Active Directory penetration testing services: published prices, what they cover and how to choose

By The PenTest Index · Prices and terms checked October 10, 2026

Active Directory penetration testing services commonly start from an ordinary user inside your network and test whether that account can reach domain admin. Published prices we found run from $3,950 for an internal network test that includes Active Directory (Halo Security, starting price) to €12,800–€19,200 for a dedicated test (Syslifters, 8–12 days at €1,600). Most providers quote on request.

Those two prices buy different amounts of work, so don't line them up as cheap versus expensive yet. First pick the kind of test you need. Then use the price table, which shows what each published figure includes and when the retest runs out.

Which Active Directory test do you need?

Most buyers need one of five things, and only two of them are penetration tests. Find your row.

Table columns: If this is you; What to buy; Why; When it's not enough.
If this is youWhat to buyWhyWhen it's not enough
Nobody asked for a report. You want to know how bad things are.Nothing yet. Run a free check first.Tools like Purple Knight and PingCastle score your setup at no cost. Microsoft customers may already have an Active Directory Security assessment.Someone outside your team needs an independent report.
An auditor, customer or insurer asked for an "internal penetration test."Internal network penetration test with Active Directory written into the scopeThat is the document they asked for.The quote says "internal network" and never mentions Active Directory.
The directory itself is the worry: ransomware, a merger, certificate services, or last year's tester got domain admin fast.Dedicated Active Directory penetration testThe testing focuses on finding ways from a normal user to control of the domain.You also need every server and network segment checked.
You want a full fix-it list more than proof of an attack.Active Directory security assessment or attack path assessmentA review of settings and permissions covers more ground.Your recipient wants to see that an attack was carried out.
You want to know whether your security team would notice.Red team or purple team exerciseIt tests detection and response, which a normal pentest does not usually focus on.You just need a list of weaknesses. See red team services.

Two terms before we go on. Active Directory (AD) is the Microsoft system that holds your user accounts and decides who can log in to what. Domain admin is the account level that controls all of it.

One thing can rule out a provider no matter the price. If your IT company or MSP built your Active Directory, don't hire them to test it. They would be grading their own work.

Not sure a penetration test is the right purchase at all? See penetration testing vs vulnerability scanning.

Active Directory penetration testing services with a published price

Four providers publish a price or a day rate for testing that covers Active Directory. Three are in Europe and one is in the US. We read each page on October 10, 2026. We did not buy these services or ask for quotes, so every figure below is what the provider publishes, not what you will be charged.

Providers are listed A to Z in each group. This is not a ranking. Prices are shown in the currency the provider uses; we have not converted them.

Dedicated Active Directory tests

Table columns: Provider and offer; What it covers and who tests; Published price; What that adds up to; Retest; Ask this before you sign.
Provider and offerWhat it covers and who testsPublished priceWhat that adds up toRetestAsk this before you sign
Agility Cyber (UK), "Active Directory / Entra Security Assessment (Penetration Test)" on the UK government's G-Cloud 15 marketplaceOn-site and cloud Active Directory. Agility says its testers are UK based and security cleared. The listing also describes a "configuration review focus."Day rates of £1,300 (associate), £1,500 (lead) and £1,800 (principal) for cyber security testing. These are government marketplace rates.No total. The listing gives no number of days.Not stated"How many tester days for our size? How much of that is attack testing and how much is reviewing settings? Is a retest included?"
Syslifters (Austria), Active Directory and internal pentestStarts from a normal user account. You supply one unprivileged domain user, one domain workstation with local admin rights and a list of networks in scope. On-site preferred; remote on request."Roughly 8–12 person-days at €1,600 each." Its handbook gives a guideline of €12,000–€20,000 and a 15% discount from 20 person-days.€12,800 to €19,200 (8 × €1,600 and 12 × €1,600; our arithmetic)One free retest if your fixes are finished within eight weeks of report delivery"Is travel included for on-site work? What happens if our fixes take longer than eight weeks?"

Sources: Agility Cyber G-Cloud 15 listing; Syslifters service page; Syslifters pricing handbook. Provider-published. Checked October 10, 2026.

View the G-Cloud 15 listing

View the Active Directory pentest

Internal network tests that include Active Directory

Table columns: Provider and offer; What it covers and who tests; Published price; Retest; Ask this before you sign.
Provider and offerWhat it covers and who testsPublished priceRetestAsk this before you sign
Halo Security (US), internal network penetration testingStarts from inside the network. Lists "Active Directory Security": domain controller attacks, Kerberos weaknesses and group policy mistakes. One dedicated pentester; Halo says its testers are US based. You get a report and an attestation letter."Starts at $3,950." Halo gives a fixed-price quote after a scoping call. Price moves with host count, network segments and the size of your Active Directory."One round of retesting" included. No deadline stated."At the starting price, how many hosts and domains are covered? How many days go to Active Directory? Until when can we ask for the retest?"
VidraSec (Austria), internal IT infrastructure penetration testIncludes Active Directory testing "from an attacker's perspective," including checks of certificate services. Usually on-site. VidraSec sells a deeper Active Directory Audit separately."Fixed project price from €8,000." Typically 3–5 days of testing, with reporting time adding roughly 30–50% of the testing time. The offer total is final."Available on request." Price not stated."What does the retest cost, and by when must we ask for it?"

Sources: Halo Security internal network page; VidraSec internal pentest page. Provider-published. Checked October 10, 2026.

Both figures are starting prices. A starting price tells you the floor, not your bill. Halo's page also gives two timings: its process section says the tester "will generally spend about one week," and its FAQ says small networks take one to two weeks. Ask which applies to you.

View the internal network test

View the internal infrastructure test

What the day rates add up to

Agility Cyber publishes a day rate but no day count, so there is no total to compare. To give you a feel for the size of the bill, here is the rate multiplied by 8 and 12 days. We borrowed those day counts from Syslifters' estimate. They are not Agility's numbers, and your quote may use more or fewer days.

Table columns: Tester level; Day rate; 8 days (illustration); 12 days (illustration).
Tester levelDay rate8 days (illustration)12 days (illustration)
Associate£1,300£10,400£15,600
Lead£1,500£12,000£18,000
Principal£1,800£14,400£21,600

Providers that quote on request

These five describe relevant work on their own pages but publish no price for it. Read the note beside each one, because the names of their services do not mean the same thing.

Table columns: Provider; What its page describes; What the page does not say.
ProviderWhat its page describesWhat the page does not say
KrollAn Active Directory Security Assessment using "automated and manual testing." Its list includes certificate services, Kerberos, delegation, group policy and permissions. Done remotely.Price, length, retest. It is called an assessment, so ask whether the report will read as a penetration test.
Rapid7A goal-based internal network test that "may include" attempts to gain elevated access. Remote, during Rapid7's business hours. Rapid7 sets the number of service days.Active Directory is not named. Ask for it in writing.
SpecterOpsTwo separate services: penetration testing built around your objectives, and attack path assessments that map chains of misused privileges across Active Directory and Entra ID using its BloodHound Enterprise product.Price and retest. Ask which of the two your quote is for.
StingraiActive Directory engagements "quoted individually," starting from two unprivileged accounts by default. Stingrai says retesting of fixed findings is included.Price and retest deadline.
TrustedSecLists an "Active Directory Security Assessment" under its hardening services and "Penetration Testing" under its evaluation services.The assessment page states "real-time attack simulation and testing" but does not say whether it includes carrying out a full attack path. Its own menu files it under hardening, so ask.

Sources: Kroll; Rapid7 service documentation; SpecterOps services; Stingrai guide; TrustedSec services. Provider-published. Checked October 10, 2026.

View the Active Directory Security Assessment

View the goal-based internal test

View SpecterOps services

View the Active Directory service

View the Active Directory Security Assessment

Which offer deserves a closer look?

Start with the reason you are buying.

  • A US company that was asked for an internal penetration test. Look at Halo Security first. It is the only US provider we found with a published price, and it includes an attestation letter and one retest. It does not fit if the directory is your main worry and you want every day spent there, because the page does not say how much of the test goes to Active Directory.
  • The directory is the whole point and you want it priced up front. Look at Syslifters. It is the only dedicated test with enough published detail to work out a total. Its free retest does not fit if your fixes will take more than eight weeks, and remote work must be arranged if you can't host testers on site.
  • You want a specialist and you expect to pay for one. Ask SpecterOps and TrustedSec for quotes. Both name Active Directory work on their pages. Neither publishes a price, and both sell a review-style service next to their penetration test, so name the one you want.
  • You are a UK public body buying through G-Cloud. Agility Cyber's listing gives you the day rate. Get the day count before you compare it with anything.
  • You need every server and network segment covered, not only the directory. An internal network test from Halo, Rapid7 or VidraSec is the better starting point. Have Active Directory written into the scope.

We compare offers against a buyer's stated requirements and show the source for each term. That method is the PenTest Index Purchase Check. Here is one worked example.

Say you run IT for a 300-person manufacturer in Ohio. You have one domain, certificate services are installed, and accounts sync to Microsoft 365. Your insurer asked for an internal penetration test. You expect fixes to take about ten weeks. This buyer is made up.

Table columns: Your requirement; Offer; What the published terms show; Next question.
Your requirementOfferWhat the published terms showNext question
The report must be an internal penetration test (required by the insurer)Halo SecuritySupported. The offer is an internal network penetration test with an attestation letter. Your insurer still decides whether to accept it."Will you accept a report and attestation letter from this provider?" (to the insurer)
Certificate services and the Microsoft 365 sync are tested (wanted)Halo SecurityUnresolved. The page lists domain controllers, Kerberos and group policy. It does not name these two."Are certificate services and Entra Connect in scope?"
A retest after ten weeks (required)SysliftersMismatch. The free retest needs fixes finished within eight weeks."Can you extend the window, and at what price?"
A retest after ten weeks (required)Halo SecurityUnresolved. One round is included. No deadline is stated."Until when can we request the retest?"
The document is called a penetration test (required)KrollUnresolved. The service is an assessment."Will the report describe this as a penetration test?"

For this buyer, Halo is the first call. Three answers decide it: the retest deadline, the two missing scope items, and the insurer's yes. If Halo's answers come back wrong, the same three questions go to SpecterOps, TrustedSec and Rapid7.

How much does an Active Directory penetration test cost?

A dedicated test with a published figure comes to €12,800–€19,200 at Syslifters. Internal network tests that include Active Directory start at $3,950 at Halo Security and €8,000 at VidraSec. Agility Cyber publishes £1,300–£1,800 a day with no day count. Every other provider we checked gives a quote.

We could not find a US provider that publishes a price for a dedicated Active Directory test. Rather than guess at a "typical" US range, here is what the providers themselves say moves the number. Halo lists host count, network segments and the size and structure of your Active Directory. Stingrai lists the number of domains and forests, how many admin accounts you have, whether certificate services and cloud sync are in use, where the tester starts, and how thorough the retest is.

The gap between $3,950 and €19,200 is mostly a gap in days. A one-week internal test and a 12-day dedicated test are different amounts of work, so compare the days before you compare the price.

Check the day rate in your quote

If you already have a quote, divide the total by the number of tester days. That gives you a day rate you can hold against the published ones.

Count days of testing and reporting if the quote lists both.

This runs in your browser. Don't enter domain names, account names or passwords.

A made-up example. A made-up quote of €16,000 for 10 tester days works out to €1,600 a day, the same as Syslifters' published rate.

Budgeting for more than Active Directory? See penetration testing cost.

What's the difference between an Active Directory pentest and an internal network pentest?

An internal network test checks machines within the agreed scope for weaknesses. An Active Directory test follows one question: can a normal user account become the administrator of everything?

Think of an office building. An internal network test tries every door and window. An Active Directory test asks whether a visitor badge can be turned into the master key. The comparison has a limit: in practice the two overlap, and many internal tests include some directory work. How much is the thing to ask.

Table columns: Comparison factor; Active Directory penetration test; Internal network penetration test; Active Directory security assessment.
Comparison factorActive Directory penetration testInternal network penetration testActive Directory security assessment
The questionCan a normal user take over the domain, and by which routes?What can an attacker reach and break into across our internal systems?Where do our settings and permissions fall short of good practice?
Where the tester startsUsually a normal user account you provideA connection to the network, with or without an accountAn account that can read the directory
What the report leads withThe routes that worked, step by stepSystems that were broken intoA ranked list of settings to change
Buy it whenThe directory is the worryYou need the whole internal network coveredYou want a fix-it list more than proof

Why does the directory get its own test? Microsoft reported in April 2025 that in more than 78% of the human-operated attacks it observed, the attackers got into a domain controller, the server that runs Active Directory (Microsoft Security Blog). That is Microsoft's own data from its own customers.

VidraSec draws the same line on its page. Its internal test asks "can I reach Domain Admin?", and it sells a separate, deeper review of the configuration.

Is a free tool like PingCastle or Purple Knight enough?

For a first look, often yes. For a report someone else will rely on, no. A free tool scores your settings. It does not send a person to try the attack, and it does not give you an independent report.

Table columns: Tool; What it does; Cost and terms; Source.
ToolWhat it doesCost and termsSource
Purple Knight (Semperis)Scans Active Directory, Entra ID and Okta for risky settings and signs of compromise, and gives a score.Semperis describes it as free.Semperis
PingCastle (now part of Netwrix)Reports on Active Directory risk.Free to run "as long as you do not derive any revenue from it." A company can use it on its own systems. Anyone who includes it in a paid service must buy a licence.PingCastle download page
Microsoft Active Directory Security assessmentReviews privileged accounts, trusts, domain controller settings and permissions against Microsoft's guidance.Runs through Microsoft Engage Center and needs an Azure subscription. Ask your Microsoft contact whether your agreement includes it.Microsoft Learn

Checked October 10, 2026.

All three review settings. None of them is a penetration test, and Microsoft's own page describes its assessment as a set of reviews.

That PingCastle licence term gives you a useful question. If a consultant's "Active Directory assessment" turns out to be a PingCastle report with a cover page, ask whether they hold the commercial licence, and ask what a person did beyond running the tool. The sharper question for any provider is this: "Which attack routes did a person carry out, and which did you choose not to run?" A tester has a clear answer. A reseller of tool output does not.

What should an Active Directory penetration test include?

It should name the parts of your setup that create routes to domain admin, and say which ones the tester will try. Cyber agencies from the US, UK, Australia, Canada and New Zealand published joint guidance covering 18 common techniques used to compromise Active Directory, including Kerberoasting, password spraying and attacks on certificate services (ASD). You don't need to understand all 18. Send the link to each provider and ask which ones they test.

Kroll's page shows what a provider needs from you to price the job: how many forests and domains, how many user and computer accounts, how many domain controllers, how many trust relationships, and whether your network is flat or split into segments. Have rough answers ready. "Don't know" is a fine answer for any line; the provider will help you find out.

Copy this scope brief and send it to every provider

Send the same brief to each provider and the answers line up. Send a different description to each and you will get prices for different jobs.

Keep it high level. Do not put passwords, account names, server names, IP addresses or network diagrams in it.

Request for proposal: Active Directory security testing

1. Why we need this. [Who asked, or what we want to learn. Example: "Our insurer asked for an internal penetration test."]

2. Who receives the report, and by when. [Customer, insurer, auditor or our own team. Paste their exact wording if we have it. Date needed.]

3. Size, in round numbers. [Number of forests and domains. Approximate users. Approximate admin accounts. Number of domain controllers and sites. Trusts with other domains: yes / no / don't know.]

4. Certificate services (AD CS) in use? [Yes / no / don't know]

5. Synced to Microsoft Entra ID (Microsoft 365)? [Yes / no / don't know. Should the cloud side be tested too?]

6. Where the tester starts. [One or two normal user accounts we create for the test. A company laptop if we can provide one. Or: no account, network access only.]

7. Our account lockout threshold. [Number of failed logins before an account locks.]

8. Off limits. [Anything that could take a domain controller offline. Any systems, hours or techniques we rule out.]

9. What the report must contain. [What was tested and what was left out. Each route that worked, step by step. Which routes were only suspected. Fixes in priority order. A summary a non-technical reader can follow.]

10. Retest. [Our fixes should be ready by about ___. We need them rechecked by ___.]

Please state in your proposal: price and currency; number of tester days; who will do the testing; start date and report date; what is excluded; whether a retest is included, its deadline and its cost if extra; whether you will share a sample report; how you store and delete our directory data and any passwords you recover.

This brief is not permission to test. Testing needs signed, written authorization that names the systems and the activities.

A made-up example. A 75-person company has one domain, certificate services installed and Microsoft 365 sync. A customer asks for an internal pentest. The company first asks the customer whether the report has to show an attack being carried out. It then sends this brief to three providers with lines 4 and 5 marked "yes." Two come back with a penetration test. One comes back with a settings review. The review is not a cheaper version of the same thing. It answers a different question, so it leaves the comparison.

The brief covers Active Directory. If your request also takes in a web app, an API or cloud systems, or you still need to ask your report recipient what they will accept, Find My PenTest Match walks you through those questions and gives you a checklist to copy. It is free and needs no email. It does not yet list provider matches for internal network testing.

Build your scope checklist

For a filled-in example of a wider scope, see penetration testing scope.

What do you get at the end, and what about the retest?

You should get a report that shows each route from a normal user to admin, one step at a time, and a list of fixes in the order that closes the most routes. A list sorted only by severity score is much less useful here, because how serious a permission mistake is depends on where it leads.

Ask for a sample before you sign. Syslifters links a public sample Active Directory report from its service page, which is a quick way to see what one provider's finished work looks like. Halo includes an attestation letter, a short document you can hand to a customer in place of the full report if that customer accepts it.

The retest is where buyers get caught. A retest is the tester coming back to confirm your fixes worked. The three priced offers that mention one handle it three different ways:

  • Syslifters: one free retest if your fixes are finished within eight weeks of report delivery. Put that on a calendar. If the report arrives on Monday, November 16, 2026, eight weeks later is Monday, January 11, 2027. We counted 56 calendar days; confirm with Syslifters how it counts.
  • Halo Security: one round included, no deadline on the page.
  • VidraSec: available on request, no price on the page.

Active Directory fixes are slow. Changing permissions and service accounts in a live company takes meetings and change windows. Be honest in the brief about how long you will need, and get the retest deadline in writing.

More on deliverables: penetration testing report.

Does PCI DSS, SOC 2 or cyber insurance require an Active Directory penetration test?

We have not found a standard that asks for Active Directory testing by name. What buyers are usually asked for is internal penetration testing, and the person receiving your report decides what counts.

So ask them, in writing, before you buy:

  1. "Which systems must the test cover?"
  2. "Does the test have to show an attack being carried out, or is a review of settings enough?"
  3. "Does the tester need to be independent of us or hold a particular qualification?"
  4. "How recent must the test be?"

Their answers go into line 2 of your brief. For what each rule actually says about penetration testing, see our source-by-source tracker. If you answer to a PCI assessor, an auditor or an insurer, their reading is the one that matters, not ours and not a provider's.

Is it safe to test a live Active Directory?

It is routine work, but nobody can promise zero disruption, so agree the rules before testing starts. Sysadmins discussing internal tests on Reddit raise the same worries again and again: locked-out accounts and knocked-over servers (one thread, another). Both are handled in the rules of engagement, the signed document that says what testers may do.

Get these four things in writing:

  • Your lockout threshold, so any password guessing stays under it.
  • No attacks meant to take a domain controller offline.
  • Testing hours. Rapid7's service description, for example, says work is done during its standard business hours.
  • A named contact on each side and a way to stop the test. Syslifters says it reports critical findings during the engagement instead of waiting for the report.

NIST's guide to security testing, SP 800-115, covers planning and rules of engagement if you want a neutral reference (NIST). Our own walkthrough is at penetration testing rules of engagement.

Do you need a new test if you already had an internal pentest?

Maybe not. Pull out last year's statement of work and report and check four things:

  1. Does the scope name Active Directory, or only "internal network"?
  2. Where did the tester start, and did they try to reach domain admin?
  3. Were certificate services and the Microsoft 365 sync covered, if you have them?
  4. Is the report recent enough for whoever is asking now?

If the answers are yes, send the report to your recipient and ask whether it is accepted. That costs nothing. If Active Directory got one paragraph, ask your current provider to quote an add-on using the brief above before you shop for a new one.

Already have a quote?

Run it through the day-rate check above, then hold it against the ten lines of the brief. Anything the quote doesn't answer is a question to send back. For a line-by-line review, run a Quote Check.

Questions buyers still ask

How long does an Active Directory penetration test take?

The providers that publish a figure say this: Syslifters plans roughly 8–12 person-days; VidraSec says 3–5 days of testing for its internal test, up to two weeks for large environments, plus reporting time; Halo says about one week of testing, or one to two weeks for small networks. Those are testing days. Scheduling, report writing and your fixes come on top. See how long a penetration test takes.

Do the testers need to be on site?

No, but some prefer it. Syslifters and VidraSec both say they generally work on site and can test remotely by arrangement. Halo offers VPN access or a small device it ships to you to plug into your network. Kroll and Rapid7 describe remote delivery.

Does an Active Directory test cover Microsoft Entra ID and Microsoft 365?

Only if the scope says so. Active Directory runs on your own servers. Entra ID is Microsoft's cloud directory. Many companies sync the two, and that link can be a route in either direction. Line 5 of the brief asks about it.

Is a BloodHound map proof that a pentest was done?

No. BloodHound draws the possible routes from one account to another. Whether a person followed a route and proved it works is a separate piece of work. Ask which routes were carried out.

Is this page for learning how to pentest Active Directory?

No. It is for people buying the service. If you want to understand what testers do, start with how to do a penetration test.

Sources

All pages read on October 10, 2026. Offer details are provider-published. We did not buy any service, request any quote or inspect any provider's work.

Table columns: Source; What we used it for.
SourceWhat we used it for
Agility Cyber, G-Cloud 15 listingDay rates, service description
Halo Security, internal network penetration testingStarting price, coverage, retest, timing
Kroll, Active Directory Security AssessmentsCoverage list, scoping questions
Rapid7, goal-based internal network testScope wording, hours, delivery
SpecterOps, servicesPenetration testing and attack path assessment descriptions
Stingrai, Active Directory penetration testing services guideIts own offer terms and stated price drivers
Syslifters, Active Directory pentestDay count, day rate, preparation, retest
Syslifters, pricing handbookDay rate, discount, guideline range
TrustedSec, servicesWhere its Active Directory assessment and penetration testing are listed
VidraSec, internal IT infrastructure penetration testStarting price, duration, retest
Microsoft Learn, Active Directory Security assessmentWhat the assessment reviews and needs
Microsoft Security Blog, April 9, 2025Domain controller figure
Semperis, Purple KnightTool description and cost
PingCastle, download and licenceLicence terms
ASD and partner agencies, Detecting and mitigating Active Directory compromisesUpdated joint guidance and its 18 techniques
NIST SP 800-115Reference for planning security tests

Found a price or term that has changed? Tell us and we will check it and update the date.