{"id":22270,"date":"2026-01-07T12:21:24","date_gmt":"2026-01-07T12:21:24","guid":{"rendered":"https:\/\/www.synetis.com\/configuration-audit-2\/"},"modified":"2026-05-11T12:06:19","modified_gmt":"2026-05-11T12:06:19","slug":"configuration-audit-2","status":"publish","type":"page","link":"https:\/\/www.synetis.com\/en\/ssi-audit\/safety-audits\/configuration-audit-2\/","title":{"rendered":"Configuration audit"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"22270\" class=\"elementor elementor-22270 elementor-10602\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7832a80 e-flex e-con-boxed e-con e-parent\" data-id=\"7832a80\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-3e4f659 e-con-full e-flex e-con e-child\" data-id=\"3e4f659\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-c3605d1 elementor-widget elementor-widget-shortcode\" data-id=\"c3605d1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\"><div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.synetis.com\/en\/\" title=\"Accueil\">Accueil<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">\u203a<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.synetis.com\/en\/ssi-audit\/\" title=\"SSI audit\">SSI audit<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">\u203a<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.synetis.com\/en\/ssi-audit\/safety-audits\/\" title=\"Safety audits\">Safety audits<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">\u203a<\/span><span class=\"aioseo-breadcrumb\">\n\tConfiguration audit\n<\/span><\/div><\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-30325ff elementor-widget elementor-widget-heading\" data-id=\"30325ff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Configuration audit<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-05554ba elementor-widget elementor-widget-text-editor\" data-id=\"05554ba\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">A configuration audit to prevent misconfigurations and reinforce the security of your Information System<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-897e4aa elementor-widget elementor-widget-button\" data-id=\"897e4aa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.synetis.com\/en\/contact\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Contact our teams<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-c0162c2 e-flex e-con-boxed e-con e-parent\" data-id=\"c0162c2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-5a04d67 elementor-widget elementor-widget-heading\" data-id=\"5a04d67\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Purpose of a configuration audit<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7cca607 elementor-widget elementor-widget-text-editor\" data-id=\"7cca607\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The configuration audit consists of analyzing the configuration of your equipment to verify the integration of security mechanisms and reduce the attack surface.  <\/span><\/p><p> <\/p><p><span style=\"font-weight: 400;\">This assessment may be based on the manufacturer&#8217;s safety recommendations, ANSSI, CIS or an internal reference framework.<\/span><\/p><p> <\/p><p><span style=\"font-weight: 400;\">Interviews may be necessary to assess the relevance of the analysis to operational constraints.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-af5828d e-flex e-con-boxed e-con e-parent\" data-id=\"af5828d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-032e07a elementor-widget elementor-widget-heading\" data-id=\"032e07a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Benefits expected from a configuration audit<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3b73412 elementor-widget elementor-widget-text-editor\" data-id=\"3b73412\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The benefits of a configuration audit include :<\/span><\/p><p> <\/p><ul><li aria-level=\"1\">An assessment of the quality of your system configuration by a recognized, independent audit firm;<\/li><li aria-level=\"1\">A better understanding of the functionalities exposed by your systems ;<\/li><li aria-level=\"1\">An action plan for upgrading the safety of your equipment, taking into account the risks identified and the complexity of implementing the recommendations.<\/li><\/ul><p> <\/p><p><span style=\"font-weight: 400;\">As Synetis is a PASSI-qualified company, the configuration audit can be carried out under this qualification as defined by ANSSI. This applies, for example, to the audit of a Restricted Diffusion network or a SecNumCloud qualification. <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-4dfaf54 e-flex e-con-boxed e-con e-parent\" data-id=\"4dfaf54\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-810e8d4 elementor-widget elementor-widget-heading\" data-id=\"810e8d4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Configuration audit methodology<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-79bd4b6 elementor-widget elementor-widget-text-editor\" data-id=\"79bd4b6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">After determining the configuration points to be assessed, the auditors compare the configuration of the audited equipment with the safety recommendations. This detailed analysis of configuration faults enables them to identify relevant metrics for risk assessment and treatment. <\/span><\/p><p> <\/p><p><span style=\"font-weight: 400;\">Synetis carries out configuration audits of various <\/span><b>bricks,<\/b><span style=\"font-weight: 400;\"> both <\/span><b>software<\/b><span style=\"font-weight: 400;\"> as well as<\/span><b> of your Information System<\/b><span style=\"font-weight: 400;\">.<\/span><\/p><p> <\/p><p><span style=\"font-weight: 400;\">In addition to relying on appropriate and recognized security standards (ANSSI, CIS), our approach is also based on feedback from our technical experts in charge of integrating security solutions.<\/span><\/p><p> <\/p><p><span style=\"font-weight: 400;\">We cover configuration audits for a wide variety of systems, including :<\/span><\/p><p> <\/p><ul><li>Microsoft Active Directory ;<\/li><li>Microsoft Windows (10, 11) ;<\/li><li>Microsoft Windows Server (2003, 2008, 2012, 2016, 2019 and 2022) ;<\/li><li>Linux servers ;<\/li><li>Databases (MySQL, MSSQL, Oracle, &#8230;) ;<\/li><li>Cloud environments (AWS, Azure, GCP, &#8230;) ;<\/li><li>Security components, such as firewalls, proxies, PAM (Privileged Access Management) solutions, etc., an approach that can complement a target Information System architecture audit.<\/li><\/ul><p> <\/p><p><span style=\"font-weight: 400;\">In a broader sense, Synetis also carries out audits of telecommuting or work environments, based on a study of the configuration of a corporate workstation. The aim of this type of audit is to verify that the configuration has been hardened (according to state-of-the-art rules) and to identify any loopholes that could enable an attacker or malicious employee to gain elevated privileges. <\/span><\/p><p> <\/p><p><span style=\"font-weight: 400;\">This type of audit can also be complemented by <\/span><span style=\"font-weight: 400;\">a hardware audit<\/span><span style=\"font-weight: 400;\">which validates the choice of hardware and &#8220;low-level&#8221; configurations (Bios&#8230;).<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-78c2e41 e-flex e-con-boxed e-con e-parent\" data-id=\"78c2e41\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-cab1247 elementor-widget elementor-widget-heading\" data-id=\"cab1247\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Some examples of technical recommendations<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-97c339d elementor-widget elementor-widget-text-editor\" data-id=\"97c339d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">By way of illustration, here are a few recommendations resulting from our configuration audit work:<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-eb0a5c4 elementor-widget elementor-widget-heading\" data-id=\"eb0a5c4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Active Directory audit<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ea683d2 elementor-widget elementor-widget-text-editor\" data-id=\"ea683d2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<ul><li>Modify unwanted rights that have appeared following the installation of Windows Server 2016 (AD PREP bug) ;<\/li><li>Modify the composition of privileged groups ;<\/li><li>Set up a third-party administration model ;<\/li><li>Reinforce the audited elements in the audit policy.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4c33569 elementor-widget elementor-widget-heading\" data-id=\"4c33569\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Web server audit<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3e8e07e elementor-widget elementor-widget-text-editor\" data-id=\"3e8e07e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<ul><li>Disable directory listing and file system access rights for Web servers ;<\/li><li>Managing exposed HTTP verbs ;<\/li><li>Configure session cookies to manage the duration of a session.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-29c6a5b elementor-widget elementor-widget-heading\" data-id=\"29c6a5b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Cloud Audit<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c45c15c elementor-widget elementor-widget-text-editor\" data-id=\"c45c15c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<ul><li>Enable dual authentication for administration accounts ;<\/li><li>Set up default network filtering for VPCs ;<\/li><li>Define logging filters for certain security events (group changes, access control modifications, etc.).<\/li><\/ul><p> <\/p><p><strong><a href=\"https:\/\/www.synetis.com\/en\/contact\/\" target=\"_blank\" rel=\"noopener\">Contact our Synetis experts<\/a> for more information on configuration audits to improve your cybersecurity!<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Analyze the configuration of your equipment to verify the integration of security mechanisms and reduce the attack surface.<\/p>\n","protected":false},"author":7,"featured_media":0,"parent":22669,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"class_list":["post-22270","page","type-page","status-publish","hentry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.synetis.com\/en\/wp-json\/wp\/v2\/pages\/22270","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.synetis.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.synetis.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.synetis.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.synetis.com\/en\/wp-json\/wp\/v2\/comments?post=22270"}],"version-history":[{"count":4,"href":"https:\/\/www.synetis.com\/en\/wp-json\/wp\/v2\/pages\/22270\/revisions"}],"predecessor-version":[{"id":22712,"href":"https:\/\/www.synetis.com\/en\/wp-json\/wp\/v2\/pages\/22270\/revisions\/22712"}],"up":[{"embeddable":true,"href":"https:\/\/www.synetis.com\/en\/wp-json\/wp\/v2\/pages\/22669"}],"wp:attachment":[{"href":"https:\/\/www.synetis.com\/en\/wp-json\/wp\/v2\/media?parent=22270"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}