Cq
Claritiq
·
Audit Pack
Critical
Caution
Healthy · target
Scope: eni.enigron.com · c1.eni.enigron.com
Report Period
Q2 2026
Apr 1 – Jun 30
Total Enabled Accounts
966
+12 vs Q1
Privileged Accounts
47
+2 net (+3 added, -1 removed)
Stale Enabled (90+)
247
point-in-time snapshot
Critical Findings
0
zero PASSWD_NOTREQD
Audit-Ready
Yes
all controls passing
Control attestation summary
| Control | Expected | Observed | Status |
|---|---|---|---|
| AC-01: Privileged access reviewed quarterly | Yes | Yes (2026-04-01) | Pass |
| AC-02: Stale accounts disabled within 90 days | 0 violations | 0 | Pass |
| AC-03: No PASSWD_NOTREQD on privileged | 0 | 0 | Pass |
| AC-04: No unconstrained delegation on users | 0 | 0 | Pass |
| AC-05: Admin accounts in Protected Users | 100% | 89% | Partial |
| AC-06: krbtgt password rotated annually | < 365d | 287d | Pass |
| AC-07: Disabled users removed from admin groups | 100% | 95% | Partial |
| AC-08: Mailbox retention enforced | 100% | 98% | Partial |
6 passing, 3 partial, 0 failing. Partial controls need remediation plans attached in Appendix B.
Point-in-time evidence summary
| Metric | Current | Severity |
|---|---|---|
| Enabled users | 966 | |
| Disabled users (total in AD) | 196 | |
| Stale 90+ accounts (enabled) | 247 | |
| Stale 180+ accounts (enabled) | 143 | |
| Never-logged-in enabled | 38 | |
| Privileged users (active) | 47 | |
| Kerberoastable admins | 3 | |
| PASSWD_NOTREQD set | 4 | |
| Workaround-provisioned | 89 |
Snapshot data, refreshed daily. Quarter-over-quarter trend lines arrive in Phase 4 (Historical Trends — BACKLOG F.13). For real-time change tracking on privileged accounts, see Phase 3 Sentinel integration (BACKLOG F.11).