity rationale to that context so readers understand the proposed priority.

Make the roadmap assignable

Set agreed priorities, owners and dependencies. Distinguish an interim risk reduction from the lasting change, and record what will demonstrate completion.

Make it your own in Vulnotes

  1. 1

    Download your template from Vulnotes Manager

    Sign in to Vulnotes Manager, download this template and add it to your instance. Select it when creating a report to reuse its layout, report variables and finding sections. The public PDF shows an example of the finished output.

  2. 2

    Let Vulnotes fill the connected variables

    The template includes variables connected to your report: client details, engagement dates, findings and severity statistics where used. Vulnotes fills these from the data saved in your report. Add your findings and complete assessment-specific sections such as scope, analysis and conclusions; automatic population does not replace that work. Match the finding fields and categories expected by the template.

  3. 3

    Edit the structure and visual design

    Change page layout, orientation, margins, fonts, colors, branding, headers and footers in the template editor. Edit or replace tables, chart settings, images, code blocks and section labels. Heading numbering and the table of contents can be adapted to your delivery conventions. Text embedded inside an image must be changed in the source image or replaced.

  4. 4

    Adapt the data bindings

    Report variables hold engagement-specific content. Finding loops and filters control repeatable sections; charts and score tables can use report data. Review these bindings when renaming fields or changing the finding structure. Individually authored slide summaries still need editorial updates when findings change.

  5. 5

    Write, review and deliver

    Create your report with its client, scope and dates. Replace the example content, add your findings, review the preview and export the finished document.

Three ways to create and adapt your templates

Use the template editor

Start with a Manager template or create your own in the visual editor. Change the layout, branding, content and variables, then preview the result with your report data.

Template editor documentation

Import your existing Word document

Import a DOCX report into Vulnotes as an editable template draft. Review conversion warnings and page layout, then connect report variables and finding sections before reusing it. Complex Word formatting may need adjustments.

DOCX import documentation

Create and edit through MCP

Connect an MCP-compatible assistant to Vulnotes to create templates or edit pages, elements, variables and styling. Access follows your API key permissions. Review the changes and preview the document before using it for client delivery.

MCP setup and template authoring

See which fields Vulnotes supplies automatically and how to add engagement-specific content in the report variables documentation. Browse available templates in Vulnotes Manager.

Common questions

What should an Active Directory assessment report include?

Include the assessment scope, directory environment, executive summary, evidence-backed findings and a prioritized remediation plan. Document access limitations and explain severity ratings so the recipients can understand both the risks and the boundaries of the assessment.

Is this suitable for a broader internal network assessment?

It is a useful starting point when Active Directory is central to the engagement. Add separate coverage for other infrastructure, applications or services in scope, and adapt the environment overview to describe them accurately.

How should I set remediation deadlines?

Set deadlines using your organization's risk decisions, operational constraints and change process, then update the plan as owners agree the work.

How do I use the Active Directory template in Vulnotes?

Preview the example PDF without an account. Download the template from Vulnotes Manager, add it to your instance and select it for your report. Its connected variables use your client, engagement and finding data. Complete the assessment narrative and customize the branding in the template editor.

What export formats are available in Vulnotes?

Vulnotes exports reports as PDF, editable Word documents (DOCX), Excel spreadsheets (XLSX), structured report data (JSON), and ZIP archives containing the report PDF and attachments, with optional password protection. XLSX lets you select finding fields and report content sections. You can also export selected findings as a partial PDF or DOCX report. The client portal additionally offers CSV exports of findings when enabled by the administrator. Read the export documentation.

Further reading