Security Guardian Identity Assessment
Delivered by NTT DATA in partnership with Quest
The Security Guardian Identity Assessment gives organisations clear, data driven insight into identity exposure and privileged access risk across Active Directory, Entra ID, and hybrid identity environments. Using Quest Security Guardian, we rapidly identify misconfigurations, exposure pathways, and high-risk access models. The assessment provides leadership and delivery teams with a clear plan for risk reduction and identity uplift.
Assessment Overview
This assessment provides a structured, four step approach that creates rapid visibility, prioritisation, and actionable outcomes
Rapid AD and Entra ID Assessment & Maturity Strategy
The Rapid AD and Entra ID Assessment and Maturity Strategy delivers ultra efficient, data-driven insights to immediately highlight active identity vulnerabilities, misconfigurations and potentially even malicious activity. Using best practice standards and frameworks, we identify and prioritize high-risk Identity exposures, define optimal safeguards for critical objects, identify and list Tier Zero objects and formalize how to prevent Identity threats before they escalate.
Step 1
Alignment

Alignment workshop to understand your strategic and technical Identity objectives, including access provisioning and configuration of Quest Security tooling.
Step 2
Assessment

Conduct Rapid AD and Entra ID Assessment & Strategy to locate Tier Zero objects, active exposures, security weaknesses and misalignment from best practice.
Step 3
Analysis

Complete analysis of located risks, delivering actionable recommendations, insights, risk reduction pathway and remediation prioritization.

Step 4
Playback

Facilitate executive playback workshop highlighting key findings, risk position, recommendations, and remediation plan.

How the Assessment Works
Below is the complete delivery workflow from initial activation through to findings, prioritisation, and agreed next steps.
Delivery Phases
Alignment & Activation
  • Activate project and review Identity goals
  • Map assessment to client objectives
  • Access provisioning and Quest Security tooling config
AD & Entra ID Assessment
  • Deploy AD discovery agent and Entra ID connector
  • Configure data sources and reporting modules
  • Initiate assessment to formalise AD security posture
SME
Analysis
  • Expert-led AD risk analysis against best practice
  • Expert-led Entra ID risk analysis
  • Alignment with frameworks, GRC requirements
Clear & Actionable Next Steps
  • Executive report with findings and recommendations
  • Critical risks and risk prioritization
  • Remediation plan and detailed analysis
  • Quarterly review to align with maturity goals
Phase 1: Alignment and Activation
Set the objectives and prepare the assessment.
  • Clarify identity goals and client outcomes
  • Map assessment scope and expectations
  • Provision access and configure Quest Security Guardian
  • Confirm stakeholders, timelines, and reporting preferences
Phase 2: AD and Entra ID Assessment
Run the technical discovery and data collection.

  • Deploy Active Directory discovery agent
  • Deploy Entra ID connector
  • Configure data sources and reporting
  • Initiate identity posture and exposure assessment
Phase 3: SME Analysis
Translate data into clear, prioritised insights.

  • Expert review of AD and Entra ID findings
  • Analysis against identity security best practice
  • Alignment with ISM, PSPF, and Essential Eight uplift needs
  • Identification of critical risks and Tier Zero weaknesses
Phase 4: Clear and Actionable Next Steps
Provide leadership and technical teams with practical, prioritised guidance.

  • Executive report with key findings and recommendations
  • Prioritised risks and remediation sequencing
  • Detailed technical remediation plan
  • Optional quarterly review to track uplift progress
What the Assessment Identifies
  • Identity exposure paths and misconfigurations
  • Privileged access sprawl and high-risk delegation chains
  • Identity hygiene issues such as stale or orphaned accounts
  • Over permissioning and weaknesses in access models
  • Monitoring and visibility gaps across identity activity
  • Application, service, and federation dependencies
  • Issues that impact assurance, auditability, and policy alignment
Outcomes
Executive Outcomes
  • Clear visibility into identity exposure and privileged access risk
  • Prioritised issues and decision points for uplift planning
  • Maturity indicators and staged improvement themes
  • Defined next steps for reducing identity risk
Operational and BAU Outcomes
  • Detailed findings for remediation teams
  • Visibility into misconfiguration, delegation, and admin pathways
  • Sequencing guidance for uplift activities
  • Operational considerations for sustained posture management
Further Engagement Options
  • Deeper validation and expanded discovery
  • Mapping findings to compliance and policy requirements
  • Target state identity architecture and maturity roadmap
  • Remediation delivery and operationalisation support
  • And many more.
Ready to reduce your identity risk?
Request your NTT DATA Assessment Discussion now.
Security Guardian Identity Assessment delivered by NTT DATA in partnership with Quest.


About  |  Privacy statement  |  Terms of use

© 2025 NTT DATA Inc. All Rights Reserved.