
The threats to corporate identity are constantly evolving, and when an attacker breaches the identity system, the impact is long-lasting and costly. In this context, auditing and strengthening Active Directory (AD) and its cloud counterpart, Entra ID/Azure AD, has become a daily necessity for IT and security. Choosing the right tools and understanding what each one offers It is the first step to closing gaps before someone exploits them.
Among the best-known free options are Purple Knight (Semperis) and PingCastle (originally created by Vincent Le Toux and currently part of the Netwrix ecosystem). Both run smoothly and provide valuable diagnostics, but their approach, methodology, and target audience differ. Compare them closely, without overlooking their limitations and strengths.It allows you to decide when to use one or the other, or why to combine them to get the most out of them.
Identity security: why focus on Active Directory and Entra ID
AD and Entra ID typically concentrate control of accounts, permissions, authentication, and trust relationships; if they fail, the heart of enterprise access fails. Intrusions into these systems can remain invisible for months.This exposes critical assets and facilitates lateral movement. Therefore, strengthening identity security requires prioritizing Active Directory and its cloud layer. One-off assessment tools help obtain a clear picture of the risk, while continuous monitoring tools allow for timely intervention to address deviations.
PingCastle: A maturity-based snapshot of the AD environment
PingCastle was born as an Active Directory assessment tool developed in C# by Vincent Le Toux and consolidated in the market with a free basic edition since 2017. Its purpose is to measure the risk and security maturity of Active Directory based on models and rulesgenerating a health and risk report highly focused on practical decisions.
What PingCastle does well
One of its strengths is translating technical data into contextual information: it analyzes Active Directory subprocesses, trust relationships, privileged accounts, and obsolete objects, among other things. The result is a risk score and a detailed report that can be consolidated with others to facilitate comparisons over time. Additionally, it incorporates an Active Directory map to visualize hierarchies and trusts.This speeds up the understanding of complex environments and uncovers forgotten domains.
- Risk and health assessment based on internal models and rules, with scoring and risk reporting.
- Visibility of privileges and potential routes to critical objects, with a focus on high-access accounts.
- Domain and trust mapping to visualize relationships, including trust considerations with Azure AD/Entra ID.
- Consolidation of reports for benchmarking, KPIs and management dashboards (in higher editions).
PingCastle also goes beyond the directory and performs workstation scans for unsafe practices. Detects excessive local administratorspoorly protected shared resources, vulnerabilities like WannaCry and even irregularities in start-up time, which helps to uncover backdoors and delegation weaknesses that could facilitate lateral movement.
How it works and what it delivers
PingCastle's engine collects data using unprivileged LDAP queries and WMI, and can be integrated with powershell scripts, and applies a risk model grouped by categories: obsolete objects, privileged accounts, trusts and anomalies. The resulting report highlights critical problems (for example, outdated trust protocols, fragile delegations, weak Kerberos configurations, or insecure control paths) and assigns an AD health score: the lower, the better.
In hybrid environments, PingCastle can report on whether the trust relationship with Azure AD is well secured. The map view and the consolidation of results They are especially useful for organizations with many domains or multiple trust relationships, where it's easy to lose track.
Editions, license and scope
The basic edition is free for auditing your own environment, while the Auditor/Standard and Professional editions add advanced capabilities and commercial support. Subscriptions such as Auditor (around $3.449/year) and Professional are marketed. (around $10.347 per domain per year), plus an Enterprise edition with consolidation features and a global perspective for large companies. The project signs its binaries and releases the code under the OSL 3.0 (Non-Profit) license, with restrictions on unlicensed commercial use.
Known limitations of PingCastle
In deployments with many domains, reports can be dense and somewhat difficult to navigate if consolidation processes and views are not established. The free edition does not include advanced reports or detailed remediation guides.and the focus is on indicators of exposure and risk, not on signs of compromise that have already materialized.
Purple Knight: Exposure and engagement indicators at the click of a button
Semperis launched Purple Knight in 2021 as a free security assessment tool for Active Directory and hybrid environments. Since then, it has become a favorite due to its focus on Indicators of Exposure (IOE) and Indicators of Compromise (IOC). Its goal is to uncover risky configurations and evidence of intrusion. In AD, enter ID/Azure AD and even Okta.
Indicators, categories and reference frameworks
Purple Knight groups results into five main areas: AD Delegation, AD Infrastructure Security, Account Security, Group policy security (GPO) and Kerberos Security. The report uses a "bulletin" with a rating by category and an overall percentage., offering prioritized remedies, severity (Informative, Warning or Critical) and mappings to frameworks such as MITRE ATT&CK and ANSSI, in addition to references to the MITRE D3FEND model.
- More than one hundred indicators (and recent versions easily exceed that figure) covering common attack vectors.
- Difference between IOE and IOC to separate potential misconfiguration from evidence of active compromise.
- Prescriptive correction guidelines and prioritized by risk and probability of exploitation.
- Hybrid coverage with local AD, Enter ID/Azure AD and Okta support.
User experience and reporting
The tool is portable and has a graphical interface. You download a ZIP file, extract it, and run the binary; upon startup, it detects forests and domains and allows you to select which IOE/IOC to run—a granularity that both blue and red teams appreciate. The scan is usually completed in minutes and generates an HTML report that includes a checklist of critical IOE and clear explanations with links to documentation.
The "report card" format is convenient: a letter and a percentage, with different weights for each category. The descriptions include the reason, the impact, the fit within security frameworks, and remediation steps.Purple Knight runs in read mode, makes no changes to Active Directory, and does not "call home"; it can be repeated periodically without risk to production.
Registration, community version and development
To download the tool, Semperis requires registration and provides the link; it also notifies users of new versions and continuous improvements. The Community edition is updated frequently And it maintains a remarkable polish despite its youth, with improvements based on community feedback.
Limitations and how it is complemented
Purple Knight performs one-off assessments; it is not a continuous monitoring solution nor does it automate mitigation on its own. That layer is provided by Directory Services Protector (DSP) from Semperis.which is a paid service and is geared towards real-time identity threat detection and response (ITDR), with alerts and reversal of malicious changes.
Purple Knight vs PingCastle: what they have in common and how they differ
Although both tools can be used to assess Active Directory security and support hybrid environments with Entra ID/Azure AD, their focus is not identical. PingCastle prioritizes a maturity methodology and a “health check” report with risk scoring; Purple Knight focuses on IOE/IOC and on providing a highly actionable remediation guide. The first one looks closely at the “model” and the state of the AD ecosystem, while the second delivers a very rich snapshot to correct quickly.
In terms of ease of use, Purple Knight stands out for its interface and granular test selection; in PingCastle, the domain map and report consolidation shine in organizations with many forests and trusts. In reporting, Purple Knight rates by category with a score and percentage.And PingCastle offers an overall health score where a lower number is better.
For coverage, Purple Knight encompasses AD, Entra ID/Azure AD and Okta and maps findings to MITRE ATT&CK and ANSSI, prioritizing remediation. PingCastle, for its part, offers analysis of delegations, stale objects, local privileges, and endpoint vulnerabilities.And it can assess trust security with Azure AD. The ability to discover forgotten domains and unify results is a plus when the perimeter has become blurred.
In terms of licensing, Purple Knight is offered as a free tool (after registration); continuous and corrective capabilities reside in Semperis DSP, which is commercial. PingCastle offers a free basic edition for personal use. and paid editions (Auditor/Standard, Professional, Enterprise) with extended functionalities, support and scalability.
Which one to choose? If you're looking for a quick, clear assessment with prioritized repair instructions, Purple Knight is a perfect fit. If what you need is a maturity method with domain mapping and risk consolidation For hundreds or thousands of segments, PingCastle might be a better fit, especially with its paid editions. In practice, many organizations use both: the combination offers cross-validation and deeper coverage.
Practical details of implementation and results
Both tools are portable and can be run with standard user credentials in most contexts, collecting data primarily by reading. This makes it easier for teams with limited resources to adopt. and avoids friction with production systems, since they do not make changes.
Purple Knight stores its results in HTML with a logical structure and links to documentation, as well as a checklist that highlights what is urgent. The breakdown by severity and the reference to frameworks It provides context to CISOs and technical teams. PingCastle, for its part, delivers a report with scores, prioritized findings, and, if desired, consolidated views to facilitate KPIs and quarterly monitoring.
Warnings and operational considerations
With PingCastle, in multi-forest environments or with dozens of domains, reports may require additional work to navigate and prioritize. The basic edition lacks advanced features and extensive proofreading guidesThese features are included with paid licenses. Purple Knight, being a one-off assessment, does not replace a continuous monitoring system, and its automated mitigation capabilities are not available in the free version.
Neither of them is intended to be an IDS/IPS for AD; they are diagnostic complements that feed into remediation and maturity plans. In scenarios with real-time alert and response needsITDR solutions such as Semperis DSP or continuous audit offerings come into play.
Other tools that complement the ecosystem
When the focus is on continuity and recording every change with context, Netwrix Auditor provides change control in Active Directory and other systems (Exchange, SQL Server, SharePoint, Microsoft 365, Teams, etc.). Its focus is on alerting users to suspicious modifications. (for example, if a user is added to the Domain Administrators group) and maintain a configuration history with views useful for governance.
To understand attack paths and control relationships, BloodHound is a classic open-source (GPL-3.0) tool that models objects, relationships, and permissions in AD, with compilers like SharpHound and AzureHound. It's key for red teams and also for blue teams who want to visualize the "shortest path" to critical objectives and close off climbing routes.
In the area of real-time response and monitoring, Semperis' Directory Services Protector (DSP) offers continuous monitoring, alerts, and even automated rollback in response to malicious changes, both in AD and Entra ID. It acts as the missing ITDR layer in a point assessment. and accelerates the containment of identity incidents.
The French ANSSI (French Data Security Agency) provides utilities such as ORADAD for Active Directory and ORADAZ for Azure/Entra, used in advanced audits. Although the data collection is public, the complete processing requires unpublished tools. These are valuable references for teams that follow government guidelines. or wish to align audits with recognized best practices.
Some market comparisons show offers with hosting and varied deployments (Windows service, portable, on-premises or SaaS), correlation with MITRE ATT&CK, export to CSV, multi-tenant capability and options to accept risks in a documented way. In practice, the choice boils down to balancing spot auditing, incident detection, and ongoing governanceTaking into account budgets, licensing (free for personal use in some cases) and partner support.
Frequently asked questions: Can I prevent a user from running these tools?
This is a common question when you discover that portable tools can run without administrator privileges. Generally, Purple Knight and PingCastle operate in read-only mode with user permissions to query the directory. If your goal is to restrict its execution, then application control comes into play.Policies such as AppLocker or Windows Defender Application Control (WDAC), or software restriction rules, help limit unauthorized binaries. Additionally, hardening permissions in Active Directory reduces the exposure of sensitive data to standard users.
That said, the AD security model assumes that certain information is readable by authenticated users because many applications depend on it. Effective mitigation involves strengthening delegations, auditing control routes, and reducing privileges.Using these tools to detect and correct what shouldn't be visible or enabled. Prevention shouldn't rely solely on blocking executables, but rather on eliminating the attack surface at the configuration level.
Common use cases and smart combination
A small IT team that needs a quick diagnosis and clear troubleshooting guide will appreciate Purple Knight. Prioritization by severity and its mapping to enabling frameworks It allows users to prepare penetration tests, demonstrate progress, and communicate risks to management. Meanwhile, recurring internal audits and consulting firms serving multiple domains benefit from PingCastle's maturity model, domain mapping, and consolidation capabilities.
Many organizations run both tools in different cycles to obtain complementary insight: first a “snapshot” with IOE/IOC, followed by a review of processes and maturity with consolidated health checks. Cross-validation reduces false negatives and improves remediation prioritization.accelerating the closing of critical gaps and raising identity hygiene in the medium term.
There is no silver bullet. Choosing well involves aligning needs with capabilities: a snapshot with prescriptive guidelines or maturity models and maps? A one-off assessment or continuous monitoring with ITDR? The answer is usually a “yes, and…” rather than a resounding “or”combining free assessment with monitoring solutions tailored to risk and budget.
If the goal is to sustainably improve identity security, it is advisable to schedule regular assessments, review delegations and trusts, and maintain account hygiene, GPOs (and ADMX files) and Kerberos. The combined use of Purple Knight and PingCastle, plus a change audit layer and/or ITDRIt offers the right balance between early detection, prioritized correction, and continuous monitoring of the status of AD and Entra ID.